Senior IAM Architect
Xtensys Connected Health Solutions
Job description Who We Are
Xtensys is a rapidly growing managed service provider delivering innovative technology solutions to health systems, beginning in New York and expanding nationwide. Owned by two industry leaders with a strong focus on advancing rural and community healthcare, Xtensys is executing several major initiatives and scaling quickly. With a team of more than 500 professionals, we are building a people-centered culture rooted in collaboration, innovation, and strategic thinking.
We are seeking an experienced Senior IAM Architect to support our continued growth and commitment to deliver exceptional client outcomes.
Why Join Us?
• Mission-Driven Work: You are the "bridge" ensuring technology serves health systems and their patients when they need it most.
• Autonomy & Ownership: We trust you. You'll lead projects, define success, and manage complexities with total support.
• A Culture of Innovation: Have a fresh perspective? We want it. We encourage risk-taking and continuous improvement.
• Continuous Growth: We fuel your "restless curiosity" with opportunities to expand your skillset and mentor others.
The Role:
Your Mission: The Senior IAM Architect is a senior technical lead responsible for designing, documenting, and driving the maturation of identity and access management capabilities across the Xtensys environment and its customers. This is not a purely advisory role. The right candidate will own the current state, define the future state, and build the steppingstones between them, producing deliverables that are equally credible to a CISO and a systems administrator.
This role requires a high degree of independent judgment and self-direction. The IAM Architect is expected to proactively identify process gaps, access anomalies, governance risks, and operational inefficiencies without waiting to be directed. When something is wrong or could be improved, the expectation is that you investigate it, document your findings, and bring a recommendation, not just an observation. The IAM Manager should be learning about problems and proposed solutions together, not assigning discovery work.
The role operates across two horizons simultaneously. In the near term, the Architect will optimize existing tooling, including ManageEngine ADManager Plus, to reduce manual lifecycle work and improve governance controls while the organization evaluates a next-generation IGA platform (SailPoint IdentityNow, pending budget approval). In the longer term, the Architect will lead the design and phased implementation of that platform, including Epic EMR provisioning, enterprise RBAC, and access certification programs.
This role may mentor or provide technical direction to junior IAM team members but does not carry formal supervisory responsibility at this time.
What You'll Do Day-to-Day:
Proactive Governance and Anomaly Detection:
• Continuously monitor identity systems, access patterns, lifecycle workflows, and audit logs for anomalies, policy violations, and process gaps without waiting for issues to be escalated.
• Independently investigate anomalies, document root cause findings, and implement or recommend corrective actions with minimal direction.
• Establish and maintain proactive monitoring practices including stale account detection, orphaned access identification, offboarding compliance tracking, and privilege creep analysis.
• Maintain a standing risk and improvement register for the IAM program, self-updating it as new findings are identified and tracking items through resolution.
Current State Assessment and Documentation:
• Assess, document, and baseline all primary IAM workflows including Joiner, Mover, Leaver, Leave of Absence, and Reactivation processes across all Xtensys-managed domains.
• Identify and document manual process steps, tooling gaps, compliance exposure, and quality control risks in existing workflows.
• Maintain living documentation of the IAM environment including architecture diagrams, process flows, and system integration maps.
IAM Program Strategy and Roadmap:
• Develop and maintain a multi-horizon IAM program roadmap that addresses current state gaps, defines measurable future state outcomes, and accounts for budget contingencies and platform decisions.
• Produce executive-facing program summaries, status reports, and governance updates suitable for CTO and CISO audiences.
• Evaluate emerging IAM platforms and technologies against organizational requirements and present structured vendor recommendations to IAM leadership.
Identity Lifecycle Management:
• Design, implement, and optimize Joiner, Mover, and Leaver workflows across on-premises Active Directory, Microsoft Entra ID, and integrated SaaS platforms.
• Reduce manual lifecycle work in the current ManageEngine ADManager Plus environment through targeted workflow automation, role template optimization, and Jira integration improvements.
• Design and implement Workday-to-IGA Platform integration for lifecycle event triggering, attribute mapping, and manager synchronization.
• Define and enforce offboarding standards including cross-domain account disablement, Epic access revocation, and privileged account closure within defined SLAs.
IGA Platform Implementation (SailPoint IdentityNow):
• Lead the design and phased implementation of SailPoint IdentityNow pending budget approval, including connector configuration, lifecycle workflow build, and role model design.
• Manage Epic EMP and SER integration within the IGA platform, coordinating with Epic Security and clinical informatics teams.
• Design and implement access certification campaigns, attestation workflows, and governance reporting within the IGA platform.
• Develop and execute a migration plan transitioning lifecycle workflows from ManageEngine ADManager Plus to SailPoint.
Identity Governance and Access Control:
• Design and implement enterprise RBAC models across Active Directory, Entra ID, and clinical systems, with particular attention to Epic security role correlation.
• Conduct and support periodic access reviews, recertifications, and audit evidence collection across all managed identity systems.
• Develop and enforce IAM policies covering account standards, naming conventions, attribute requirements, and lifecycle SLAs.
• Partner with cybersecurity and compliance teams to ensure IAM controls satisfy HIPAA, NIST 800-53, and organizational audit requirements.
Technical Operations and Escalation:
• Serve as the senior technical escalation point for identity-related service tickets, provisioning failures, and access disputes.
• Monitor IAM infrastructure for performance, availability, and security anomalies; proactively identify and remediate issues.
Who You Are & What You'll Bring: Proven Track Record:
• 8+ years of hands-on IAM experience with a combination of design, implementation, and operational ownership of enterprise identity systems.
• Demonstrated experience producing current state assessments, IAM program roadmaps, and executive-facing communications for senior leadership audiences.
• Experience designing and managing Joiner, Mover, Leaver workflows in complex multi-domain or post-merger environments.
• Experience with Workday-to-Active Directory integration including HR-driven provisioning, attribute mapping, and lifecycle synchronization.
• Experience implementing or operating in a healthcare or regulated industry environment with HIPAA compliance obligations.
Preferred Skills & Experience:
• SailPoint IdentityNow implementation experience including connector development, lifecycle workflow configuration, role model design, and access certification campaigns.
• Familiarity with Epic EMR identity and access workflows, including EMP record management, SER provider records, security template design, and provisioning integration with an IGA platform.
• Experience designing IAM programs in post-merger or multi-entity environments with multiple Active Directory domains and distinct identity namespaces.
Certifications:
• SailPoint Certified IdentityNow Engineer or equivalent IGA platform certification preferred.
• Microsoft Identity and Access Administrator (SC-300) or equivalent Entra ID certification preferred.
Technical Savvy:
• Deep expertise with Microsoft Active Directory and Microsoft Entra ID (Azure AD) including hybrid identity, Conditional Access, and delegated administration.
• Strong PowerShell scripting capability for lifecycle automation, audit log analysis, group membership management, and reporting.
• Proficiency with ManageEngine ADManager Plus including role-based templates, delegated workflows, and provisioning automation.
• Experience with SAML, OAuth 2.0, OIDC, SCIM, and LDAP protocols in enterprise integration contexts.
• Working knowledge of Jira for service ticket workflow management and IAM request routing.
• Familiarity with BeyondTrust and SecureLink for privileged and third-party access management.
Work Schedule & Additional Requirements:
• On-call support may be required approximately once every six weeks to assist with escalations and provide after-hours support as needed.
• Occasional travel (5% or less) may be required for team meetings and collaboration.
Physical Readiness:
• Sedentary work requiring exertion of up to 10 pounds of force occasionally. The role involves sitting most of the time, with occasional walking and standing as needed.
#LI-Remote
Xtensys is a rapidly growing managed service provider delivering innovative technology solutions to health systems, beginning in New York and expanding nationwide. Owned by two industry leaders with a strong focus on advancing rural and community healthcare, Xtensys is executing several major initiatives and scaling quickly. With a team of more than 500 professionals, we are building a people-centered culture rooted in collaboration, innovation, and strategic thinking.
We are seeking an experienced Senior IAM Architect to support our continued growth and commitment to deliver exceptional client outcomes.
Why Join Us?
• Mission-Driven Work: You are the "bridge" ensuring technology serves health systems and their patients when they need it most.
• Autonomy & Ownership: We trust you. You'll lead projects, define success, and manage complexities with total support.
• A Culture of Innovation: Have a fresh perspective? We want it. We encourage risk-taking and continuous improvement.
• Continuous Growth: We fuel your "restless curiosity" with opportunities to expand your skillset and mentor others.
The Role:
Your Mission: The Senior IAM Architect is a senior technical lead responsible for designing, documenting, and driving the maturation of identity and access management capabilities across the Xtensys environment and its customers. This is not a purely advisory role. The right candidate will own the current state, define the future state, and build the steppingstones between them, producing deliverables that are equally credible to a CISO and a systems administrator.
This role requires a high degree of independent judgment and self-direction. The IAM Architect is expected to proactively identify process gaps, access anomalies, governance risks, and operational inefficiencies without waiting to be directed. When something is wrong or could be improved, the expectation is that you investigate it, document your findings, and bring a recommendation, not just an observation. The IAM Manager should be learning about problems and proposed solutions together, not assigning discovery work.
The role operates across two horizons simultaneously. In the near term, the Architect will optimize existing tooling, including ManageEngine ADManager Plus, to reduce manual lifecycle work and improve governance controls while the organization evaluates a next-generation IGA platform (SailPoint IdentityNow, pending budget approval). In the longer term, the Architect will lead the design and phased implementation of that platform, including Epic EMR provisioning, enterprise RBAC, and access certification programs.
This role may mentor or provide technical direction to junior IAM team members but does not carry formal supervisory responsibility at this time.
What You'll Do Day-to-Day:
Proactive Governance and Anomaly Detection:
• Continuously monitor identity systems, access patterns, lifecycle workflows, and audit logs for anomalies, policy violations, and process gaps without waiting for issues to be escalated.
• Independently investigate anomalies, document root cause findings, and implement or recommend corrective actions with minimal direction.
• Establish and maintain proactive monitoring practices including stale account detection, orphaned access identification, offboarding compliance tracking, and privilege creep analysis.
• Maintain a standing risk and improvement register for the IAM program, self-updating it as new findings are identified and tracking items through resolution.
Current State Assessment and Documentation:
• Assess, document, and baseline all primary IAM workflows including Joiner, Mover, Leaver, Leave of Absence, and Reactivation processes across all Xtensys-managed domains.
• Identify and document manual process steps, tooling gaps, compliance exposure, and quality control risks in existing workflows.
• Maintain living documentation of the IAM environment including architecture diagrams, process flows, and system integration maps.
IAM Program Strategy and Roadmap:
• Develop and maintain a multi-horizon IAM program roadmap that addresses current state gaps, defines measurable future state outcomes, and accounts for budget contingencies and platform decisions.
• Produce executive-facing program summaries, status reports, and governance updates suitable for CTO and CISO audiences.
• Evaluate emerging IAM platforms and technologies against organizational requirements and present structured vendor recommendations to IAM leadership.
Identity Lifecycle Management:
• Design, implement, and optimize Joiner, Mover, and Leaver workflows across on-premises Active Directory, Microsoft Entra ID, and integrated SaaS platforms.
• Reduce manual lifecycle work in the current ManageEngine ADManager Plus environment through targeted workflow automation, role template optimization, and Jira integration improvements.
• Design and implement Workday-to-IGA Platform integration for lifecycle event triggering, attribute mapping, and manager synchronization.
• Define and enforce offboarding standards including cross-domain account disablement, Epic access revocation, and privileged account closure within defined SLAs.
IGA Platform Implementation (SailPoint IdentityNow):
• Lead the design and phased implementation of SailPoint IdentityNow pending budget approval, including connector configuration, lifecycle workflow build, and role model design.
• Manage Epic EMP and SER integration within the IGA platform, coordinating with Epic Security and clinical informatics teams.
• Design and implement access certification campaigns, attestation workflows, and governance reporting within the IGA platform.
• Develop and execute a migration plan transitioning lifecycle workflows from ManageEngine ADManager Plus to SailPoint.
Identity Governance and Access Control:
• Design and implement enterprise RBAC models across Active Directory, Entra ID, and clinical systems, with particular attention to Epic security role correlation.
• Conduct and support periodic access reviews, recertifications, and audit evidence collection across all managed identity systems.
• Develop and enforce IAM policies covering account standards, naming conventions, attribute requirements, and lifecycle SLAs.
• Partner with cybersecurity and compliance teams to ensure IAM controls satisfy HIPAA, NIST 800-53, and organizational audit requirements.
Technical Operations and Escalation:
• Serve as the senior technical escalation point for identity-related service tickets, provisioning failures, and access disputes.
• Monitor IAM infrastructure for performance, availability, and security anomalies; proactively identify and remediate issues.
Who You Are & What You'll Bring: Proven Track Record:
• 8+ years of hands-on IAM experience with a combination of design, implementation, and operational ownership of enterprise identity systems.
• Demonstrated experience producing current state assessments, IAM program roadmaps, and executive-facing communications for senior leadership audiences.
• Experience designing and managing Joiner, Mover, Leaver workflows in complex multi-domain or post-merger environments.
• Experience with Workday-to-Active Directory integration including HR-driven provisioning, attribute mapping, and lifecycle synchronization.
• Experience implementing or operating in a healthcare or regulated industry environment with HIPAA compliance obligations.
Preferred Skills & Experience:
• SailPoint IdentityNow implementation experience including connector development, lifecycle workflow configuration, role model design, and access certification campaigns.
• Familiarity with Epic EMR identity and access workflows, including EMP record management, SER provider records, security template design, and provisioning integration with an IGA platform.
• Experience designing IAM programs in post-merger or multi-entity environments with multiple Active Directory domains and distinct identity namespaces.
Certifications:
• SailPoint Certified IdentityNow Engineer or equivalent IGA platform certification preferred.
• Microsoft Identity and Access Administrator (SC-300) or equivalent Entra ID certification preferred.
Technical Savvy:
• Deep expertise with Microsoft Active Directory and Microsoft Entra ID (Azure AD) including hybrid identity, Conditional Access, and delegated administration.
• Strong PowerShell scripting capability for lifecycle automation, audit log analysis, group membership management, and reporting.
• Proficiency with ManageEngine ADManager Plus including role-based templates, delegated workflows, and provisioning automation.
• Experience with SAML, OAuth 2.0, OIDC, SCIM, and LDAP protocols in enterprise integration contexts.
• Working knowledge of Jira for service ticket workflow management and IAM request routing.
• Familiarity with BeyondTrust and SecureLink for privileged and third-party access management.
Work Schedule & Additional Requirements:
• On-call support may be required approximately once every six weeks to assist with escalations and provide after-hours support as needed.
• Occasional travel (5% or less) may be required for team meetings and collaboration.
Physical Readiness:
• Sedentary work requiring exertion of up to 10 pounds of force occasionally. The role involves sitting most of the time, with occasional walking and standing as needed.
#LI-Remote
Vacancy posted 19 hours ago
Similar jobs that could be interesting for youBased on the Senior IAM Architect in United States vacancy
$104.55k - $193.63k
...be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Senior Identity & Access Management (IAM) Architect- Remote to join our team in Phoenix, Arizona (US-AZ), United States (US).NTT Data is seeking an experienced IAM...SeniorTemporary workWork at officeRemote workFlexible hours- ...Jazz Solutions Inc. seeks a SailPoint IdentityIQ Architect to lead the design, integration, and operation of enterprise IAM in a large federal environment. This hybrid role requires a deep expertise in identity governance, lifecycle management, and secure cloud integration...Senior
$107.93k - $188.9k
...critical to protecting enterprise systems, data, and users. As an IAM Architect, you will help design and deliver identity management... ...Professional development From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities...Senior- ...Senior Identity And Access Management Consultant Provide senior Identity and Access Management (IAM) guidance, advisory, and architecture services to support Bank objectives and... ...recent demonstrated experience as an IAM architect, or identity security consultant in...SeniorRemote work
- EY in Dallas is seeking a Senior Consultant to shape and deliver Enterprise Identity & Access Management solutions. You will design, implement and maintain IAM programs using Saviynt and SailPoint, while guiding stakeholders and ensuring secure access governance across...Senior
- PepsiCo seeks an Authentication, SSO/MFA and CIAM SME/Architect to lead enterprise IAM strategy, design, and delivery from Plano, TX. You will guide secure authentication across workforce, partner, and customer identities, shaping zero-trust aligned architectures. You...Senior
- Booz Allen Hamilton is seeking a Senior Identity and Access Management Specialist to design, implement, and sustain secure identity lifecycle... ..., authorization, and directory services to strengthen IAM posture and protect sensitive data. Work closely with stakeholders...Senior
- Cencora is seeking a Principal IAM Architect to serve as the senior technical authority for Identity and Access Management across the enterprise. You will define strategy, architecture standards, and a technology roadmap to secure workforce, partner, and customer access...Senior
- TALENT Software Services is seeking a Senior Identity & Access Management professional to design, implement, and oversee Active Directory... ...AD modernization, cloud integration with AWS, and strengthening IAM governance across a large enterprise. You will lead the design...Senior
- Itron, Inc. is seeking a Principal, Identity Management to lead the enterprise IAM program across hybrid and multi-cloud environments. This role drives architecture, standards, and strategic IAM initiatives to secure workforce, customer, product, and non-human identities...Senior
- Conexess Group is seeking an experienced candidate with deep hands-on expertise in Enterprise Identity and Access Management (IAM) specifically within regulated industries like healthcare and financial services. This role emphasizes operational excellence and solution architecture...Senior
- Performix in Minnesota seeks a Senior Professional Identity & Access Management to design, implement, and oversee identity and access management... ...brings extensive Active Directory expertise and hands-on IAM experience, with a track record of integrating AD with AWS and...Senior
- Kerry Search Partners is seeking a Senior Enterprise Identity Architect for a global technology leader in semiconductor manufacturing. You will own the enterprise identity architecture, shaping IAM, security, and Zero Trust across a complex global environment, combining...Senior
- ICF is seeking an IAM Lead to architect, implement, and operate the identity and access management platform for a federal technology program. You will own the full identity lifecycle from onboarding automation to privileged access controls and external identity federation...SeniorRemote job
- Tata Consultancy Services in Sunnyvale, CA seeks an experienced IAM Architect to lead design, implementation, and modernization of enterprise IAM solutions, with deep expertise in Okta, SailPoint IdentityIQ/Identity Security Cloud, and Microsoft Active Directory. You will...Senior
- ...We are seeking a Senior IAM Architect with strong expertise in enterprise identity architecture, Microsoft Entra ID, Active Directory, and identity lifecycle management. The role will focus on designing scalable IAM solutions, modernizing identity provisioning processes...SeniorTemporary work
- A technology solutions provider is seeking a Senior IAM Developer in California. This role focuses on implementing OKTA-based integrations, managing API credential migrations, and ensuring high security standards. The ideal candidate should have deep expertise in IAM protocols...Senior
- ...Description We are seeking an Identity and Access Management (IAM) Architect to lead the design and evolution of our enterprise identity strategy... ...objectives and communicate decisions and tradeoffs to senior leadership. Qualifications ~Strong experience in the identity...SeniorFull timeRemote workHome officeFlexible hours
- KTek Resourcing seeks an IAM Architect to define and lead the enterprise-wide Identity and Access Management strategy. The role involves collaborating closely with various teams to ensure secure and compliant access across on-premises and cloud environments. The ideal candidate...Senior
- PepsiCo hires an Authentication, SSO/MFA and CIAM SME/Architect to lead secure identity solutions across workforce, partner, and customer... ...mentor engineers, drive DevOps practices, and deliver scalable IAM capabilities including Okta and related #J-18808-Ljbffr PepsiCo...Senior
- A consulting firm is seeking a Senior IAM Consultant in St. Louis to lead the design and deployment of identity governance solutions such as SailPoint and Saviynt. The ideal candidate will have 5-7+ years in IAM, strong hands-on implementation skills, and a solid understanding...Senior
$150k - $195k
A global digital transformation firm is seeking a specialist to design and implement IAM strategies on GCP. The role involves configuring federated identity solutions, managing security compliance, and optimizing IAM practices across cloud infrastructure. You will work...Senior- ...and Access Management specialist in College Park, Maryland. The selected candidate will play a vital role in designing and deploying IAM solutions using Ping technology to protect sensitive data for clients within the Department of Defense and Intelligence Community. Ideal...Senior
$121k - $137k
Berkley Technology Services is seeking a Sr Systems Engineer to design, plan, and implement Identity and Access Management (IAM) solutions. The role demands experience in IAM technologies such as Okta, Auth0, and Microsoft Entra ID, alongside project leadership and technical...Senior- ...Job Description Job Description Senior SailPoint IAM Engineer / Architect Location: NYC, NY Duration: 12 Months Work Schedule: 37.5 Hours/Week Position Overview We are seeking a highly skilled Senior SailPoint IAM Engineer / Architect to design, engineer...Senior
$145.6k - $209.3k
...succeeds together. Because at UKG, your work matters—and so do you.UKG is seeking an experienced Identity & Access Management (IAM) Architect to help define, design, and evolve the identity security architecture supporting our global workforce, enterprise platforms, and...Senior- Deal Exchange, LLC is seeking an Identity and Access Management Architect in Southfield, MI. This role involves leading identity security efforts, implementing role-based access control, and acting as a technical advisor across teams. The ideal candidate should have significant...Senior
- MartinFed is seeking an experienced Senior SailPoint Subject Matter Expert (SME) to lead an enterprise on-prem SailPoint environment supporting a federal customer. The role requires deep hands-on IIQ development, architecture, and DevOps collaboration in a government context...Senior
- Booz Allen Hamilton is seeking an Enterprise ICAM Architect to lead ICAM strategy, implementation, and governance for VA programs, including SSO, IGA, and PAM. You will drive security architecture, regulatory alignment, and vendor decisions while coordinating across government...Senior
- ..., or related technical disciplines ~5+ years of experience serving as a Technical Architect for a Customer Identity and Access Management (CIAM) or Identity and Access Management (IAM) enterprise platform ~5+ years of experience designing, implementing, or supporting...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior IAM Architect. Be the first to apply!
Related searches
- senior human resources associate United States
- senior network engineer remote United States
- senior education consultant United States
- senior benefits manager United States
- senior app developer United States
- senior personal assistant United States
- senior manager legal United States
- senior geologist United States
- senior internal tool engineer United States
- senior retail sales associate United States



