Sr. Staff IAM Engineer

OpenLoop · Remote · United States - Remote

ABOUT OPENLOOP OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states. ABOUT THE ROLE OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. Our Identity and Access Management team governs how every person, partner, and system proves who they are and what they can reach. We are hiring a Sr. Staff IAM Engineer(Architect) to be the design authority for identity across the company: workforce, non-employee, customer, partner, non-human, and AI agent. That last one is not filler. Service accounts and AI agents are on track to outnumber the people we govern, and very few companies have a real architecture for them yet. You would own ours. The platforms are chosen and in flight. Okta is our workforce IdP. SailPoint ISC and NERM are deploying for identity governance and non-employee records. Britive is deploying for privileged just-in-time access. Auth0 is our customer identity platform, procured with machine-to-machine flows in production and the interactive login experience in active build. iam-ops-hub, our identity posture and remediation platform, is built in house and deployed. What we do not have is a single design authority tying them together. Architecture currently gets decided project by project, under delivery pressure. This role exists to change that. This is a hands-on architecture role, and we mean that concretely. Expect to write Auth0 Actions, Okta Workflows, and Terraform, and to query the posture warehouse yourself. Identity controls here carry HIPAA, HITRUST, and SOC 2 weight. The person who does well in this role is comfortable in ambiguity, writes decisions down, and can explain a design tradeoff to a staff engineer and to a CISO in the same week. WHAT YOU’LL DO: - Own the target-state identity architecture across workforce, non-employee, external, non-human, and AI agent identity types, and set the standards, reference patterns, and decision records that make platform choices consistent rather than improvised per project. - Own our Auth0 customer identity architecture end to end, including tenant and organization modelling, MFA and phishing-resistant authentication, and machine-to-machine patterns, taking it from partially live to fully architected and governed across our external and partner use cases. - Keep the customer and patient identity plane deliberately separate from the workforce plane, define the interfaces where the two must meet, and design the external and partner identity models for third-party developers and B2B customers. - Own the architecture for consolidating our remaining authentication paths onto a single workforce IdP, including the sequencing and patterns our engineers build against. - Design SSO, SCIM provisioning, and automated deprovisioning patterns for applications handling sensitive data, with audit evidence produced as a byproduct of the design rather than as a manual exercise. - Define the federation and directory architecture across Okta, Entra ID, AWS, and GCP, including subsidiary and acquisition integration patterns. - Build out Identity Security Posture Management, extending the posture warehouse and remediation engine we built in house, and define the metrics that tell us whether identity posture is actually improving. - Partner with Security Operations and Security Architecture to design identity threat detection and response into our existing SIEM rather than a parallel stack. - Design access controls that satisfy HIPAA, HITRUST, and SOC 2 requirements without adding manual overhead, and keep architecture documentation and control mappings current enough that supporting an audit is a lookup rather than a project. -

Sign in to apply — one profile, every role on PreferHired.

Sign in to apply
Sr. Staff IAM Engineer at OpenLoop — PreferHired