Cotiviti

Enabling a high-quality and viable healthcare system

Security Engineer - IAM

Security EngineerSecurity EngineerFull TimeRemoteTeam 5,001-10,000H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

4 days ago

Salary

$90K - $120K / year

AWSEntra IDOktaADFSSAMLOauthSSOMFAPAMPower ShellPythonRBACHIPAAHITRUSTCISSPCISMCIAMDelineaCyber ArkBeyond TrustGroup PolicyActive Directory

Job Description

Overview

The Security Engineer - IAM role plays a crucial part in IT security, by ensuring that the right individuals have appropriate access to technology resources. They manage and maintain the IAM infrastructure, monitor user access activities, and implement policies to safeguard sensitive information. The Security Engineer - IAM collaborates with other departments to design, configure, and support secure access systems, ensuring compliance with regulatory requirements. Their role involves continuously evaluating and improving security measures to protect against unauthorized access and potential data breaches.

Responsibilities

  • Design, implement, and maintain IAM solutions across on‑prem and cloud environments (AWS, Entra ID, Okta).
  • Administer lifecycle provisioning/deprovisioning and access changes.
  • Develop IAM policies, standards, and governance documentation.
  • Configure and support MFA, SSO, and federation services (SAML, ADFS, OAuth)
  • Integrate and manage privileged/service accounts through PAM platforms.
  • Conduct access audits and compliance reporting (HIPAA, HITRUST).
  • Automate IAM workflows using PowerShell/Python.
  • Monitor IAM logs and access patterns for anomalies.
  • Participate in identity-related incident response.
  • Partner across IT and Cloud teams to enforce least privilege and RBAC.
  • Support IAM portions of disaster recovery and business continuity.
  • Complete all responsibilities as outlined in the annual performance review and/or goal setting.
  • Complete all special projects and other duties as assigned.
  • Must be able to perform duties with or without reasonable accommodation.

This job description is intended to describe the general nature and level of work being performed and is not to be construed as an exhaustive list of responsibilities, duties and skills required. This job description does not constitute an employment agreement and is subject to change as the needs of Cotiviti and requirements of the job change.

Qualifications

  • Bachelor’s degree in technology discipline or equivalent professional experience.
  • 2+ years of experience in Identity and Access Management or related security roles.
  • Relevant IAM certifications preferred (CISSP, CISM, CIAM).
  • Experience with AWS IAM, Entra Active Directory, Active Directory (Group Policy), and Okta.
  • Strong understanding of IAM concepts, principles, frameworks, and compliance requirements.
  • Expertise in federation technologies (ADFS, SAML, OAuth), SSO, and MFA.
  • Experience with PAM design and service account integration (Delinea, CyberArk, BeyondTrust).
  • Ability to manage IAM policies, permissions, RBAC, and least privilege.
  • Proficiency in PowerShell and Python automation.
  • Experience conducting access audits and compliance reporting (HIPAA, HITRUST).
  • Strong troubleshooting and problem‑solving skills.
  • Excellent communication and collaboration abilities.
  • Experience with IAM DR/BCP planning.

 

Cognitive/Mental Requirements:

  • Communicating with others to exchange information.
  • Problem-solving and thinking critically.
  • Completing tasks independently.
  • Interpreting data
  • Making timely decisions in the context of a workflow.
  • Maintaining focus.
  • Assessing the accuracy, neatness and thoroughness of the work assigned.
  • Learning new tasks and completing tasks in situations that have a speed or productivity quota.
  • Remembering and adhering to processes and protocols.
  • Applying established protocols in a timely manner.

Working Conditions and Physical Requirements:

  • Remaining in a stationary position, often standing or sitting for prolonged periods.
  • Communicating with others to exchange information.
  • Repeating motions that may include the wrists, hands, and/or fingers.
  • Assessing accuracy, neatness, and thoroughness of work.
  • Must be able to provide a dedicated, secure work area.
  • Must be able to provide high-speed internet access/connectivity and office setup and maintenance.
  • No adverse environmental conditions are expected.

Base compensation ranges from $90,000 to $120,000 per year. Specific offers are determined by various factors, such as experience, education, skills, certifications, and other business needs.

 

Cotiviti offers team members a competitive benefits package to address a wide range of personal and family needs, including medical, dental, vision, disability, and life insurance coverage, 401(k) savings plans, paid family leave, 9 paid holidays per year, and 17-27 days of Paid Time Off (PTO) per year, depending on specific level and length of service with Cotiviti. For information about our benefits package, please refer to our Careers page.

 

Date of Posting: 2/3/2026

We anticipate that the application window will close on 4/3/2026, but the application window may change depending on the volume of applications received or close immediately if a qualified candidate is selected.

#LI-REMOTE

#LI-AK1

#senior

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 1,001-5,000H1B Sponsor

This role leads the design, implementation, and management of enterprise Single Sign-On (SSO) integrations, MFA strategy, and access control policies primarily within Microsoft Azure (Entra ID). Key duties include configuring provisioning, managing Conditional Access, supporting App Registrations, and troubleshooting federation issues.

SAMLOAuthOpenID ConnectSCIMAzure Active DirectoryMicrosoft Graph APIPowerShellMulti-Factor AuthenticationConditional AccessApp Registration
United States
$127K - $160K / year
Full TimeRemoteTeam 1,001-5,000

The engineer will support service line initiatives within the IAM team, providing analysis and development for Identity Governance and Administration, specifically SailPoint IdentityNow (IDN). Responsibilities include managing IDN operations, configuring virtual appliances, and continuously improving the IAM posture from technical and functional perspectives.

SailPoint IdentityNowIdentity Access ManagementAWSPowerShellREST APISingle Sign-OnMulti-Factor AuthenticationSCIMRole-Based Access ControlAgile MethodologyJIRAConfluencePostman
United States
$172K - $178K / year

Strategic Account Manager – Managed Security Services

Binary Defense

Real people detecting real threats in real time.

Security Engineer4 days ago
Full TimeRemoteTeam 51-200Since 2014H1B No Sponsor

Strategic Account Manager handling enterprise client relationships at Binary Defense

Cyber Security
Texas
Security Engineer4 days ago
Full TimeRemoteTeam 1,001-5,000Since 2012H1B Sponsor

Regional Director leading cybersecurity team for Optiv's Philadelphia market

Cyber Security
Pennsylvania