NYU Langone Health · 5 months ago
Lead IAM Engineer, MCIT-Security Admin
NYU Langone Health is a fully integrated health system recognized for its quality patient care and low mortality rates. They are seeking a Lead IAM Engineer to design and manage secure identity and access solutions across hybrid environments, implementing enterprise IAM strategies and aligning access controls with security requirements.
EducationHealth CareHospitalMedicalNon Profit
Responsibilities
Manage and maintain a unified IAM architecture by integrating Active Directory (AD), Entra ID (Azure AD), and AWS IAM to ensure consistent, secure identity and access controls across on-premises and cloud platforms
Build and maintain a centralized identity framework connecting AD, Entra ID, and AWS IAM and GCP to protect sensitive healthcare data and streamline secure access across cloud and on-prem systems
Define and enforce enterprise identity standards, including naming conventions, group structures, RBAC policies, and lifecycle automation
Lead the adoption of Zero Trust principles and modern identity-centric security models by implementing secure IAM frameworks in AWS and GCP including roles, policies, SCPs, and federation while supporting vulnerability management efforts through alignment of access controls with cloud security findings
Collaborate with DevOps and cloud teams to ensure least privilege, access auditing, and just-in-time access models across Multi Cloud resources
Administer and optimize on-prem Active Directory, including domain trusts, Sites and Services, GPOs, OU structure, and replication
Design and enforce Entra ID Conditional Access policies, MFA (DUO, MS), risk-based authentication, and device trust
Lead integration of Entra ID with key business and clinical systems
Implement and manage access certification processes, audit trails, and automated entitlement reviews aligned with HIPAA frameworks
Lead response efforts for IAM-related audit findings, penetration tests, and security assessments
Develop scripts and tools (PowerShell, Python, or Terraform) to automate user provisioning, de-provisioning, and group management across systems
Act as the subject matter expert (SME) for IAM technologies and processes
Mentor other engineers and contribute to cross-functional initiatives across IT security, clinical systems, cloud infrastructure, and compliance teams
Qualification
Required
Typically requires 7 or more years of experience
BA/BS degree
Preferred
Experience with Privileged Access Management (PAM) tools (e.g., CyberArk, BeyondTrust)
Familiarity with Terraform, CloudFormation, or similar infrastructure-as-code tools for identity resource management
Preferred experience with Identity Governance and Administration (IGA) solutions such as SailPoint
Cloud certifications such as: Microsoft Certified: Identity and Access Administrator Associate, AWS Certified Security Specialty, GCP Cloud Security Engineer
Qualified candidates must be able to effectively communicate with all levels of the organization
Benefits
Comprehensive benefits and wellness package
Financial security benefits
Generous time-off program
Employee resources groups for peer support
Holistic employee wellness program
Company
NYU Langone Health
NYU Langone Health is a nonprofit organization that provides a center of excellence in healthcare, research, and medical education.
H1B Sponsorship
NYU Langone Health has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2023 (1)
2022 (5)
2021 (8)
2020 (35)
Funding
Current Stage
Late StageTotal Funding
$33.5MKey Investors
National Institute of Diabetes and Digestive and Kidney DiseasesMHCIPNational Institutes of Health
2024-02-06Grant· $13M
2023-10-16Grant· $12.5M
2022-02-17Grant· $8M
Leadership Team
Recent News
2026-01-05
News-Medical.Net
2026-01-03
2025-12-31
Company data provided by crunchbase