IAM Manager - Engineering
We tailor your resume to this role and apply for you in seconds.
Apply to IAM Manager - Engineering at EnsemblehpJob details
- Location
- United States or Georgia
- Work type
- Remote
- Compensation
- $92,400 - $138,600/yr
- Posted
- yesterday
- Apply on
- ensemblehp.wd5.myworkdayjobs.com
About this role
Thank you for considering a career at Ensemble!
Ensemble is a leading provider of technology-enabled revenue cycle management solutions for health systems, including hospitals and affiliated physician groups. They offer end-to-end revenue cycle solutions as well as a comprehensive suite of point solutions to clients across the country.
Ensemble keeps communities healthy by keeping hospitals healthy. We recognize that healthcare requires a human touch, and we believe that every touch should be meaningful. This is why our people are the most important part of who we are. By empowering them to challenge the status quo, we know they will be the difference!
O.N.E Purpose:
Customer Obsession: Consistently provide exceptional experiences for our clients, patients, and colleagues by understanding their needs and exceeding their expectations.
Embracing New Ideas: Continuously innovate by embracing emerging technology and fostering a culture of creativity and experimentation.
Striving for Excellence: Execute at a high level by demonstrating our “Best in KLAS” Ensemble Difference Principles and consistently delivering outstanding results.
The Opportunity:
Manager, IAM Engineering & New Client Provisioning
Ensemble Health Partners | Identity & Access Management | Technology Security
Position Summary
The Manager, IAM Engineering & Client Provisioning is an Ensemble Health Partners Technology Security leadership role responsible for unifying IAM platform engineering with client access provisioning operations. This leader ensures Ensemble has secure, compliant, scalable, and measurable identity services across enterprise and client environments, with clear ownership for SailPoint/IGA maturity, lifecycle automation, ServiceNow intake, client provisioning readiness, SLA performance, escalation management, audit evidence, and operational improvements.
This role is designed to support Ensemble’s IAM transformation priorities: standardizing provisioning processes, expanding automation, improving client onboarding readiness, strengthening governance, and giving leadership reliable visibility into IAM service performance.
Strategic Purpose for Ensemble
This role provides the leadership bridge between strategic IAM engineering and operational access delivery. The position is accountable for ensuring that identity platforms, intake workflows, provisioning standards, and client onboarding processes work together as one integrated service model.
- Improve consistency across client provisioning models and reduce one-off access fulfillment processes.
- Advance automation for joiner, mover, leaver, transfer, rehire, contractor, and termination workflows.
- Strengthen audit readiness through standardized evidence, entitlement reconciliation, and access governance support.
- Increase leadership visibility through dashboards, SLA trends, backlog reporting, and risk-based recommendations.
- Protect Ensemble and client operations by improving access accuracy, timeliness, least-privilege alignment, and escalation discipline.
Primary Responsibilities
IAM Engineering Leadership
- Lead engineering ownership and operational support of IAM platforms, including SailPoint/IGA, directory services, cloud identity, access request workflows, lifecycle automation, and related identity technologies.
- Develop and execute the IAM engineering roadmap aligned to Ensemble’s security, automation, client onboarding, compliance, and operational efficiency goals.
- Oversee design, configuration, testing, deployment, support, and continuous improvement of identity profiles, lifecycle states, roles, access profiles, entitlements, connectors, workflows, transforms, provisioning logic, and reporting.
- Establish and maintain technical standards, runbooks, SOPs, configuration documentation, support playbooks, and operational readiness practices.
- Ensure IAM platforms are reliable, scalable, secure, auditable, and aligned to Technology Security architecture and operational expectations.
Identity Lifecycle & Automation
- Lead engineering standards for joiner, mover, leaver, transfer, rehire, leave, contractor, and termination workflows.
- Partner with HR/HCM, ServiceNow, directory, cloud, application, and client-facing teams to improve authoritative data quality, lifecycle triggers, access accuracy, and deprovisioning timeliness.
- Drive automation opportunities that reduce manual work, improve SLA performance, strengthen controls, and create measurable time and cost savings.
- Advance role-based access control, standard entitlement models, identity governance maturity, and reusable patterns across enterprise and client access environments.
- Maintain an automation and technical debt backlog with owners, business value, risk impact, and target delivery milestones.
Client Onboarding & Readiness
- Partner with Implementation, Client Success, Operations, Application Owners, and client stakeholders to define access requirements early in the client onboarding lifecycle.
- Ensure client provisioning requirements, entitlement files, role mappings, access dependencies, test users, escalation contacts, and go-live readiness criteria are documented and tracked.
- Support readiness checkpoints and post-go-live stabilization activities to reduce access delays, rework, and operational disruption.
- Identify client-specific process variation and lead standardization opportunities that can scale across Ensemble’s client portfolio.
- Escalate readiness risks with clear business impact, ownership, resolution path, and decision requirements.
- documented, time-bound, assigned to owners, and communicated with appropriate leadership visibility.
Governance, Risk & Compliance
- Ensure IAM engineering and provisioning processes support Ensemble audit, regulatory, security, and internal control expectations.
- Partner with GRC, Internal Audit, Cybersecurity, application owners, and client stakeholders to support access reviews, audit evidence, entitlement reconciliation, control testing, and compliance reporting.
- Promote separation of duties, least privilege, standard access patterns, and access certification readiness.
- Maintain documentation for policies, SOPs, RACI models, readiness checklists, operational evidence packages, and exception approvals.
- Identify risks in provisioning workflows and recommend remediation plans with clear ownership, timeline, and measurable control impact.
People Leadership
- Lead, coach, and develop a high-performing IAM engineering and client provisioning team.
- Set clear goals, expectations, KPIs, development plans, and accountability rhythms for team members.
- Foster a culture of ownership, transparency, continuous improvement, customer service, innovation, and operational excellence.
- Provide leadership-ready updates on performance, risks, accomplishments, staffing needs, automation wins, and strategic priorities.
- Build cross-functional partnerships that improve trust, reduce friction, and enable scalable client onboarding and identity operations.
Required Qualifications
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Engineering, or related field, or equivalent experience.
- 7+ years of Identity & Access Management, cybersecurity, access provisioning, identity operations, or related technology experience.
- 3+ years of people leadership experience leading IAM engineering, provisioning, security operations, client delivery, or technical support teams.
- Experience with IAM transformation, lifecycle management, access governance, provisioning workflows, escalation management, metrics, and operational reporting.
- Strong executive communication skills with the ability to translate technical and operational issues into leadership-ready risk, impact, options, and action plans.
Preferred Qualifications
- Experience with SailPoint or comparable Identity Governance and Administration platforms.
- Experience with ServiceNow access request workflows, queue management, dashboards, catalog items, approvals, and operational reporting.
- Experience with Active Directory, Microsoft Entra ID, SSO, federation, MFA, privileged access, APIs, connectors, workflow automation, or identity lifecycle integrations.
- Healthcare, revenue cycle, client implementation, managed services, or highly regulated industry experience.
- Master's degree, CISSP, CISM, Security+, ITIL, PMP, or relevant IAM/vendor certification preferred.
Core Competencies
- Strategic IAM leadership and roadmap execution.
- Operational excellence and process standardization.
- Client-focused service delivery and readiness management.
- Automation-first mindset and continuous improvement discipline.
- Risk-based decision-making and audit readiness.
- Data-driven performance management and executive storytelling.
- Coaching, team development, accountability, and cross-functional influence.
This position pays between $92,400 – $138,600 based on experience
Must be inquisitive and demonstrate openness to innovation including AI to explore better processes and ways to alleviate friction and improve patient and client experiences.
This is a remote position; however, candidates must be willing and able to travel to and work onsite at client, temporary, or corporate office locations as business needs require.
#LI-SA1
#LI-REMOTE
Join an award-winning company
Five-time winner of “Best in KLAS” 2020-2022, 2024-2025
Black Book Research's Top Revenue Cycle Management Outsourcing Solution 2021-2024
22 Healthcare Financial Management Association (HFMA) MAP Awards for High Performance in Revenue Cycle 2019-2024
Leader in Everest Group's RCM Operations PEAK Matrix Assessment 2024
Clarivate Healthcare Business Insights (HBI) Revenue Cycle Awards for strong performance 2020, 2022-2023
Energage Top Workplaces USA 2022-2024
Fortune Media Best Workplaces in Healthcare 2024
Monster Top Workplace for Remote Work 2024
Great Place to Work certified 2023-2024
Innovation
Work-Life Flexibility
Leadership
Purpose + Values
Bottom line, we believe in empowering people and giving them the tools and resources needed to thrive. A few of those include:
Associate Benefits – We offer a comprehensive benefits package designed to support the physical, emotional, and financial health of you and your family, including healthcare, time off, retirement, and well-being programs.
Our Culture – Ensemble is a place where associates can do their best work and be their best selves. We put people first, last and always. Our culture is rooted in collaboration, growth, and innovation.
Growth – We invest in your professional development. Each associate will earn a professional certification relevant to their field and can obtain tuition reimbursement.
Recognition – We offer quarterly and annual incentive programs for all employees who go beyond and keep raising the bar for themselves and the company.
Ensemble is an equal employment opportunity employer. It is our policy not to discriminate against any applicant or employee based on race, color, sex, sexual orientation, gender, gender identity, religion, national origin, age, disability, military or veteran status, genetic information or any other basis protected by applicable federal, state, or local laws. Ensemble also prohibits harassment of applicants or employees based on any of these protected categories.
Ensemble provides reasonable accommodations to qualified individuals with disabilities in accordance with the Americans with Disabilities Act and applicable state and local law. If you require accommodation in the application process, please contact [email protected].
This posting addresses state specific requirements to provide pay transparency. Compensation decisions consider many job-related factors, including but not limited to geographic location; knowledge; skills; relevant experience; education; licensure; internal equity; time in position. A candidate entry rate of pay does not typically fall at the minimum or maximum of the role’s range.