Senior IAM Automation Engineer
Listed on 2026-02-28
-
IT/Tech
Cybersecurity
Vaco has partnered with an Arizona-based healthcare organization as they expand and mature their Identity and Access Management function as part of a broader five-year IAM strategy. This team is centralizing identity governance, automation, and access controls to improve security posture, compliance, and operational efficiency across the enterprise.
This Senior IAM Automation Engineer will report directly into IAM leadership and serve as a key technical driver for automation, integration, and access governance initiatives. The environment includes Entra , Defender, Intune, RBAC governance, and advanced Power Shell automation. The organization plans to implement Cyber Ark in the near future, so exposure to privileged access management is a plus.
The role is open to Arizona-based remote candidates to start, with the potential to expand nationwide if needed. Onsite expectations are minimal, approximately one day per month.
What You’ll Be DoingDesign and build advanced Power Shell automation to streamline identity lifecycle management and reduce manual provisioning tasks
Support and enhance Entra , Defender, Intune, and hybrid identity environments
Implement and refine RBAC models to ensure secure, scalable access governance
Lead automation efforts for onboarding, offboarding, and access modification workflows
Integrate IAM systems with enterprise platforms such as Workday and Service Now
Support the rollout of new IAM tooling and contribute to future Cyber Ark implementation efforts
Partner with IT and business teams to transition decentralized SaaS access management into a centralized IAM process
Monitor IAM risks, audit findings, and performance metrics, providing visibility to leadership
Contribute to IAM policies, procedures, documentation, and long-term roadmap initiatives
Identify inefficiencies and proactively recommend automation and process improvements
6 or more years of experience in Identity and Access Management, systems administration, or related security operations roles
Advanced Power Shell scripting and automation experience
Strong hands‑on experience with Entra , Defender, Intune, and hybrid identity environments
Experience implementing and managing RBAC frameworks
Experience integrating IAM systems with enterprise applications such as Workday and Service Now
Familiarity with MFA, SSO, audit controls, and identity lifecycle management
Ability to operate independently with high accountability and ownership
Bachelor’s degree in Computer Science, IT, or related field
Experience with Cyber Ark or other Privileged Access Management solutions
Experience working in healthcare or other regulated industries
Object‑oriented programming experience
Microsoft or IAM‑related certifications such as Azure Administrator, Identity and Access Administrator, or Security+
Salary range up to $150,000 annually, depending on experience
Full‑time employment with benefits package available
If you are a self‑driven IAM professional who thrives in automation‑focused environments and wants to help shape the long‑term identity strategy of a growing organization, we would welcome the opportunity to connect.
Vaco by Highspring values a diverse workplace and strongly encourages women, people of color, LGBTQ+ individuals, people with disabilities, members of ethnic minorities, foreign‑born residents, and veterans to apply.
EEO NoticeVaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law.
Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).