667,602open jobs
39,042companies
100,809added this week
Browse all
Salary
$106k – $228k per year (Estimated)
Location
Remote/Hybrid (Dallas, United States)
Seniority
Principal · 8+ years exp
Overview
Company
Impact
Profile match
Carrum Health is a California company founded in 2014 that connects employers with centres of excellence for surgery and cancer care. Its platform bundles payments and steers patients to high-quality providers. The company works with large self-insured employers.

About Lantern

Lantern is the specialty care platform connecting people with the best care when they need it most. By curating a Network of Excellence comprised of the nation's top specialists for surgery, cancer care, infusions and more, Lantern delivers excellent care with significant cost savings to employers and their workforces. Lantern also pairs members with a dedicated care team, including Care Advocates and nurses, for the entirety of their care journey, helping them get back to good health, back to their families and back to work. With convenient access to specialists nationwide, Lantern means quality care is within driving distance for most. Lantern is trusted by the nation's largest employers to deliver care to more than 6 million members across the country. Learn more about us at lanterncare.com. 

Lantern is the specialty care platform, connecting people with high-quality, affordable specialty care close to home. We operate in a regulated healthcare environment (HIPAA, HITRUST, SOC 2), we handle protected health information at scale, and we are becoming an AI healthcare company, with AI adoption a top company priority.

This Principal IAM Engineer is a senior level, individual-contributor role and the technical authority for identity at Lantern. In an organization where the security perimeter is effectively identity, you will own the identity control plane end to end, and you will determine who can reach PHI and under what conditions. You will set the identity standard, build the automation behind it, and hold the verification bar that other teams operate against.

You will report to the CISO and partner closely with our IAM engineer and with the platform, cloud, and service delivery teams that execute alongside you. This is a hands-on principal seat, not a people-management role today, with a clear path to expand into a leadership role as the identity function grows.

Our security philosophy is open by default, secure by design. Security exists to help the business move fast, safely, and the default answer is “yes, safely,” because guardrails are built into the platform, pipelines, and tooling rather than enforced by someone saying no. Gates exist only where risk genuinely warrants them, and even then they are automated, fast, and transparent.

Location: Hybrid - at least 3 days/wk in our Dallas, TX offices

Responsibilities:

  • Own the identity lifecycle: joiner, mover, and leaver provisioning and deprovisioning, automated from role- and attribute-based models (RBAC/ABAC), with deprovisioning verified against an entitlement inventory rather than assumed.
  • Own access management, including Conditional Access, phishing-resistant MFA, and privileged access on a Zero Trust model, with least-privilege by default, just-in-time (JIT) elevation, and enforcement confirmed on every access path rather than only saved.
  • Own directory and federation across Entra ID, single sign-on, SAML, OIDC, and OAuth2.
  • Own secrets and non-human identity, including API keys, service accounts, and workload identity, and maintain an owner registry for them.
  • Own key access governance and separation of duties in a model where another team operates the key management system.
  • Own identity automation and identity-as-code, building lifecycle and access controls as reviewable, version-controlled infrastructure (Terraform and policy-as-code) rather than manual configuration.
  • Own the identity-verification standard the service desk follows for password resets, MFA resets, and device enrollment. This is a hands-on control point, because helpdesk-initiated resets are a leading account-takeover vector.

Key Deliverables in Your First Year:

  • Conditional Access enforced by default on PHI-facing applications, with enforcement verified.
  • Automated joiner, mover, and leaver provisioning and deprovisioning that meets its SLA every time.
  • A secrets golden path, with vaulted secrets, none in code, and a populated key-to-owner registry.
  • Strong, phishing-resistant MFA coverage on privileged accounts.
  • Documented runbooks and depth across the control plane, so no critical control depends on a single person.

How You Will Work:

You will set standards that partner teams execute. Service Delivery performs provisioning tasks and resets against the verification bar you own. Cloud Engineering carries cloud access, workload identity, and key-management operations, with key access governed by you. HR events are the sole trigger for lifecycle changes. The Governance, Risk & Compliance team independently attests to the entitlements you produce, and access certification deliberately sits outside this role so that the team reviewing access is not the team granting it. Holding those boundaries cleanly is central to the job.

Requirements:

  • Eight or more years in identity and access management, including principal- or staff-level ownership of an identity control plane.
  • Deep Microsoft Entra ID engineering, including Conditional Access policy design, phishing-resistant MFA, single sign-on, and federation across SAML, OIDC, and OAuth2, and verifying that enforcement takes effect across every access path, not only the expected one.
  • Identity lifecycle automation across cloud, SaaS, and privileged systems, with role- and attribute-based provisioning (RBAC/ABAC) and deprovisioning verified against an entitlement inventory.
  • Zero Trust identity design, including least-privilege, just-in-time (JIT) access, and risk-based or adaptive access controls.
  • Identity governance and administration (IGA) platform engineering, including privileged access management.
  • Automation and scripting (PowerShell, Python, or similar) to build lifecycle workflows and custom connectors.
  • Identity-as-code and policy-as-code practice, using Terraform with source-controlled change management (for example, GitHub).
  • Secrets and non-human identity (API keys, service accounts, workload identity), and maintaining an owner registry for them.
  • Key access governance and separation of duties in a model where another team operates the key management system.
  • The ability to act as the technical authority for a function without formal people-management authority, working directly to a CISO.
  • Bachelor’s degree in a relevant field, or equivalent professional experience.

Strong Candidates Will:

  • Healthcare or another regulated environment where identity controls gate access to PHI.
  • Hands-on Saviynt with PAM, Azure PIM, and Keeper, or transferable depth in comparable platforms.
  • Experience remediating a Conditional Access enforcement gap or a deprovisioning failure, and making the structural change that prevented recurrence.
  • Passkeys and FIDO2, or phishing-resistant authenticator experience, aligned with NIST SP 800-63 Rev. 4.
  • Experience growing a technical scope into a broader leadership remit.
  • Microsoft Identity and Access Administrator certification, CIMP, or equivalent.

Who Thrives in This Role:

  • Verified enforcement. You do not consider a control done until you have seen it working on every path.
  • Automation bias. You remove the manual step rather than documenting it more carefully.
  • Structural fixes. You solve the class of failure, not the instance.
  • Boundary clarity. You hold the standard with partner teams without taking over their execution.
  • Governance respect. You keep access certification independent rather than absorbing it.

Benefits

  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • Short & Long Term Disability
  • Life Insurance
  • 401k with company match
  • Flexible Time Off
  • Paid Parental Leave

About You:

  • You use LOGIC in your decision making and understand that progress is critical to making change. You focus on the execution of your content while balancing a fast-paced environment and you take the time to celebrate both the small & big wins. 
  • INCLUSION is a core tenant of your personal beliefs. A diverse and inclusive environment is incredibly important to you. You understand and desire to be a part of a diverse team with different experiences and perspectives & you cherish the differences in each individual that you interact with.
  • You have the GRIT, drive and ambition to tackle big problems. Big problems require big ideas and a team that supports new ideas. 
  • You care deeply for your customers are driven to keep HUMANITY in all decisions. Your customers aren’t just the individuals using your product. They are the driving factor in your motivation to make a change.
  • Integrity guides you in life. Focusing on the TRUTH vs. giving people the answers they want to hear. 
  • You thrive in a Team Environment. Collaboration is key in innovation and creating change.

These pillars of LIGHT are a reminder to our team that we are making a difference by providing guidance and support in navigating the often complex and confusing landscape of healthcare. We hope that through this  LIGHT, individuals can find their way to the best care, resources, and support they need to get back to life. 

If this sounds like you, we would love to connect to speak further about career opportunities at Lantern.

Please apply to our role & someone from our Talent Acquisition Team will reach out to help you navigate our interview process.

Lantern does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
667,602 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Dallas
$26k – $54k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Mumbai
PowerShell
AI/ML
Copilot
DevOps
Azure
Cybersecurity
Microsoft Defender
Microsoft Entra ID
Management
Power Automate
Power Apps
Microsoft Teams
OneDrive
SharePoint
Apply
In office • 3+ years exp • Bengaluru
Python
AI/ML
AI Agents
NLP
LLM
RAG
BERT
DevOps
GCP
Azure
AWS
Cybersecurity
HIPAA
Apply
$40k – $79k per year (Estimated) • In office • Internship • Bachelor's Degree • Singapore
Python
Apply
Intern 1 day ago
$40k per year • In office • Internship • Toronto
Python
SQL
Analytics
Power BI
Apply
DevOps Specialist 1 day ago
$15k – $30k per year (Estimated) • Remote • 2+ years exp • Bachelor's Degree • Moscow
Python
DevOps
OpenShift
Prometheus
CI/CD
Jenkins
Kubernetes
Nginx
Grafana
TeamCity
Bitbucket
GitLab
Apply
$88k – $165k per year (Estimated) • Remote/Hybrid • 5+ years exp • Bachelor's Degree • Dallas
Management
Monday.com
Microsoft Project
Jira
Outlook
Apply
$40k – $48k per year • In office • 1+ year exp • High School Diploma • Dallas
Apply
$128k – $228k per year (Estimated) • Remote/Hybrid • 5+ years exp • New York
SQL
Apex
AI/ML
AI Agents
Apply
$100k – $194k per year (Estimated) • Remote/Hybrid • 5+ years exp • Dallas
Python
SQL
Databases
Databricks
MS SQL
AI/ML
Spark
Interpretability
DevOps
Terraform
GCP
Azure
AWS
Analytics
Power BI
Apply
$99k – $192k per year (Estimated) • Remote/Hybrid • 4+ years exp • Bachelor's Degree • Dallas
DevOps
Terraform
GCP
Azure DevOps
GitHub Actions
Azure
CI/CD
AWS
Docker
Kubernetes
Azure AKS
Cybersecurity
SOC 2
HIPAA
Management
Agile
Apply
$44k – $94k per year (Estimated) • In office • Full-Time • 2+ years exp • Bachelor's Degree • Dallas
Analytics
Power BI
Apply
$74k – $150k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Chicago • Phoenix • Dallas • Houston • Wichita
AI/ML
Copilot
ChatGPT
LLM
OpenAI
Cybersecurity
GDPR
Analytics
Power BI
A/B Testing
Marketing
Salesforce
Google Ads
Marketo
LinkedIn
Reddit
Apply
$70k – $141k per year (Estimated) • In office • Full-Time • Phoenix • Dallas
DevOps
Rest API
Apply
$113k – $224k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Dallas
Python
SQL
Python
pySpark
Databases
Azure SQL Database
Microsoft Fabric
AI/ML
Spark
DevOps
Terraform
Azure DevOps
Azure
CI/CD
Analytics
Informatica
Azure Data Factory
Apply
In office • Full-Time • 2+ years exp • Bachelor's Degree • Dallas
Apply
See all jobs
This is one of many
667,602 more open roles from verified company boards, updated every day.