Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Principal IAM Engineer role.
Rezi rewrites your resume against Lantern's job description. Free.

Tailor your resume to this Principal IAM Engineer role.
Rezi rewrites your resume against Lantern's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Principal IAM Engineer posting at Lantern — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Principal IAM Engineer posting at Lantern — free, in seconds.
About the Role
This Principal IAM Engineer is a senior-level, individual-contributor role and the technical authority for identity at Lantern. You will own the identity control plane end to end, determining who can reach PHI and under what conditions. You will set the identity standard, build the automation behind it, and hold the verification bar that other teams operate against. You will report to the CISO and partner closely with our IAM engineer and with the platform, cloud, and service delivery teams. This is a hands-on principal seat with a clear path to expand into a leadership role as the identity function grows. Our security philosophy is open by default, secure by design, helping the business move fast, safely.
Responsibilities
- Own the identity lifecycle: joiner, mover, and leaver provisioning and deprovisioning, automated from role- and attribute-based models (RBAC/ABAC), with deprovisioning verified against an entitlement inventory.
- Own access management, including Conditional Access, phishing-resistant MFA, and privileged access on a Zero Trust model, with least-privilege by default, just-in-time (JIT) elevation, and enforcement confirmed on every access path.
- Own directory and federation across Entra ID, single sign-on, SAML, OIDC, and OAuth2.
- Own secrets and non-human identity, including API keys, service accounts, and workload identity, and maintain an owner registry for them.
- Own key access governance and separation of duties in a model where another team operates the key management system.
- Own identity automation and identity-as-code, building lifecycle and access controls as reviewable, version-controlled infrastructure (Terraform and policy-as-code).
- Own the identity-verification standard the service desk follows for password resets, MFA resets, and device enrollment.
Requirements
- A minimum of 8 years in identity and access management, including principal- or staff-level ownership of an identity control plane.
- Deep Microsoft Entra ID engineering, including Conditional Access policy design, phishing-resistant MFA, single sign-on, and federation across SAML, OIDC, and OAuth2, and verifying that enforcement takes effect across every access path.
- Identity lifecycle automation across cloud, SaaS, and privileged systems, with role- and attribute-based provisioning (RBAC/ABAC) and deprovisioning verified against an entitlement inventory.
- Zero Trust identity design, including least-privilege, just-in-time (JIT) access, and risk-based or adaptive access controls.
- Identity governance and administration (IGA) platform engineering, including privileged access management.
- Automation and scripting (PowerShell, Python, or similar) to build lifecycle workflows and custom connectors.
- Identity-as-code and policy-as-code practice, using Terraform with source-controlled change management (for example, GitHub).
- Secrets and non-human identity (API keys, service accounts, workload identity), and maintaining an owner registry for them.
- Key access governance and separation of duties in a model where another team operates the key management system.
- The ability to act as the technical authority for a function without formal people-management authority, working directly to a CISO.
- Bachelor’s degree in a relevant field, or equivalent professional experience.
Skills
- Microsoft Entra ID engineering
- Conditional Access policy design
- Phishing-resistant MFA
- Single sign-on
- Federation (SAML, OIDC, OAuth2)
- Identity lifecycle automation
- RBAC/ABAC
- Zero Trust identity design
- Least-privilege access
- Just-in-time (JIT) access
- Risk-based access controls
- Adaptive access controls
- Identity governance and administration (IGA)
- Privileged access management (PAM)
- Automation
- Scripting (PowerShell, Python)
- Identity-as-code
- Policy-as-code
- Terraform
- Secrets management
- Non-human identity management
- API key management
- Service account management
- Workload identity management
- Key access governance
- Separation of duties
- Saviynt
- Azure PIM
- Keeper
- Passkeys
- FIDO2
- NIST SP 800-63 Rev. 4
Location
- NYC, NY
Work Type
- Hybrid
Experience Level
- Principal
- Staff
- 8+ years in identity and access management
Education Level
- Bachelor’s degree in a relevant field, or equivalent professional experience
- Microsoft Identity and Access Administrator certification
- CIMP certification
Salary/Compensations
- $175,000 - $225,000 annually
Benefits
- Medical Insurance
- Dental Insurance
- Vision Insurance
- Short & Long Term Disability
- Life Insurance
- 401k with company match
- Flexible Time Off
- Paid Parental Leave
- Annual bonus
About the Company
- Lantern is the specialty care platform connecting people with the best care when they need it most.
- Lantern curates a Network of Excellence comprised of the nation's top specialists for surgery, cancer care, infusions and more.
- Lantern delivers excellent care with significant cost savings to employers and their workforces.
- Lantern pairs members with a dedicated care team, including Care Advocates and nurses, for the entirety of their care journey.
- Lantern provides convenient access to specialists nationwide.
- Lantern is trusted by the nation's largest employers to deliver care to more than 6 million members across the country.
- Lantern operates in a regulated healthcare environment (HIPAA, HITRUST, SOC 2).
- Lantern handles protected health information at scale.
- Lantern is becoming an AI healthcare company, with AI adoption a top company priority.
Equal Opportunity
- Lantern does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits.