Full Job Description
Overview
How you can make a difference
Every member who logs into HealthEquity trusts us to recognize them instantly and protect them completely — across 16M+ accounts and a login experience we're actively reinventing. This team has already proven what that looks like in practice: passwordless login is now the default experience for millions of members, with adoption running ahead of industry benchmarks and login time cut by nearly 80%. It's not just a UX win — passkeys close off the attack vector behind most account takeover attempts before it gets a foothold, and it's a big part of why HealthEquity's fraud rate sits well below industry peers.
You'll lead the engineering organization responsible for building on that: two identity engineering PODs plus a global support team, owning everything from the identity server and core auth APIs to the passkey and account recovery experiences members interact with directly. The mandate goes beyond running what already works — it's unifying a fragmented login experience into one, extending strong identity to members who've never had an account, and pushing past passwordless into whatever comes next in frictionless, phishing-resistant authentication. You'll own the roadmap, the vendor and staffing strategy, and the architecture — with real latitude to shape where this platform goes next, not just inherit what's already running.
What you’ll be doing
Build on a proven foundation
• Own delivery of the identity platform's roadmap — unifying the team's remaining login experiences into one, extending secure self-service account recovery across web and mobile, and bringing verified identity to members who don't yet have an account — all in service of a single, unified next-generation app experience
• Keep the systems members already trust running flawlessly: production reliability, monitoring, and continuous hardening of the identity platform at scale
Push the identity frontier
• Go beyond passwordless — explore and prototype what's next in phishing-resistant, low-friction authentication, and make the case for where the platform should go
• Build with AI-native engineering practices as a first-class part of how the team designs, ships, and tests — not a side experiment, but how the team moves faster than a traditional identity org can
• Own the platform's next architectural chapter: identity server/CIAM strategy, and resiliency planning for the third-party dependencies the platform relies on
Lead a large, distributed engineering organization
• Lead two identity engineering PODs plus a global (onshore and offshore) support function operating around the clock
• Build and grow a blended team of full-time engineers and delivery partners, with a clear strategy for where to build in-house capability over time
• Identify and develop your strongest engineers into bigger roles as the team's scope grows
Own the vendor and architecture landscape
• Own key identity and authentication vendor relationships, and bring a clear point of view on build-vs-buy as the CIAM and IDV vendor landscape evolves
• Represent identity engineering in cross-functional planning with fraud, product security, member services, and mobile/UX — translating business priorities into a resourced, defensible plan
What you will need to be successful
• 10+ years in software/platform engineering with progressive people leadership, including experience leading multiple teams or engineering PODs concurrently, ideally across a blended onshore/offshore organization
• Direct, hands-on experience with consumer identity and access management (CIAM): identity servers, OIDC/OAuth2, SSO, JWT-based auth, and passwordless/passkey (FIDO2/WebAuthn) technologies
• A track record owning a production identity or API platform at real scale — not just a feature team, but the operational and architectural discipline that comes with being the system everything else depends on
• Genuine fluency with AI-assisted software development — someone who wants their team building with AI tooling as a core practice, not just talking about it
• Experience making vendor and architecture decisions under real-world constraints, in a highly regulated, high-trust environment (healthcare, fintech, or similar)
• A frontier mindset: someone who's genuinely excited about where authentication and identity trust are headed, and wants to help define it — not just maintain what's already been built
#LI-Remote
This is a remote position.
Salary Range$144000.00 To $220000.00 / year
Benefits & Perks
The actual compensation offer is determined based on job-related knowledge, education, skills, experience, and work location. This position will be eligible for performance-based incentives and restricted stock units as part of the total compensation package, in addition to a full range of benefits including:
• Medical, dental, and vision
• HSA contribution and match
• Dependent care FSA match
• Uncapped paid time off
• Paid parental leave
• 401(k) match
• Personal and healthcare financial literacy programs
• Ongoing education & tuition assistance
• Gym and fitness reimbursement
• Wellness program incentives
Onboarding & Travel
This is a remote role, with an in-person onboarding training component. New team members must participate in Trailhead, HealthEquity’s immersive onboarding experience Trailhead is designed to foster meaningful connections, support your integration into the organization, and equip you with a strong understanding of our business. Trailhead participation is a key expectation of this role. Trailhead is held onsite at our headquarters once per quarter. HealthEquity covers all required travel and accommodations.
This role may begin with a virtual, self-paced onboarding experience, followed by a mandatory onsite Trailhead session at a later date.