The Opportunity:
Manager, IAM Engineering & New Client Provisioning
Ensemble Health Partners | Identity & Access Management | Technology Security
Position Summary
The Manager, IAM Engineering & Client Provisioning is an Ensemble Health Partners Technology Security leadership role responsible for unifying IAM platform engineering with client access provisioning operations. This leader ensures Ensemble has secure, compliant, scalable, and measurable identity services across enterprise and client environments, with clear ownership for SailPoint/IGA maturity, lifecycle automation, ServiceNow intake, client provisioning readiness, SLA performance, escalation management, audit evidence, and operational improvements.
This role is designed to support Ensembles IAM transformation priorities: standardizing provisioning processes, expanding automation, improving client onboarding readiness, strengthening governance, and giving leadership reliable visibility into IAM service performance.
Strategic Purpose for EnsembleThis role provides the leadership bridge between strategic IAM engineering and operational access delivery. The position is accountable for ensuring that identity platforms, intake workflows, provisioning standards, and client onboarding processes work together as one integrated service model.
- Improve consistency across client provisioning models and reduce one-off access fulfillment processes.
- Advance automation for joiner, mover, leaver, transfer, rehire, contractor, and termination workflows.
- Strengthen audit readiness through standardized evidence, entitlement reconciliation, and access governance support.
- Increase leadership visibility through dashboards, SLA trends, backlog reporting, and risk-based recommendations.
- Protect Ensemble and client operations by improving access accuracy, timeliness, least-privilege alignment, and escalation discipline.
Primary Responsibilities
IAM Engineering Leadership- Lead engineering ownership and operational support of IAM platforms, including SailPoint/IGA, directory services, cloud identity, access request workflows, lifecycle automation, and related identity technologies.
- Develop and execute the IAM engineering roadmap aligned to Ensembles security, automation, client onboarding, compliance, and operational efficiency goals.
- Oversee design, configuration, testing, deployment, support, and continuous improvement of identity profiles, lifecycle states, roles, access profiles, entitlements, connectors, workflows, transforms, provisioning logic, and reporting.
- Establish and maintain technical standards, runbooks, SOPs, configuration documentation, support playbooks, and operational readiness practices.
- Ensure IAM platforms are reliable, scalable, secure, auditable, and aligned to Technology Security architecture and operational expectations.
Identity Lifecycle & Automation- Lead engineering standards for joiner, mover, leaver, transfer, rehire, leave, contractor, and termination workflows.
- Partner with HR/HCM, ServiceNow, directory, cloud, application, and client-facing teams to improve authoritative data quality, lifecycle triggers, access accuracy, and deprovisioning timeliness.
- Drive automation opportunities that reduce manual work, improve SLA performance, strengthen controls, and create measurable time and cost savings.
- Advance role-based access control, standard entitlement models, identity governance maturity, and reusable patterns across enterprise and client access environments.
- Maintain an automation and technical debt backlog with owners, business value, risk impact, and target delivery milestones.
Client Onboarding & Readiness- Partner with Implementation, Client Success, Operations, Application Owners, and client stakeholders to define access requirements early in the client onboarding lifecycle.
- Ensure client provisioning requirements, entitlement files, role mappings, access dependencies, test users, escalation contacts, and go-live readiness criteria are documented and tracked.
- Support readiness checkpoints and post-go-live stabilization activities to reduce access delays, rework, and operational disruption.
- Identify client-specific process variation and lead standardization opportunities that can scale across Ensembles client portfolio.
- Escalate readiness risks with clear business impact, ownership, resolution path, and decision requirements.
- documented, time-bound, assigned to owners, and communicated with appropriate leadership visibility.
Governance, Risk & Compliance- Ensure IAM engineering and provisioning processes support Ensemble audit, regulatory, security, and internal control expectations.
- Partner with GRC, Internal Audit, Cybersecurity, application owners, and client stakeholders to support access reviews, audit evidence, entitlement reconciliation, control testing, and compliance reporting.
- Promote separation of duties, least privilege, standard access patterns, and access certification readiness.
- Maintain documentation for policies, SOPs, RACI models, readiness checklists, operational evidence packages, and exception approvals.
- Identify risks in provisioning workflows and recommend remediation plans with clear ownership, timeline, and measurable control impact.
People Leadership- Lead, coach, and develop a high-performing IAM engineering and client provisioning team.
- Set clear goals, expectations, KPIs, development plans, and accountability rhythms for team members.
- Foster a culture of ownership, transparency, continuous improvement, customer service, innovation, and operational excellence.
- Provide leadership-ready updates on performance, risks, accomplishments, staffing needs, automation wins, and strategic priorities.
- Build cross-functional partnerships that improve trust, reduce friction, and enable scalable client onboarding and identity operations.
Required Qualifications- Bachelors degree in Information Technology, Cybersecurity, Computer Science, Engineering, or related field, or equivalent experience.
- 7+ years of Identity & Access Management, cybersecurity, access provisioning, identity operations, or related technology experience.
- 3+ years of people leadership experience leading IAM engineering, provisioning, security operations, client delivery, or technical support teams.
- Experience with IAM transformation, lifecycle management, access governance, provisioning workflows, escalation management, metrics, and operational reporting.
- Strong executive communication skills with the ability to translate technical and operational issues into leadership-ready risk, impact, options, and action plans.
Preferred Qualifications
- Experience with SailPoint or comparable Identity Governance and Administration platforms.
- Experience with ServiceNow access request workflows, queue management, dashboards, catalog items, approvals, and operational reporting.
- Experience with Active Directory, Microsoft Entra ID, SSO, federation, MFA, privileged access, APIs, connectors, workflow automation, or identity lifecycle integrations.
- Healthcare, revenue cycle, client implementation, managed services, or highly regulated industry experience.
- Masters degree, CISSP, CISM, Security+, ITIL, PMP, or relevant IAM/vendor certification preferred.
Core Competencies
- Strategic IAM leadership and roadmap execution.
- Operational excellence and process standardization.
- Client-focused service delivery and readiness management.
- Automation-first mindset and continuous improvement discipline.
- Risk-based decision-making and audit readiness.
- Data-driven performance management and executive storytelling.
- Coaching, team development, accountability, and cross-functional influence.
This position pays between $92,400 $138,600 based on experience
Must be inquisitive and demonstrate openness to innovation including AI to explore better processes and ways to alleviate friction and improve patient and client experiences.
This is a remote position; however, candidates must be willing and able to travel to and work onsite at client, temporary, or corporate office locations as business needs require.
#LI-SA1
#LI-REMOTE