Sanford Health

Senior Identity System Engineer

Sanford Health$83K — $137K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science or related field, or Associate's Degree plus 3 years of experience.
  • 3-4 years of experience in Active Directory, Domain Services, Hybrid Identities, & Entra ID.
  • Experience implementing SSO/MFA workflows using SAML 2.0 and/or OIDC.
  • Strong background in maintaining Public Key Infrastructure (PKI).
  • Knowledge of Identity Lifecycle & Access Governance workflows.

Responsibilities

  • Design and optimize enterprise identity infrastructure across on-premises and cloud environments.
  • Lead the architecture of domain topologies and global replication.
  • Drive adoption of modern authentication protocols such as Kerberos and OAuth.
  • Integrate systems through API calls (REST, SOAP, JSON).
  • Manage enterprise PKI and certificate lifecycles.
  • Enforce security baselines via Group Policy to ensure compliance.
  • Mentor junior engineers and support team knowledge growth.

Benefits

  • Opportunities for professional development and continuous learning.
  • Flexibility with remote work arrangements depending on projects.
  • Collaboration with cross-functional IT and security teams.
  • Access to advanced technology and tools in identity management.
  • Participation in innovation-focused initiatives.
Full Job Description


Work Shift:
8 Hours - Day Shifts (United States of America)
Scheduled Weekly Hours:
40
Compensation:
Salary Range: $40.00 - $66.00Pay starts at $40 and increases according to years of applicable experience.
Union Position:
No
Department Details
Saviynt experience highly preferred.

Summary
The Senior Identity Systems Engineer is responsible for designing, implementing, and securing enterprise identity and access management infrastructure that enables reliable authentication, authorization, and access management across hybrid environments. Engineers in this family ensure that users, systems, and applications are authenticated, authorized, and protected in alignment with security standards, regulatory requirements, and business needs.

Job Description
The Senior Identity Systems Engineer is an advanced technical role responsible for designing, implementing, and optimizing enterprise identity infrastructure across on-premises and cloud environments. This position leads the architecture of domain topologies, forest structures, and global replication, while ensuring hybrid identity solutions provide seamless sign-in experiences across platforms. The engineer drives the adoption of modern authentication protocols such as Kerberos, OAuth, OpenID Connect, and SAML, and leads initiatives around just-in-time access, privileged session monitoring, and automated access governance. Responsibilities include integrating systems through API calls (REST, SOAP, JSON), managing enterprise PKI and certificate lifecycles, enforcing security baselines via Group Policy, and ensuring compliance with regulatory frameworks such as SOX, HIPAA, and GDPR. In addition to technical execution, the Senior Identity Systems Engineer plays a mentoring role, guiding junior engineers in best practices and fostering team knowledge growth. With a focus on innovation and automation, this role ensures that the organization's identity services remain secure, resilient, and aligned with modern zero trust principles and evolving business needs.

This role requires deep technical expertise in Active Directory, Entra ID, authentication protocols, Identity Governance Administration (IGA), Privileged Access Management (PAM) and PKI with a strong focus on information security, compliance, strong problem-solving skills, a security-first mindset, and least-privilege enforcement. The Senior Identity Systems Engineer ensures the organization's identity platforms are resilient, scalable, and secure to support business operations and protect sensitive data. The Senior Identity Systems Engineer will work closely with cross-functional IT, application, and security teams to ensure alignment with business objectives, regulatory requirements, and industry best practices.

Qualifications
Bachelor's degree required, in lieu of education, leadership may consider an Associate's Degree plus 3 years of applicable experience in computer science or related field.

Minimum of 3-4 years applicable work experience required. Including but not limited to:
• Supporting Active Directory, Domain Services, Hybrid Identities, & Entra ID
• Implementing SSO/MFA workflows using SAML 2.0 and/or OIDC
• Maintaining Public Key Infrastructure (PKI)
• Supporting Identity Lifecycle & Access Governance workflows and technical integrations
• Implementation of information security standards and procedures including HIPAA and PCI

Security Certifications (CISSP, CISA, CISM, Security+, CEH, etc.) are highly desired.

About Sanford Health

Sanford Health is a non-profit, integrated health care system headquartered in Sioux Falls, South Dakota. It is the largest rural, not-for-profit health care system in the nation with locations in 26 states and nine countries. Sanford Health's 48,000 employees, including 1,400 physicians, make it the largest employer in the Dakotas. Sanford Health provides care to patients through a network of hospitals, clinics, long-term care facilities, and other health care services. The organization's mission is to improve the human condition through exceptional care, innovation, and discovery.
Learn more about Sanford Health
Size
1,409 employees
Industry
NASDAQ

Similar Jobs

More Jobs at Sanford Health

More Information Technology Jobs

Find similar Senior Identity System Engineer jobs: