Qualifications
Responsibilities
Benefits
How you can make a difference
HealthEquity is rebuilding how 17 million members, their employers, brokers and partners sign in and prove who they are. The Consumer Identity team owns that platform: passwordless sign-in with passkeys, identity verification, non-member authentication for employers and partners, retail enrollment, and the identity services behind our next-generation mobile app. We are in the middle of the largest change to member authentication in the company's history and are planning the next one. You will build the systems that decide whether a login is a member or an attacker. You will do it in a small senior team that owns the full stack and ships to production often. The team is led by a director who helped write the identity standards this industry uses and has shipped passkeys at consumer scale. AI-assisted development is part of how we work.
What you’ll be doing
- Own technical decisions and lead design across the customer identity stack: authentication, authorization, session management, and the OIDC, OAuth2 and SAML flows for member-facing applications.
- Build the services behind them end to end, including passkey (FIDO2 and WebAuthn) registration and sign-in, step-up and out-of-band verification, and the APIs that connect our member platforms.
- Own authentication journeys on our customer identity platform, from design through production telemetry, including identity verification with document and selfie checks and phone-based risk signals.
- Set the standards for secure credential handling and token and session lifecycle, and partner with Information Security and Compliance on the regulatory requirements that come with financial and health data.
- Extend non-member authentication for employers, brokers, agents and partners, including corporate-email and phone factors, and the admin tooling around them.
- Build the identity layer for the next-generation mobile app: token exchange, session and device trust, and the GraphQL and REST endpoints it consumes.
- Lead parts of the platform consolidation: evaluating and implementing an open-source CIAM stack, retiring legacy federation, and designing the migration paths for member credentials.
- Work with the fraud team to wire risk signals into the login path: phone intelligence, device and behavioral signals, bank account verification, and the rules that act on them.
- Treat security findings as engineering work: triage SCA and SAST results, fix dependency and base-image vulnerabilities, keep PII out of logs, and build the checks that stop regressions.
- Apply agentic development practices as a normal part of the job: author and maintain the AI agent skills and workflows the team uses for code review, testing and secure implementation, use agentic coding tools for implementation and remediation, and bring the judgment to verify what they produce. Help the team set the pattern for how identity engineering uses these tools well.
- Instrument what you ship. Dashboards, alerts and queries are part of done, and you will use them to find the next problem before members report it.
- Write things down. Architecture notes, runbooks and knowledge-base pages are how this team scales; your work should be understandable by the engineer who picks it up after you.
What you will need to be successful
- Seven or more years of software engineering, with at least three on authentication, identity or security-sensitive systems in production.
- Deep, hands-on knowledge of OIDC, OAuth2, SAML, FIDO2 and WebAuthn, including the failure modes and the attacks against them.
- Strong TypeScript and Node (we use NestJS) and working C# and .NET; you can read and change both codebases and choose the right one for a service.
- Experience with at least one customer identity platform at scale (for example Transmit Security, Ory, Ping, Duende IdentityServer, Auth0 or Okta), and an informed view on build versus buy.
- Cloud-native delivery on Azure or an equivalent: Kubernetes and Helm, API gateways, key vaults, managed identities, and CI/CD pipelines you have written yourself.
- Comfort with GraphQL and REST API design, SQL and Postgres, and event-driven integration.
- Daily fluency with AI-assisted development tools, hands-on experience building or orchestrating AI agents in day-to-day development, and a track record of using them to raise quality and speed, not just output.
- Security engineering habits: threat modeling, secure defaults, dependency hygiene, and the ability to explain a vulnerability and its fix to a non-engineer.
- Clear written communication. You will work with product, fraud operations, member services and vendors, often in writing and often across time zones.
Nice to have
- Identity verification and fraud integrations: phone risk, document and selfie IDV, bank account verification, call-center voice risk.
- Mobile authentication: app attestation, device binding, biometric unlock, deep links and app-to-web handoff.
- Regulated-industry experience: healthcare, benefits, banking or fintech, with HIPAA or PCI exposure.
- Observability with Dynatrace and analytics with Databricks.
- Experience migrating credentials or users between identity systems without downtime.
The problems you will own
- A member whose phone number cannot be trusted and who declines a selfie check has no digital path today. Design the one that should exist, with its abuse case, and ship it.
- Employers, brokers and partners sign in to manage benefits for thousands of people each. Many have no phone on file and some have no email we control. Build authentication for them that is strong without becoming a help-desk queue.
- Retail enrollment matches a new customer to records we already hold. Ambiguous matches are the difference between a customer and an abandoned form. Raise the match rate without raising fraud.
- Our next-generation mobile app needs a token exchange, session model and device trust that work across two legacy platforms during a multi-year migration. Make it boring.
- Identity verification is moving from documents and selfies toward mobile driver's licenses and verifiable credentials. Help decide when we move and build the first integration.
Location: US-Remote. Travel: occasional, to Draper, Utah.
#LI-Remote
This is a remote position.
Salary Range$144000.00 To $237500.00 / year Benefits & PerksThe actual compensation offer is determined based on job-related knowledge, education, skills, experience, and work location. This position will be eligible for performance-based incentives and restricted stock units as part of the total compensation package, in addition to a full range of benefits including:
Onboarding & Travel
This is a remote role, with an in-person onboarding training component. New team members must participate in Trailhead, HealthEquity’s immersive onboarding experience Trailhead is designed to foster meaningful connections, support your integration into the organization, and equip you with a strong understanding of our business. Trailhead participation is a key expectation of this role. Trailhead is held onsite at our headquarters once per quarter. HealthEquity covers all required travel and accommodations.
This role may begin with a virtual, self-paced onboarding experience, followed by a mandatory onsite Trailhead session at a later date.
Our team will look into this right away.