SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
OpenLoop is a telehealth platform that powers virtual care delivery at scale across all 50 US states. The company is seeking a Sr. Staff IAM Engineer to serve as the design authority for identity and access management across the entire organization.
This is a hands-on architecture role responsible for designing and governing identity across workforce, non-employee, customer, partner, and non-human (including AI agents) identity types. The role owns the target-state architecture and sets standards, reference patterns, and decision records to ensure consistent platform choices rather than ad-hoc project decisions.
Key responsibilities include:
- Owning Auth0 customer identity architecture end-to-end, including tenant modeling, MFA, phishing-resistant authentication, and machine-to-machine patterns
- Designing and consolidating workforce authentication onto a single IdP (Okta)
- Defining federation and directory architecture across Okta, Entra ID, AWS, and GCP
- Building out Identity Security Posture Management and extending the in-house posture warehouse
- Designing access controls that satisfy HIPAA, HITRUST, and SOC 2 requirements without manual overhead
- Partnering with Security Operations to integrate identity threat detection into the existing SIEM
- Serving as design authority between identity risk and remediation functions
- Writing reference implementations, architecture decision records, and design documentation
The ideal candidate is an architect who still codes, comfortable writing Auth0 Actions, Okta Workflows, Terraform, and querying data warehouses. They excel at setting direction without direct authority, documenting decisions clearly, and finishing partially-built systems. The role requires deep hands-on experience with CIAM platforms (ideally Auth0), enterprise IdP architecture (Okta or equivalent), federation protocols (SAML, OIDC, OAuth 2.0, SCIM, WebAuthn, FIDO2), and regulated-industry access requirements.
The identity estate is largely in flight with multiple platforms deploying concurrently (Okta, SailPoint ISC/NERM, Britive, Auth0, in-house iam-ops-hub). This role exists to create coherent architecture across these systems and establish governance patterns for an emerging challenge: service accounts and AI agents will soon outnumber human identities, and few companies have real architecture for this yet.