About this role
Your Future Evolves Here
Evolent partners with health plans and providers to achieve better outcomes for people with most complex and costly health conditions. Working across specialties and primary care, we seek to connect the pieces of fragmented health care system and ensure people get the same level of care and compassion we would want for our loved ones.
Evolent employees enjoy work/life balance, the flexibility to suit their work to their lives, and autonomy they need to get things done. We believe that people do their best work when they're supported to live their best lives, and when they feel welcome to bring their whole selves to work. That's one reason why diversity and inclusion are core to our business.
Join Evolent for the mission. Stay for the culture.
What You’ll Be Doing:
Job Summary
This role designs, implements and continuously improves identity and access management (IAM) capabilities across Microsoft Entra ID, Active Directory and adjacent platforms, with particular focus on role-based access control (RBAC), conditional access, privileged access and identity governance. The engineer builds automation and agentic AI solutions—such as access-review and role-mining agents—to reduce manual administrative overhead and strengthen the organization’s zero-trust security posture. The engineer collaborates with security, compliance and platform teams to ensure identity controls align with company policy and applicable regulations.
Essential Functions
- Design, implement and operate IAM capabilities including RBAC, conditional access, privileged identity management (PIM), and entitlement management
- Write and maintain scripts and integrations (PowerShell, Python, Microsoft Graph API, or similar) for identity provisioning, access reviews, certification workflows and reporting
- Design, build and deploy agentic AI solutions (e.g., a role-mining agent) that analyze access patterns, recommend least privilege role assignments and automate periodic access certification
- Integrate IAM systems with adjacent technologies (endpoint management, security operations, ITSM, directory services) to support end-to-end identity lifecycle management
- Monitor and report on identity-related security anomalies and support incident response and remediation for identity-based threats
- Support audit readiness by producing and maintaining documentation of IAM design, controls, and automation
- Create, publish and communicate knowledgebase articles and standard operating procedures for IAM processes
- Act as a mentor to junior engineers and operations teams on IAM for best practices, secure coding and responsible use of AI-driven automation
Required Qualifications
- 7+ years managing or supporting identity and access management, identity governance, or related security platforms
- 3+ years of hands-on experience with Microsoft Entra ID (Azure AD), RBAC design, conditional access and privileged identity management (PIM)
- Demonstrated coding/scripting ability (PowerShell, Python, Microsoft Graph API, or similar) with a track record of building identity automation, integrations and reporting tools
- Hands-on experience designing or deploying agentic AI or automation solutions for identity/access use cases (e.g., role mining, access certification, anomaly detection)
- Experience with identity protocols and standards (SAML, OAuth/OIDC, SCIM) and identity governance/compliance frameworks
- Working knowledge of Generative AI and agentic AI concepts (LLM integration, tool/function calling, retrieval-augmented generation) as applied to identity and security operations
- Ability to write clear technical documentation
Preferred Qualifications
- Experience building or contributing to an internal AI agent/Center of Excellence pod, including agent design and application lifecycle management (ALM) practices
- Experience with Microsoft Copilot Studio or similar low-code AI agent platforms
- Passion for zero-trust security with an awareness of the latest identity and AI trends
Preferred Education
- Bachelor’s degree in IT, Computer Science, or related field
Preferred Certifications
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Azure AI Engineer Associate (AI-102) or Copilot Studio/agentic AI certification
General Performance Criteria
As the Sr Engineer, Identity & Access Management, you will be required to fulfill your responsibilities while meeting the following general performance criteria for this position at this level:
Expertise: You research, create proof of concepts, and introduce new methods
Communication: You guide others through problem solving whether it is a technical issue, project impediment, or conflict
Domain: You guide the delivery of your team to make a positive impact on other parts of the company based on detailed knowledge of the needs of those stakeholders and how those needs are supported by your team
System: You own relevant segment of systems that are used regularly for the business to function and are well versed in the related KPIs
Process: You question the status quo in a constructive manner to find areas for the team to improve
Influence: You regularly make an impact to your entire team
To ensure a secure hiring process we have implemented several identity verification steps, including submission of a government issued photo ID. We conduct identity verification during interviews, and final interviews may require onsite attendance. All candidates must complete a comprehensive background check, in-person I-9 verification, and may be subject to drug screening prior to employment. The use of artificial intelligence tools during interviews is prohibited and monitored. Misrepresentation will result in immediate disqualification from consideration.
Mandatory Requirements:
Employees must have a high-speed broadband internet connection with a minimum speed of 50 Mbps and the ability to set up a wired connection to their home network to ensure effective remote work. These requirements may be updated as needed by the business.
Evolent is an equal opportunity employer and considers all qualified applicants equally without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, or disability status. If you need reasonable accommodation to access the information provided on this website, please contact [email protected] for further assistance.
The expected base salary/wage range for this position is $. As part of our total compensation package, Evolent is proud to offer comprehensive benefits (including health insurance benefits) to qualifying employees. All compensation determinations are based on the skills and experience required for the position and commensurate with experience of selected individuals, which may vary above and below the stated amounts.