Back to search
Tempus AI Builtin · Posted yesterday

Associate IAM Engineer

Chicago, Illinois, USA USD 70000-95000 / year Full time Remote

FULL_TIME Builtin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Passionate about precision medicine and advancing the healthcare industry?

Recent advancements in underlying technology have finally made it possible for AI to impact clinical care in a meaningful way. Tempus' proprietary platform connects an entire ecosystem of real-world evidence to deliver real-time, actionable insights to physicians, providing critical information about the right treatments for the right patients, at the right time.

As an Associate IAM Engineer, you will be the frontline defender and administrator of our identity perimeter. You will focus on day-to-day identity operations, single sign-on (SSO) integrations, device assurance, and troubleshooting authentication issues. This role is perfect for someone with a strong foundational understanding of identity protocols (SAML, OIDC) who wants to grow their hands-on skills in enterprise automation, identity governance, and cloud identity management using Okta.

Key Responsibilities

  • SSO & App Integration: Configure, test, and deploy standard SAML 2.0 and OIDC/OAuth 2.0 integrations for onboarding new SaaS applications.

  • Operational Support & Troubleshooting: Serve as the Tier 2/3 point of contact for identity-related tickets. Deep-dive into system logs and protocol traces to resolve authentication, MFA, and provisioning failures.

  • Lifecycle Management (LCM): Monitor and maintain automated user provisioning (Joiner/Mover/Leaver processes) across HRIS, Active Directory, and downstream applications. Help triage Okta Workflow errors.

  • Device Assurance & Endpoint Security: Assist in configuring and monitoring Okta Device Assurance policies to ensure only secure, compliant devices can access corporate resources.

  • Identity Governance & Compliance: Support user access reviews and regular entitlement certifications using Okta Identity Governance (OIG) to ensure alignment with SOC2, ISO 27001, and SOX frameworks.

Technical Qualifications

  • Experience: 1–3 years of experience in an IT, Security, or Systems Administration role, with at least 1 year of dedicated hands-on exposure to Okta administration.

  • Protocol Fundamentals: A solid conceptual understanding of the "Identity Trinity":

    • SAML 2.0: Understanding assertions, entity IDs, and ACS URLs.

    • OpenID Connect: Basic understanding of tokens (ID, Access, Refresh), scopes, and authorization flows.

    • SCIM: Familiarity with how automated provisioning works.

  • Directory Services: Comfortable navigating and managing Universal Directory (managing users, groups, and basic OU structures).

  • RESTful APIs: Foundational understanding of REST API concepts (HTTP methods like GET, POST, PUT, DELETE, and status codes) and comfort using OKTA Workflows.

  • Security Mindset: Understanding of basic security principles like Multi-Factor Authentication (MFA), Least Privilege, and Zero Trust.

Soft Skills

  • The "Log Detective": You enjoy digging into event logs and browser developer tools (SAML tracers) to find out exactly why a login failed.

  • Clear Communicator: Ability to guide non-technical employees (or partners in HR) through password resets, MFA setups, or access requests with patience and clarity.

  • Hungry to Learn: The identity space moves fast. You are excited to learn advanced tools like Okta Workflows, Terraform, or API management on the job.

Bonus Points

  • Okta Device Assurance: Prior exposure to configuring Okta Device Assurance policies and a basic understanding of how they interface with MDM tools (e.g., Jamf, Intune) to check device posture.

  • Identity Governance (IGA): Hands-on exposure to Okta Identity Governance (OIG) for managing access requests, approvals, and access certification campaigns.

  • Okta Workflows & Automation: Foundational knowledge or exposure to Okta Workflows (or similar low-code automation platforms) used to orchestrate lifecycle management.

  • Certifications: Okta Certified Professional or Okta Certified Administrator.

#LI-Hybrid

#LI-HR1

CHI - $70,000 - $95,000

The expected salary range above is applicable if the role is performed from Illinois and may vary for other locations (California, Colorado, New York). Actual salary may vary based on qualifications and experience. Tempus offers a full range of benefits, which may include incentive compensation, restricted stock units, medical and other benefits depending on the position.

We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If the repetitive CV tweaking gets heavy, Daniel can help set up Caio Agent.
Ask about Agent