JOB
The mission of Washington Health Benefit Exchange (Exchange) is to radically improve how Washington residents secure health insurance through innovative and practical solutions, an easy-to-use customer experience, our values of integrity, respect, equity and transparency, and by providing undeniable value to the health care community.
The Exchange is a public-private partnership that operates Washington Healthplanfinder, the eligibility and enrollment portal used by one in four Washington residents to obtain health and dental coverage. Through this platform, and with support from a Customer Support Center and statewide network of in-person navigators and brokers, individuals and families can shop, compare and enroll in private, qualified health plans (as defined in the Affordable Care Act) or enroll in Washington Apple Health, the state Medicaid program.
The Exchange embraces the following equity statement adopted by our Board of Directors:
Equity is fundamental to the mission of the Washington Health Benefit Exchange. The process of advancing toward equity and becoming anti-racist is disruptive and demands vigilance to dismantle deeply entrenched systems of privilege and oppression. While systemic racism is a root cause of many societal inequities, we must also use an intersectional approach to address all forms of bias and oppression, which interact with and often exacerbate racial inequities. To be successful, we must recognize the socioeconomic drivers of health and focus on people and places where needs are greatest. As we listen to community, we must hold ourselves accountable to responding to recommendations to remedy inequitable policies, systems, or practices within the Exchange’s area of influence. Our goal is that all Washingtonians have full and equal access to opportunities, power and resources to achieve their full potential.
SUMMARY
The Senior Identity and Access Management Engineer position focuses on designing, developing, and supporting customer IAM solutions using PingOne IdentityCloud to provide secure and seamless digital experiences to customers. Key responsibilities include managing user lifecycle automation, implementing access controls, integrating applications with IAM systems through industry-standard protocols, and enhancing security via Single Sign-On (SSO), Multi-Factor Authentication (MFA), and risk-based policies. The position also involves troubleshooting authentication flows, ensuring regulatory compliance, and collaborating with Information Technology (IT), security, and product teams to deliver robust IAM integrations across cloud platforms. EXAMPLE OF DUTIES •Design, develop, implement, and support customer IAM solutions utilizing PingOne IdentityCloud, and support transition to Okta where applicable.
- Build and maintain automated processes for user lifecycle management, including provisioning, deprovisioning, and role- or attribute-based access controls.
- Develop and maintain custom connectors, workflows, APIs, and scripts to integrate IAM systems with enterprise applications.
- Integrate web, mobile, and API-based cloud applications with IAM platforms using protocols such as SAML, OAuth, and OIDC.
- Implement SSO, adaptive authentication, MFA, and risk-based policies to enhance security and user experience.
- Configure and troubleshoot federation and OAuth/OIDC flows, and ensure secure session handling across systems.
- Implement and manage workflows for customer registration, login, account recovery, and profile management.
- Support migration of CIAM capabilities from PingOne Identity Cloud to Okta, including configuration, testing, validation, troubleshooting, deployment.
- Assist with migration planning, architecture design, and implementation of access and identity flows in Okta.
- Ensure IAM architecture and solutions adhere to security, privacy, regulatory, and consumer data protection requirements.
- Work closely with IT, Security, and Delivery teams to ensure secure IAM solutions across all cloud systems.
- Collaborate with delivery teams, product owners, and scrum masters to integrate IAM features into application releases.
- Participate in sprint planning, backlog refinement, and technical design discussions to ensure identity requirements are considered early in development.
- Support IAM changes during sprint release cycles, ensuring thorough testing and validation.
- Coordinate IAM-related changes with DevOps and change management teams to minimize disruptions during deployments.
- Provide guidance to IT and Delivery teams on secure authentication patterns, token usage, and best practices for IAM.
- Ensure IAM solutions align with enterprise security policies, identify gaps, and provide progress updates.
- Monitor IAM environments for authentication issues, anomalies, and performance bottlenecks.
- Document IAM architectures, integrations, and operational procedures.
- Execute and manage access recertification campaigns, ensuring timely completion and accurate audit reporting.
- Implement and maintain least-privilege and segregation-of-duties controls across IAM systems.
- Leverage microservices and API architectures to design, build, and manage IAM functionalities, enabling secure and scalable authentication, authorization, and service access controls.
- Serve as the primary technical contact with the Ping Identity support team to address environment-related issues, tenant performance concerns, incidents, and troubleshooting.
- Track vendor releases, platform updates, and new capabilities for adoption within the organization.
- Coordinate maintenance windows, patch updates, and feature releases with the Change Advisory Board, Delivery Team, and Ping Identity vendor.
- Validate vendor fixes in lower environments before production rollout.
- Monitor authentication health, login trends, and token issuance metrics.
- Perform root cause analysis for authentication and authorization incidents.
- Assist in investigations of security incidents involving identity compromise.
- Maintain detailed logging and audit trails aligned with regulatory requirements.
- Monitor IAM logs and integrate events with SIEM platforms to support security monitoring and incident response.
- Support audit activities by providing technical guidance and documentation, and act as a liaison for internal and external audit reviews as needed.
- Develop automation scripts (e.g., Python, Java, or similar) to streamline IAM processes.
- Leverage PingOne REST APIs for configuration management tasks.
- Support CI/CD deployment of IAM configurations.
- Support infrastructure-as-code initiatives where applicable.
- Assist the IAM Lead and Information Security Manager (ISM) in reviewing IAM capabilities and defining a roadmap for IAM enhancements.
- Support the development and implementation of information security awareness and training initiatives.
- Stay current on industry trends, emerging threats, and relevant technologies, and communicate key insights to the IAM Lead and ISM.
- Provide regular briefings to the IAM Lead and ISM, escalating issues and blockers as necessary.
- Perform other duties as assigned within the scope of IAM.
SUPPLEMENTAL INFORMATION APPLICATION INSTRUCTIONS
This position will be open until we find a suitable number of candidates to review. If interested, please
submit an application (CLICK HERE) as soon as possible. The Exchange reserves the right to close the recruitment at any time.
SALARY INFORMATION
Full Salary Range: $98,842.00 to $148,263.00 annually, with midpoint at $123,552.00.
Hiring Range: $ 113,668.00 and $123,552.00 annually. This is an estimate of where a qualified candidate can expect to receive an offer.
The actual salary offer will consider candidate experience, skills, qualifications, internal equity, and the market. Our compensation policy reserves the salary range above the midpoint for employees who are meeting and exceeding expectations and for growth and development, up to the maximum.
BENEFITS
Take a peek at our benefits package.
WORKING CONDITIONS
Core business hours are 8:00 a.m. to 5:00 p.m., Monday through Friday. There are times where irregular hours will be required. The preferred duty station is our Olympia, Washington headquarters. The nature of this role relies heavily on remote and in-person collaboration. While a hybrid remote and on-site schedule may be considered, the position will require flexibility to allow for in-office availability as business needs dictate. Travel requirements will be limited, however there may be occasions where an employee is required to travel and work irregular hours to attend meetings or trainings. Duties of this position require the use of standard office furniture and equipment, including setup for remote work. The employee is responsible for providing and maintaining a safe, ergonomic, and secure workspace at their remote location.
The working conditions and physical demands are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
SPECIAL REQUIREMENTS
A criminal background screen will be conducted for candidates under final consideration, and if hired, every five years of employment where highly sensitive data is processed or maintained by the position. The result of this background screen must meet the Exchanges eligibility standards.
OTHER INFORMATION
The above statements are intended to describe the general nature and levels of work being performed. They are not intended to be construed as an exhaustive list of responsibilities, duties and skills of personnel so classified.
This is not an employment agreement or contract. Management has the exclusive right to alter this job description at any time without notice.
The Washington Health Benefit Exchange is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, marital status, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.
We participate in E-Verify. You can view the Department of Justice's Right to Work poster here.