
Principal Identity System Engineer
Sanford
🇺🇸 United States
On-site
Staff / Principal
19 hours ago
- IAM
- Zero Trust
- Active Directory
- PKI
- SAML
- OIDC
- HIPAA
- CISSP
- CISA
- CISM
- CEH
19 hours ago
Sanford Health, the largest rural health system in the United States, is dedicated to transforming the health care experience and providing access to world-class health care in America’s heartland.


Work Shift:
8 Hours - Day Shifts (United States of America)

Scheduled Weekly Hours:
40

Compensation:
Salary Range: $49.50 - $81.50

Pay starts at $49.50 and increases according to applicable experience.

Union Position:
No

Department Details
Summary
The Principle Identity Systems Engineer is responsible for setting strategy and designing secure enterprise identity and access management infrastructure that enables reliable authentication, authorization, and access management across hybrid environments. Engineers in this family ensure that users, systems, and applications are authenticated, authorized, and protected in alignment with security standards, regulatory requirements, and business needs.Job Description
The Principal Identity Systems Engineer is a senior technical leader responsible for setting the vision and driving enterprise-wide strategies for identity platforms across on-premises and cloud environments. This role defines and champions the IAM roadmap, establishes architectural standards for hybrid identity, Zero Trust, and cloud integrations, and collaborates closely with executives, architects, and security leadership to ensure alignment with business objectives and regulatory requirements. The Principal Identity Systems Engineer leads modernization efforts around Active Directory, Entra ID, PKI, and authentication services while evaluating emerging technologies to strengthen enterprise identity security. Core responsibilities include architecting domain and forest structures, overseeing hybrid identity synchronization, enforcing secure authentication protocols, and automating access governance, provisioning, and privileged access management. This role also monitors and enhances KRIs to proactively identify risks, conducts expert-level troubleshooting and root cause analysis, and provides guidance on audit and compliance initiatives. In addition, the Principal Identity Systems Engineer mentors senior and lead engineers, develops standards and playbooks, and represents identity services as a strategic enabler of secure, scalable business operations. Balancing deep technical execution with enterprise strategy, this position ensures the identity ecosystem is resilient, future-ready, and integral to the organization's long-term security posture. This role requires deep technical expertise in Active Directory, Entra ID, authentication protocols, Identity Governance Administration (IGA), Privileged Access Management (PAM) and PKI with a strong focus on information security, compliance, strong problem-solving skills, a security-first mindset, and least-privilege enforcement. The Principal Identity Systems Engineer ensures the organization's identity platforms are resilient, scalable, and secure to support business operations and protect sensitive data. The Principal Identity Systems Engineer will work closely with cross-functional IT, application, and security teams to ensure alignment with business objectives, regulatory requirements, and industry best practices.Qualifications
Bachelor’s degree required, in lieu of education, leadership may consider an Associate’s Degree plus 3 years of applicable experience in computer science or related field.Minimum of 8 years applicable work experience required. Including but not limited to: • Supporting Active Directory, Domain Services, Hybrid Identities, & Entra ID • Implementing SSO/MFA workflows using SAML 2.0 and/or OIDC • Maintaining Public Key Infrastructure (PKI) • Supporting Identity Lifecycle & Access Governance workflows and technical integrations • Implementation of information security standards and procedures including HIPAA and PCI • Expert knowledge of Cloud security principles
One or more security certifications (CISSP, CISA, CISM, Security+, CEH, etc.) are required
Sanford is an EEO/AA Employer M/F/Disability/Vet.Â
If you are an individual with a disability and would like to request an accommodation for help with your online application, please call 1-877-949-5678 or send an email to talent@sanfordhealth.org.
Principal Identity System Engineer · Sanford