Senior IAM Engineer

Posted 3 Days Ago
Be an Early Applicant
Chicago, IL
Hybrid
120K-160K Annually
Senior level
Artificial Intelligence • Big Data • Healthtech • Machine Learning • Analytics • Biotech • Generative AI
Tempus is a technology company leading the adoption of AI to advance precision medicine and patient care.
The Role
The Senior IAM Engineer will architect and secure identity solutions, automate processes with Okta, and manage hybrid identity systems, ensuring compliance and security standards are met.
Summary Generated by Built In

Passionate about precision medicine and advancing the healthcare industry?

Recent advancements in underlying technology have finally made it possible for AI to impact clinical care in a meaningful way. Tempus' proprietary platform connects an entire ecosystem of real-world evidence to deliver real-time, actionable insights to physicians, providing critical information about the right treatments for the right patients, at the right time.

  • As a Senior IAM Engineer, you will be the primary architect and guardian of our identity perimeter. You will design, implement, and maintain scalable identity solutions that secure our workforce. Your focus will be on transitioning away from manual provisioning toward a fully automated "Identity-as-Code" model using Okta Workflows and API integrations.

  • Key Responsibilities
    • Architectural Leadership: Design and scale our Okta tenant, ensuring high availability and global best practices for SAML, OIDC, and OAuth 2.0 integrations.

    • Automation & Orchestration: Build complex lifecycle management (LCM) flows using Okta Workflows to automate joiner/mover/leaver processes across HRIS, AD, and downstream SaaS apps.

    • Hybrid Identity Management: Manage and optimize the synchronization between Active Directory (AD) and cloud identity providers.

    • API Integration: Develop custom integrations using REST APIs to connect homegrown or niche applications that lack out-of-the-box support.

    • Security & Compliance: Implement Adaptive Multi-Factor Authentication (MFA), Passwordless strategies, and regular access certifications to meet SOC2/ISO 27001/SOX requirements.

    • Escalation Support: Serve as the Tier 3 expert for complex authentication issues and identity-related security incidents.

  • Technical Qualifications
    • Okta Mastery: 5+ years of experience managing Okta at an enterprise scale, including advanced Workflows and Okta Expression Language.

    • Protocol Expertise: Deep understanding of the "Identity Trinity":SAML 2.0: XML-based assertions and troubleshooting.OIDC/OAuth 2.0: Scopes, claims, and grant types (Authorization Code vs. Client Credentials).SCIM: Automating user provisioning and deprovisioning.

    • Directory Services: Strong background in Active Directory (Group Policy, Kerberos, DNS) and how it interfaces with modern cloud tenants.

    • Programming/Scripting: Proficiency in Python, PowerShell, or JavaScript for interacting with APIs and automating repetitive tasks.

    • Modern Security: Familiarity with Zero Trust Architecture (ZTA) and Least Privilege principles.

  • Soft Skills
    • Problem Solver: You don't just fix the symptom; you find the root cause in the protocol trace.

    • Communicator: Ability to explain complex authentication flows to non-technical stakeholders (e.g., HR or Legal).

    • Continuous Learner: The identity landscape shifts weekly; you enjoy staying ahead of new standards like FIDO2 or Passkeys.

  • Bonus Points
    • Okta Certified Professional/Administrator/Consultant.

    • Experience with Infrastructure as Code (Terraform) for managing Okta resources.

    • Experience with Privileged Access Management (PAM) tools.

    • Experience with Identity Governance and Administration (IGA) tools.

#LI-HR1

CHI - $120,000-$160,000

The expected salary range above is applicable if the role is performed from Illinois and may vary for other locations (California, Colorado, New York). Actual salary may vary based on qualifications and experience. Tempus offers a full range of benefits, which may include incentive compensation, restricted stock units, medical and other benefits depending on the position.

We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. 

Top Skills

Active Directory
JavaScript
Oauth 2.0
Oidc
Okta
Powershell
Python
SAML
Scim
Terraform

What the Team is Saying

Rachel
Louis
Anita
Alexis
Hala
Aaron
Alexis
Ash
Emma
Anita
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
3,775 Employees
Year Founded: 2015

What We Do

We bring together one of the world’s largest libraries of multimodal clinical and molecular data with a robust suite of AI tools to help physicians personalize care in real time, connect patients with therapies and clinical trials, and enable partners to accelerate discovery and development of new treatments.

With ~8 million de-identified research records and 350+ petabytes of data, Tempus partners with more than half of U.S. oncologists and the majority of the top 20 global pharma companies. Our teams are pioneering work across oncology, neurology, psychiatry, cardiology, and beyond—transforming how care is delivered and therapies are developed.

At Tempus, every role contributes to our mission: to help each patient benefit from the experiences of those who came before.

For more information, visit tempus.com.

Why Work With Us

We’re looking for people who can change the world. People who question the status quo and refuse to shy away from tough problems. For builders who are never done building, and the learners who are never done learning. Passionate individuals with undying curiosity who want to take on one of the greatest challenges humanity has ever faced—head on.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Tempus AI Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Most of the team follows a hybrid policy, with some roles allowing for a fully remote arrangement and some roles being onsite only.

Typical time on-site: 3 days a week
Company Office Image
HQChicago - Tempus Headquarters & Lab
Company Office Image
RTP - Tempus Lab
Company Office Image
Boston - Tempus Office
Company Office Image
Seattle - Tempus Office
Company Office Image
Lewisburg - Tempus Office
Company Office Image
Madison - Tempus Office
Company Office Image
Milwaukee - Tempus Office
Company Office Image
New York City - Tempus Office
Company Office Image
Atlanta - Tempus Lab
Company Office Image
Bay Area - Tempus Office
Company Office Image
Washington DC - Tempus Office
Learn more

Similar Jobs

Tempus AI Logo Tempus AI

Engineering Lead, Data Products Platform

Artificial Intelligence • Big Data • Healthtech • Machine Learning • Analytics • Biotech • Generative AI
Hybrid
Chicago, IL, USA
3775 Employees
150K-200K Annually

Tempus AI Logo Tempus AI

Senior Software Engineer

Artificial Intelligence • Big Data • Healthtech • Machine Learning • Analytics • Biotech • Generative AI
Hybrid
Chicago, IL, USA
3775 Employees
110K-160K Annually

Tempus AI Logo Tempus AI

Scientist

Artificial Intelligence • Big Data • Healthtech • Machine Learning • Analytics • Biotech • Generative AI
Remote or Hybrid
Illinois, USA
3775 Employees
60K-100K Annually

Tempus AI Logo Tempus AI

Intellectual Property Attorney

Artificial Intelligence • Big Data • Healthtech • Machine Learning • Analytics • Biotech • Generative AI
Hybrid
Chicago, IL, USA
3775 Employees
150K-200K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account