Staff Enterprise and Cloud Engineer
Job description
About the role
Zocdoc is dedicated to transforming the healthcare experience by empowering patients and making healthcare services more accessible. As a Staff Enterprise and Cloud Engineer, you will be instrumental in ensuring that our corporate systems are secure, reliable, and scalable. Your primary focus will be on developing and executing the technical strategy for identity and access management, which is critical for safeguarding sensitive data and maintaining operational efficiency. You will lead efforts to design, implement, and oversee identity governance solutions, working closely with cross-functional teams to align security practices with business needs. This role offers an exciting opportunity to influence the company's security posture and automation initiatives while supporting a fast-paced, innovative environment.
Key facts
What you'll do
- Develop and oversee the technical roadmap for identity and access management, with a focus on Microsoft Entra ID, ensuring alignment with organizational security policies and business objectives.
- Design and implement scalable identity governance solutions that improve user productivity while minimizing security risks.
- Ensure the security, reliability, and performance of cloud environments, including AWS, Azure, and GCP, along with on-premises infrastructure, by implementing best practices and monitoring systems.
- Lead automation initiatives to streamline access management workflows, reducing manual tasks and increasing operational efficiency through scripting and API integrations.
- Participate in incident response activities related to identity and access issues, providing expertise to resolve problems quickly and prevent future occurrences.
- Collaborate with engineering, security, and compliance teams to establish and enforce technical standards, ensuring consistent and secure identity practices across the organization.
- Drive the adoption of Zero Trust security principles by implementing device posture assessments, access controls, and continuous monitoring to enhance security posture.
- Manage compliance initiatives related to identity governance, supporting HITRUST, SOC2, and other audit cycles to ensure adherence to regulatory requirements.
- Serve as a strategic partner to various teams, influencing technical roadmaps and prioritizing initiatives that align with business goals and security standards.
- Mentor and guide engineering teams on best practices for identity management, automation, and security, fostering a culture of continuous improvement.
- Evaluate and recommend new tools and technologies to enhance identity and access management capabilities, staying current with industry trends and innovations.
- Support the integration of AI platforms and governance, particularly in managing access, spend, and security considerations in AI-related environments.
Requirements
- Proven experience leading enterprise identity or platform projects within large organizations, demonstrating measurable outcomes and impact.
- Ability to influence and drive adoption of technical standards across teams through design reviews, documentation, and mentorship.
- Over 10 years of experience in IT, systems engineering, or related fields, with a focus on defining and implementing architectural standards.
- Expertise in Microsoft Entra ID, including identity governance, lifecycle management, and related features.
- Extensive experience with SSO (Single Sign-On) and SCIM (System for Cross-domain Identity Management) integrations across multiple SaaS platforms.
- Strong skills in process automation, scripting, and reducing manual tasks through programming and API integrations, using languages such as Python, PowerShell, or similar.
- Familiarity with AI governance, including managing access, spend, and security considerations in AI platforms.
- Background in security, compliance, and audit processes, especially in environments with HITRUST, SOC2, or similar standards.
- Knowledge of endpoint management tools such as Intune and Jamf, ensuring cohesive identity management across devices.
- Hands-on experience with cloud infrastructure automation tools like Terraform, and scripting languages such as Python or PowerShell.
- Ability to work collaboratively across teams, communicate complex technical concepts clearly, and influence stakeholders at all levels.
Nice to have
- Experience working with generative AI tools and their integration into enterprise systems, including governance and security considerations.
- Familiarity with cloud security best practices, incident response protocols, and threat mitigation strategies.
- Knowledge of additional security frameworks, compliance standards, or certifications relevant to enterprise security.
Skills & tools
- Microsoft Entra ID
- SSO/SCIM (SAML, OIDC)
- AWS, Azure, GCP
- Terraform, Python, PowerShell
- Intune, Jamf, CrowdStrike
Practical notes
- This position is open to remote candidates, allowing flexibility for qualified applicants.
- Zocdoc offers competitive benefits, including unlimited vacation, comprehensive health coverage, and a 401(k) plan with employer matching.
- The salary range for this role is between $180,000 and $270,000, depending on experience and qualifications.
- The role involves working on-site at our New York, NY office, with on-site responsibilities as specified.
- The company values diversity and inclusion, fostering a collaborative environment where innovation thrives.
- Candidates should be prepared for a thorough interview process that assesses technical expertise, problem-solving skills, and alignment with Zocdoc's mission and values.