Avatar for Blue Shield of California
Not-For-Profit Health Insurance company
  • B2C
  • Scale Stage
    Rapidly increasing operations

Sr. Manager, Identity Platform Engineering

  • $148k – $251k
  • |
  • |8 years of exp
  • |Full Time
Posted: 1 month ago
Job Location
Remote Work Policy

In office - WFH flexibility

Visa Sponsorship

Not Available

RelocationAllowed
Skills
Authentication
Automated Testing
Single Sign-On
Scripting Languages
SAML
OAuth 2.0
Multi-factor Authentication
Scim
openid connect
authorization
Automation Frameworks
federation
Role-Based Access Control
Privileged Access Management
Infrastructure as code
APIs
CI/CD Pipelines
Key Management
Secrets Management
Workflow Orchestration
Identity Governance
DevOps Practices
Least Privilege
Managed Identities
Configuration-As-Code
Access Governance
Identity Lifecycle Management
Ephemeral
Attribute-Based Access Control
Policy-Based Access Control
Just-in-Time
Service Identities
Workload Identity
Policy Validation
Just-Enough
Time-Bound

About the job

Job Description

Your Role

The Identity and Access Management team is responsible for designing, engineering, and operating enterprise identity services that enable secure, scalable, and seamless access across Stellarus’ technology ecosystem. The team drives Identity Lifecycle Management, Identity Governance, Privileged Access Management, authentication, authorization, automation, and Zero Trust capabilities while partnering across the enterprise to support digital transformation, regulatory compliance, secure software delivery, and responsible AI adoption.

The Senior Manager, Identity Platform Engineering will report to the Sr. Director, Identity & Access Management. In this role, you will help shape the future of Stellarus’ identity platform by engineering secure, automated, and scalable IAM capabilities that support hybrid cloud, SaaS, on-premises, application, privileged, service, machine, and AI-enabled access patterns.

You will partner with teams to integrate identity into modern software delivery practices, accelerate automation through DevOps and AI, and deliver programmatic identity services that can be consumed by development teams through self-service, least-privileged, time-bound, and policy-governed patterns.

Our leadership model is about developing great leaders at all levels and creating opportunities for our people to grow personally, professionally, and financially. We are looking for leaders who are energized by creative and critical thinking, building and sustaining high-performing teams, getting results the right way, and fostering continuous learning.

Responsibilities

Your Work

In this role, you will:

  • Design, implement, and continuously improve enterprise Identity and Access Management capabilities across hybrid cloud, SaaS, on-premises, application, privileged, service, machine, and AI-enabled access patterns.
  • Lead the engineering, automation, and modernization of Identity Lifecycle Management, Identity Governance, Privileged Access Management, authentication, authorization, federation, and access governance capabilities.
  • Contribute to enterprise IAM architecture, engineering standards, platform roadmaps, service reliability practices, operational metrics, risk reduction plans, and measurable outcomes that support Stellarus’ technology strategy.
  • Deliver IAM as a reusable, API-driven, developer-consumable platform that enables secure self-service application onboarding, entitlement workflows, access request automation, standardized integration patterns, reference architectures, and developer documentation.
  • Develop and maintain scalable identity services using Infrastructure as Code, configuration-as-code, DevOps practices, CI/CD pipelines, APIs, workflow orchestration, automated testing, policy validation, and automation frameworks to accelerate delivery and improve reliability.
  • Partner with teams to embed identity into enterprise platforms, cloud environments, software delivery pipelines, AI-enabled workflows, and modern application architectures.
  • Design and implement Role-Based Access Control, Attribute-Based Access Control, policy-based access control, Just-in-Time, just-enough, time-bound, ephemeral, and Least Privilege access models that reduce standing privilege while simplifying access administration.
  • Advance privileged access modernization and access governance through automated approval workflows, time-bound elevation, break-glass controls, credential rotation, session monitoring, access expiration, entitlement management, access certification, analytics, and risk-based privilege management.
  • Engineer integrations across identity governance, access management, privileged access, directory, cloud, HR, data, AI, and enterprise application platforms to support automated provisioning, deprovisioning, authentication, authorization, federation, policy enforcement, and machine-to-machine access.
  • Define secure identity and access patterns for AI-enabled systems, including AI agents, copilots, intelligent automation, autonomous workflows, machine identities, data access workflows, and applications requiring controlled access to enterprise or healthcare data.
  • Leverage AI, machine learning, and intelligent automation to improve identity operations, entitlement analysis, access reviews, anomaly detection, governance, audit readiness, operational insights, developer support, engineering productivity, and compliance with HIPAA, SOX, HITRUST, NIST, audit requirements, and Zero Trust principles.

Qualifications

Your Knowledge and Experience

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, Engineering, or equivalent combination of education and experience.
  • A minimum of 8 years of experience designing, implementing, and supporting enterprise Identity and Access Management solutions.
  • 4 years of prior people management experience with direct responsibility for supervising, coaching, and evaluating direct reports
  • Experience leading IAM, security engineering, platform engineering, cloud, infrastructure, or related technical teams.
  • Strong understanding of Identity Lifecycle Management, Joiner/Mover/Leaver processes, Identity Governance, and Privileged Access Management within complex hybrid cloud, SaaS, and on-premises environments.
  • Deep understanding of Role-Based Access Control, Attribute-Based Access Control, policy-based access control, Just-in-Time, just-enough, time-bound, and Least Privilege security models.
  • Strong knowledge of authentication and authorization frameworks, including Single Sign-On, Multi-Factor Authentication, SAML, OAuth 2.0, OpenID Connect, SCIM, and modern identity federation technologies across enterprise and consumer ecosystems.
  • Experience implementing and supporting enterprise identity governance, access management, directory, privileged access, cloud identity, HR, and application integration platforms.
  • Experience delivering identity as a platform capability, including self-service, API-driven, and developer-consumable IAM services for application, cloud, platform, and security engineering teams.
  • Experience developing automation using scripting languages, REST APIs, workflow automation, or similar programming approaches.
  • Experience implementing DevOps or platform engineering practices, including CI/CD, Infrastructure as Code, configuration-as-code, policy-as-code, automated testing, automated deployment, observability, and operational reliability.
  • Strong understanding of cloud identity and access patterns, including workload identity, service identities, managed identities, secrets management, key management, privileged access controls, and machine-to-machine access.
  • Experience integrating IAM capabilities into enterprise applications, cloud services, SaaS platforms, infrastructure platforms, and modern software development lifecycles.
  • Experience applying identity controls to AI-enabled systems, including AI agents, copilots, intelligent automation, machine identities, data access workflows, human-in-the-loop approvals, audit logging, and least-privilege access to sensitive enterprise data.
  • Experience leveraging AI-assisted development, intelligent automation, or machine learning technologies to improve operational efficiency, accelerate identity engineering, enhance access governance, or improve risk detection.

Hybrid

This role requires employees to be in-office based on our hybrid workplace model, balancing purposeful in-person collaboration with flexibility. For most teams, this means coming into the office two days each week.

Employees living more than 50 miles from an office location will work with their manager to determine in-office time based on business need.

About Us

About Stellarus and the Ascendiun Family of Companies

Stellarus, launched in January 2025, is designed to scale innovative healthcare solutions that support customers in creating a health care experience deserving of their family, friends, and neighbors.

Stellarus is part of a family of organizations that is overseen by a nonprofit corporate entity named Ascendiun. The Ascendiun Family of Companies also includes Blue Shield of California and its subsidiary, Blue Shield of California Promise Health Plan and Altais, a clinical services company.

Stellarus’ vision is to empower its customers to create a healthcare experience that is worthy of their family, friends, and neighbors. Stellarus’ objective is to offer innovative, modern, scalable solutions that challenge the health care status quo. This very closely aligns with Blue Shield of California’s vision by using innovation to improve quality, affordability, and experience for members.

To achieve our mission, we foster an environment where all employees can thrive and contribute fully to address the needs of the various communities we serve. We are committed to creating and maintaining a supportive workplace that upholds our values and advances our goals.

Our Values:

At Stellarus, our core values of agility, trust, drive, courage and service shape our approach to developing innovative product offerings.

Our Workplace Model:

We believe in fostering a workplace environment that balances purposeful in-person collaboration with flexibility - providing clear expectations while respecting the diverse needs of our workforce. Our workplace model is designed around intentional in-person interaction, collaboration, connection, creativity and flexibility:

  • For most teams, this means coming into the office two days per week.
  • Employees living more than 50 miles from an office location, out of state employees, and employees in certain member-facing roles should work with their manager to determine in-office time based on business need.
  • For employees with medical conditions that may impact their ability to work in-office, we are committed to engaging in an interactive process and providing reasonable accommodations to ensure their work environment is conducive to their success and well-being.

The Company reserves the right to require more presence in the office based on business needs, and requirements are subject to change with periodic reviews.

Physical Requirements:

Office Environment - roles involving part to full time schedule in Office Environment. Based in our physical offices and work from home office/deskwork - Activity level: Sedentary, frequency most of work day.

Please click here for further physical requirement detail.

Equal Employment Opportunity:

External hires must pass a background check/drug screen. Qualified applicants with arrest records and/or conviction records will be considered for employment in a manner consistent with Federal, State and local laws, including but not limited to the San Francisco Fair Chance Ordinance. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, national origin, sexual orientation, gender identity, protected veteran status or disability status and any other classification protected by Federal, State and local laws.

JOB INFO

Job Identification : 20261269

Job Category : Information Technology

Posting Date : 2026-07-10T21:56:57+00:00

Job Schedule : Full time

Locations :

Oakland, CA, United States

WA, United States

OH, United States

DC, United States

CA, United States

Long Beach, CA, United States

AZ, United States

CO, United States

CT, United States

FL, United States

GA, United States

MD, United States

NV, United States

OR, United States

El Dorado Hills, CA, United States

San Diego, CA, United States

Woodland Hills, CA, United States

AL, United States

IL, United States

VA, United States

TX, United States

NY, United States

Pay Range for California : $148940.00 to $223300.00

Pay Range for Bay Area : $167896.00 to $251720.00

Note : Please note that this range represents the pay range for this and many other positions at Blue Shield that fall into this pay grade. Blue Shield salaries are based on a variety of factors, including the candidate experience, location (California, Bay Area, or outside California), and current employee salaries for similar roles.

Role can be filled by a candidate requiring sponsorship : No

About the company

Blue Shield of California company logo
Not-For-Profit Health Insurance company5000+ Employees
  • B2C
  • Scale Stage
    Rapidly increasing operations
Learn more about Blue Shield of California image

Similar Jobs

Albeado company logo
Albeado
Breakthrough causal AI predictions, optimizations and interventions - in real time
Dreamers company logo
Dreamers
Specializing in building technological solutions for complex problems
Onos Health company logo
Onos Health
The first comprehensive AI platform for health plans to improve behavioral & mental health services
Litmos.com company logo
Litmos.com
Leading cloud based Learning Management Software
Mudflap company logo
Mudflap
Leading fintech innovation in trucking for independent owner operators & fleets
Postman company logo
Postman
Postman is the world’s leading collaboration platform for API development
Opal company logo
Opal
We’re building modern identity governance for the AI era