Optum Tech, part of UnitedHealth Group, is seeking a Senior IAM Engineer to join our team. This role is responsible for the design, implementation, administration, and optimization of Imprivata solutions like OneSign, Confirm ID, and Enterprise Access Management (EAM). You will enable secure, efficient authentication workflows that support our critical clinical and enterprise operations.
What You'll Do
- Lead the administration and lifecycle management of the Imprivata EAM platform.
- Configure and maintain authentication workflows including Single Sign-On (SSO), Badge tap / Tap n Go, FIDO2 security key workflows, Multi-factor authentication (MFA), EPCS, and fast user switching.
- Maintain system stability through proactive performance monitoring, patching, upgrades, and capacity planning.
- Manage the full upgrade lifecycle for Imprivata appliances, agents, and components.
- Integrate Imprivata solutions with clinical and enterprise applications like EHRs (Epic), virtual desktops (Citrix/VMware Horizon), Active Directory, and identity providers.
- Deploy and optimize endpoint agents, authentication devices, badge readers, FIDO compliant hardware keys, and API-driven integrations.
- Create and maintain application profiles, SSO configurations, workflows, identity policies, and device mappings.
- Ensure compliance with regulatory requirements such as HIPAA, EPCS, HITRUST, and internal security policies.
- Implement secure identity and authentication controls across the healthcare and workforce ecosystem.
- Collaborate with Security and Compliance teams for audits, risk assessments, and access reviews.
- Serve as a Tier 2 expert for escalations related to authentication, SSO, MFA, badge access, FIDO key workflows, or clinical workflow issues.
- Conduct root-cause analysis, resolve complex issues, and implement long-term remediation.
- Engage Imprivata technical support and vendors to resolve escalated issues.
- Ensure 24x7 availability and stability of services.
- Develop and maintain KB articles, documentation, deployment procedures, upgrade runbooks, and operational standards.
- Identify opportunities for workflow enhancements, automation, and optimization.
- Mentor, train, and transfer knowledge to junior engineers, analysts, and support staff.
What We're Looking For
- 8+ years of Information Technology delivery or support experience in a large, complex environment, preferably in Healthcare.
- 3+ years of proven experience with Imprivata EAM in an enterprise or healthcare environment.
- 3+ years of experience analyzing and resolving complex access and authentication issues.
- 2+ years of hands-on experience with Windows Server, Active Directory, Group Policy/Ivanti EM.
- 2+ years of hands-on experience with Citrix / VMware Horizon virtual desktop environments.
- 2+ years of hands-on experience with MFA technologies, certificate services, badge authentication, FIDO security keys, and IAM, SSO, and MFA principles.
- 1+ years of hands-on experience with Tap n Go badge workflows and FIDO2 based authentication.
- 1+ years of experience managing agent and appliance upgrade cycles, including planning, testing, and deployment.
- 1+ years of experience with ITIL processes, change management, and large-scale enterprise support.
- Proven ability to support on-call rotations and respond to incidents, providing off-business hours support as needed.
Nice to Have
- Imprivata certifications (e.g., Imprivata Certified Engineer).
- Information security or IAM background and related certifications.
- 5+ years of experience supporting Imprivata and Healthcare applications and customers.
- Experience supporting EHR systems (Epic Hyperspace, Epic Slingshot).
- PowerShell or other scripting experience for automation.
- Knowledge of Cloud, Networking, Database and Virtual Infrastructure concepts.
- Proven excellent communication and collaboration skills, with ability to work across multiple time zones.
- Proven good understanding of Clinical workflows.
- Proven excellent troubleshooting and root cause diagnosis skills.
Technical Stack
- Imprivata OneSign, Imprivata Confirm ID, Imprivata Enterprise Access Management (EAM)
- Single Sign-On (SSO), Multi-factor Authentication (MFA), Electronic Prescribing of Controlled Substances (EPCS)
- EHRs (Epic), Citrix, VMware Horizon, Active Directory
- FIDO2 security keys, Windows Server, Group Policy, Ivanti EM, PowerShell
Team & Environment
This role is part of the Enterprise Information Security (EIS) team and the Enterprise Security and Resilience Office (ESRO).
Benefits & Compensation
- Annual compensation range: $91,700 to $163,700
- Comprehensive benefits package
- Incentive and recognition programs
- Equity stock purchase plan
- 401k contribution
Work Mode
This is a hybrid position open to candidates across the United States.
UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.





