Full-Time

Principal IAM Engineer

Lantern Care

Lantern Care

501-1,000 employees

Specialty care platform with direct contracting

No salary listed

Dallas, TX, USA

Hybrid

At least three days per week in the Dallas office.

Bachelor's

Category
Cybersecurity (1)
Required Skills
PowerShell
Microsoft Azure
Python
Git
Role-based Access Control
SAML
Terraform

Get referred to Lantern Care

See people who can refer or advise you

Requirements
  • Eight or more years in identity and access management, including principal- or staff-level ownership of an identity control plane.
  • Deep Microsoft Entra ID engineering, including Conditional Access policy design, phishing-resistant multifactor authentication, single sign-on, and federation across Security Assertion Markup Language, OpenID Connect, and OAuth 2.0, with verification that enforcement takes effect across every access path.
  • Identity lifecycle automation across cloud, software-as-a-service, and privileged systems, with role- and attribute-based provisioning and deprovisioning verified against an entitlement inventory.
  • Zero Trust identity design, including least privilege, just-in-time access, and risk-based or adaptive access controls.
  • Identity governance and administration platform engineering, including privileged access management.
  • Automation and scripting using PowerShell, Python, or similar tools to build lifecycle workflows and custom connectors.
  • Identity-as-code and policy-as-code practice using Terraform with source-controlled change management, such as GitHub.
  • Experience with secrets and non-human identity, including API keys, service accounts, and workload identity, as well as maintaining an owner registry.
  • Key access governance and separation of duties in a model where another team operates the key management system.
  • Ability to act as the technical authority for a function without formal people-management authority while working directly to a CISO.
  • Bachelor’s degree in a relevant field, or equivalent professional experience.
Responsibilities
  • Own the identity lifecycle, including joiner, mover, and leaver provisioning and deprovisioning, automated from role- and attribute-based models, with deprovisioning verified against an entitlement inventory.
  • Own access management, including Conditional Access, phishing-resistant multifactor authentication, and privileged access on a Zero Trust model, with least privilege by default, just-in-time elevation, and enforcement confirmed on every access path.
  • Own directory and federation across Entra ID, single sign-on, Security Assertion Markup Language, OpenID Connect, and OAuth 2.0.
  • Own secrets and non-human identity, including API keys, service accounts, and workload identity, and maintain an owner registry for them.
  • Own key access governance and separation of duties while another team operates the key management system.
  • Own identity automation and identity-as-code by building lifecycle and access controls as reviewable, version-controlled infrastructure using Terraform and policy-as-code.
  • Own the identity-verification standard followed by the service desk for password resets, multifactor authentication resets, and device enrollment.
  • Enforce Conditional Access by default on protected-health-information-facing applications and verify enforcement.
  • Deliver automated joiner, mover, and leaver provisioning and deprovisioning that consistently meets its service-level agreement.
  • Create a secrets golden path with vaulted secrets, no secrets in code, and a populated key-to-owner registry.
  • Establish strong, phishing-resistant multifactor authentication coverage on privileged accounts.
  • Document runbooks and build sufficient depth across the control plane so no critical control depends on a single person.
  • Set standards that partner teams execute while Service Delivery performs provisioning tasks and resets against the verification standard.
  • Govern cloud access, workload identity, and key-management operations performed by Cloud Engineering.
  • Use human-resources events as the sole trigger for lifecycle changes.
  • Maintain separation between entitlement production and independent access certification performed by the Governance, Risk & Compliance team.
Desired Qualifications
  • Experience in healthcare or another regulated environment where identity controls gate access to protected health information.
  • Hands-on experience with Saviynt with privileged access management, Azure Privileged Identity Management, and Keeper, or transferable depth in comparable platforms.
  • Experience remediating a Conditional Access enforcement gap or a deprovisioning failure and making a structural change that prevented recurrence.
  • Experience with passkeys and FIDO2, or phishing-resistant authenticators aligned with NIST Special Publication 800-63 Revision 4.
  • Experience growing a technical scope into a broader leadership remit.
  • Microsoft Identity and Access Administrator certification, CIMP, or an equivalent certification.

Lantern Care is a specialty care platform that helps self-funded employer health plans access high-quality, cost-effective care for complex needs. It builds a Network of Excellence by directly contracting top specialists and facilities, offering planned surgeries, cancer care, and infusion therapies with bundled payments. A dedicated care team guides members through diagnosis, scheduling, and follow-up, emphasizing local, accessible care that boosts utilization. Its goal is to reduce employer healthcare costs while improving patient outcomes by expanding access to specialty care through direct contracting and care navigation.

Company Size

501-1,000

Company Stage

Growth Equity (Venture Capital)

Total Funding

$31M

Headquarters

Dallas, Texas

Founded

2010

Get referred to Lantern Care

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • March 2026 Morgan Health capital signals JPMorganChase conviction in employer specialty-care economics.
  • June 2026 Marathon pilot showed 47% higher referrals and 53% average savings.
  • February 2026 cancer expansion added NCI reviews and clinical trial access.

What critics are saying

  • Unknown post-rebrand unit economics make the $30 million March 2026 raise look tactical.
  • Included Health, Carrum Health, and Quantum Health commoditize Lantern’s employer sales motion.
  • If 2027 renewals miss savings claims, employers cut Lantern after pilot disappointments.

What makes Lantern Care unique

  • March 2026 PSO made Lantern the only independent COE with an AHRQ-listed PSO.
  • June 2026 Marathon Health integration embeds Lantern referrals inside primary care workflows.
  • Quantum Health and Lantern combined navigation with specialty contracting for employer clients.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Short & Long Term Disability

Life Insurance

Paid Vacation

Paid Parental Leave

401(k) Company Match

Hybrid Work Options

Growth & Insights and Company News

Headcount

6 month growth

1%

1 year growth

0%

2 year growth

3%
Associated Press
Jun 18th, 2026
Marathon Health and Lantern partner to cut specialty care costs with integrated model

Marathon Health and Lantern have partnered to integrate primary and specialty care for employers and labour organisations, aiming to reduce specialty care costs. The collaboration connects Marathon's primary care model with Lantern's specialty care platform, allowing Marathon clients to purchase Lantern services directly. A pilot programme focusing on orthopaedic and surgical care showed a 37%-100% increase in Lantern referrals, a 47% rise in completed or avoided surgeries, and 53% average savings compared to network rates. Marathon providers will identify patients needing specialists and initiate referrals, whilst Lantern Care Advocates guide members through specialist selection and coordination. The integrated solution launches this year for shared customers, initially targeting orthopaedic surgery, a major employer cost driver.

PR Newswire
Mar 19th, 2026
Lantern Secures $30M Strategic Investment from Morgan Health and Echo Health Ventures to Help Employers Reduce Costs and Improve Outcomes for Specialty Care

/PRNewswire/ -- Lantern, the leading Specialty Care Platform serving 12 million people across the U.S., today announced a $30 million investment led by Morgan...

Coverager
Mar 20th, 2024
Healthjoy Selects Edh As Surgery Network Partner

Care navigation platform. HealthJoy <i class="fa fa-info-circle company-popover" data-content="h3HealthJoy/h3. div

FinSMEs
Dec 19th, 2023
Employer Direct Healthcare Raises $92M Investment from Insight Partners, At $1 Billion Valuation

Employer Direct Healthcare raises $92M investment from Insight Partners, at $1 Billion valuation.

PR Newswire
Dec 19th, 2023
Employer Direct Healthcare (EDH) Announces $92 Million Investment from Insight Partners, $1 Billion Valuation

/PRNewswire/ -- Employer Direct Healthcare (EDH), a leading specialty healthcare network solution, today announced a $92 million secondary investment from...