All roles

Sr. Full Stack Security Software Engineer IAM (Identity and Access Management) – Hybrid 3 days

Remote · USA Full-time New today

About the position This role will play a key role in designing, building, and maintaining the Identity and Access Management (IAM) systems that power CharmHealth’s cloud-based Electronic Health Record (EHR) platform. This position blends secure software engineering, cloud systems architecture, and regulatory compliance, ensuring that all users, integrations, and systems can safely access and interact within CharmHealth’s ecosystem. This engineer will own end to end development of authentication and authorization features such as Single Sign-On (SSO), Multi-Factor Authentication (MFA), federated identity, and role-based access control (RBAC) while embedding best practices for data protection and compliance with healthcare standards like HIPAA, NIST, SOC 2, and ISO 27001. The role requires a strong foundation in Java and Python, deep understanding of IAM protocols, and a passion for building secure, scalable distributed systems. The engineer will collaborate closely with Product Engineering, DevOps, and Security teams to implement new features, optimize performance, and ensure platform stability across CharmHealth’s fast-growing health technology environment. CharmHealth works like a startup and this candidate will need to be okay with wearing multiple hats and learning on the fly as well as be adaptable.

Responsibilities

  • Design, implement, and maintain secure authentication and authorization systems for CharmHealth’s cloud-based products.
  • Develop and enhance IAM features including user management, SSO, MFA, federated identity, and access delegation.
  • Collaborate with auditors and security teams to maintain compliance with HIPAA, NIST, SOC 2, and ISO 27001 frameworks.
  • Build and manage RESTful APIs, ensuring secure data exchange and integration with internal and third party applications.
  • Contribute to system architecture and design discussions, focusing on scalability, performance, and security.
  • Write clean, modular, testable code following best practices and participate in peer code reviews.
  • Diagnose and optimize performance issues across distributed environments (AWS, MySQL, Redis, Tomcat).
  • Partner with DevOps to embed identity and security best practices within deployment pipelines and cloud configurations.
  • Stay current on IAM and cybersecurity trends, continuously improving CharmHealth’s approach to authentication, access control, and data protection.
  • Mentor junior engineers and serve as a technical resource for IAM-related challenges within the product organization.

Requirements

  • Strong Java development experience (primary language) and working proficiency in Python. Multiple languages is preferred.
  • Deep understanding of authentication and authorization frameworks, including OAuth 2.0, SAML
  • Strong understanding of security standards and compliance frameworks relevant to healthcare (e.g., HIPAA, NIST, SOC 2, ISO 27001)
  • Knowledge of data security best practices, including encryption, secure key management, and safe data sharing.
  • Proven ability to build and support secure, full stack applications with authentication, authorization, and data protection components.
  • Experience integrating with or developing identity systems (e.g., Single Sign-On, multi-factor authentication, or role-based access).
  • Background in scalable software development from medium to large companies.
  • Strong coding ability, adaptability, and willingness to learn new systems and languages.
  • Excellent communication skills and comfort working in a collaborative, feedback driven environment.
  • Able to think "outside the box" with a good attitude
  • Bachelor’s degree in Computer Science, Software Engineering, or a related field (Master’s preferred)
  • Willing and able to work on site three days a week (Pleasanton, CA)

Nice-to-haves

  • Security related certifications (CISSP, Security+, AWS Security Specialty, etc.) are a plus

Apply tot his job Apply To this Job

Related roles

Identity and Access Management Engineer

Remote · USA Full-time

Senior Identity & Access Management Engineer

Remote · USA Full-time

Senior Privileged Access Management Engineer

Remote · USA Full-time

[Remote] REMOTE–Information Security Analyst (IAM Governance)

Remote · USA Full-time

Sr. Identity Governance (IGA) Engineer

Remote · USA Full-time

Manager (IC), Compliance – Identity & Access Management - Full-time

Remote · USA Full-time

Senior Identity & Access Management (IAM) Developer

Remote · USA Full-time

Associate Security Analyst

Remote · USA Full-time

Product Recovery & Quality Co-worker

Remote · USA Full-time

Concept Art Lead

Remote · USA Full-time

Customer Service Representative – Bilingual Student Success Advocate for Online Professional Education (English & Spanish)

Remote · USA Full-time

Immediate Hiring: Business Internship for college or high school

Remote · USA Full-time

[Work From Home] Delta Airlines Remote Jobs WFH

Remote · USA Full-time

Bilingual (Spanish and English) Licensed Property and Casualty Customer Service Representative (Remo

Remote · USA Full-time

Sr. Product Manager

Remote · USA Full-time

Resource Nurse (LPN)

Remote · USA Full-time

Experienced 6th Grade Montessori Teacher for Michigan's American Montessori Academy - Remote Teaching Opportunity with Competitive Salary and Benefits

Remote · USA Full-time

Remote Data Entry Clerk – Work From Home Opportunity | Flexible Hours | arenaflex Data Management Jobs

Remote · USA Full-time

Immediate Hiring: Customer Service Representatives/arenaflex Not-For-Profit Support

Remote · USA Full-time

Part-Time Yelp Spam Comment Remover ? Vacancy G...

Remote · USA Full-time