STEM OPT Iam Engineer Jobs
IAM Engineer roles in identity governance, access provisioning, and zero-trust architecture sit squarely within STEM OPT eligibility. Your STEM degree qualifies you for a 24-month extension beyond your initial 12-month OPT period, giving you up to 36 months total, as long as your employer is enrolled in E-Verify.
Find STEM OPT Iam Engineer JobsOverview
Showing 5 of 17+ Iam Engineer jobs










See all Iam Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Iam Engineer roles.
Get Access To All Jobs
Our Mission:
Our mission is to SAVE AND IMPROVE LIVES BY EMPOWERING HEALTHCARE CONSUMERS. Come be part of remarkable.
Overview:
We are CONNECTING HEALTH AND WEALTH. Come be part of remarkable.
HealthEquity is hiring! Come join us as an Access Ops Analyst in our Identity and Access Management Security Team.
How you can make a difference
As an Access Operations Analyst within the Identity and Access Management (IAM) Operations team, you will be responsible for ensuring secure, timely, and efficient identity lifecycle management within HealthEquity’s technologies. This role ensures employees and business partners have timely access to the resources they need while balancing strong security controls with exceptional customer service. This role requires attention to detail, the ability to work independently, interaction with internal IT and business customers, as well as collaboration with a dynamic team. The successful candidate will have a thorough understanding of access management concepts and technologies.
What you’ll be doing
Identity Lifecycle Management:
- Manage the end-to-end identity lifecycle by provisioning, modifying, and deprovisioning user access while ensuring compliance with established IAM policies and controls
- Support Microsoft Entra ID, Active Directory, Azure, Exchange, and related identity platforms to maintain accurate and secure user access
- Configure and troubleshoot multi-factor authentication methods, including Passkeys, Yubikeys, FIDO2 credentials, and Microsoft Authenticator registrations
Risk Management:
- Work closely with the cybersecurity team to respond to incidents and implement corrective actions
- Contribute to a balanced security-first and customer service culture
Team Cooperation:
- Partner with your team of IAM professionals; collaborate, support initiatives, and foster a culture of continuous learning and development
- Coordinate with cross-functional teams to ensure successful support of IAM tasks
What you will need to be successful
- Demonstrated experience managing the full identity lifecycle, including provisioning, deprovisioning, access governance, role management, birthright access, and compliance-driven access controls
- Experience supporting Microsoft Entra ID, Active Directory, Azure, and Exchange environments with a strong understanding of account administration and group management
- Knowledge of BeyondTrust and privileged access management practices, including administration of privileged accounts, password vaulting, and service account controls
- Hands-on experience configuring and troubleshooting MFA solutions, including YubiKey registration and Passkeys
- Ability to investigate and resolve identity and access issues, including lifecycle state discrepancies, birthright access failures, account correlation problems, provisioning errors, and orphaned accounts
- Capable of processing high-volume access requests, validating approvals, maintaining audit evidence, supporting access review remediation, and executing provisioning and deprovisioning activities with accuracy and timeliness
- Excellent communication skills with the confidence to ask clarifying questions, challenge ambiguous requests, collaborate with stakeholders, and provide exceptional customer service while maintaining security standards
- Strong analytical and troubleshooting abilities with the capacity to perform root cause analysis, identify process gaps, interpret IAM policies, and drive issue resolution across multiple systems
- Experience using PowerShell, Python, Excel, automation tools, and AI technologies—including generative AI, machine learning–driven insights, and intelligent workflow automation—to improve operational efficiency, enhance reporting and analytics capabilities, identify opportunities for process optimization, reduce manual effort, and streamline identity and access management processes while supporting data-driven decision-making
- Ability to create and maintain SOPs to support consistency, compliance, and audit-ready IAM operations
- Bachelor’s degree, or the equivalent years' related experience in Identity and Access Management (IAM), IT Support, or Security Operations
Location:
This is a remote position.
Salary Range:
$34.62 To $42.00 / hour
Benefits & Perks:
The actual compensation offer is determined based on job-related knowledge, education, skills, experience, and work location. This position will be eligible for performance-based incentives as part of the total compensation package, in addition to a full range of benefits including:
- Medical, dental, and vision
- HSA contribution and match
- Dependent care FSA match
- Full-time team members receive a minimum of 18 days of annual PTO and 13 paid holidays per year
- Paid parental leave
- 401(k) match
- Personal and healthcare financial literacy programs
- Ongoing education & tuition assistance
- Gym and fitness reimbursement
- Wellness program incentives
Onboarding & Travel
This is a remote role, with an in-person onboarding training component. New team members must participate in Trailhead, HealthEquity’s immersive onboarding experience. Trailhead is designed to foster meaningful connections, support your integration into the organization, and equip you with a strong understanding of our business. Trailhead participation is a key expectation of this role. Trailhead is held onsite at our headquarters once per quarter. HealthEquity covers all required travel and accommodations.
This role may begin with a virtual, self-paced onboarding experience, followed by a mandatory onsite Trailhead session at a later date.
HealthEquity is committed to providing reasonable accommodations to team members with qualifying disabilities. Should you be selected for this role and require an accommodation, we will put you in touch with our Benefits Team so you can begin the accommodation request process.
Why work with HealthEquity:
HealthEquity has a vision that by 2030 we will make HSAs as widespread and popular as retirement accounts. We are passionate about providing a solution that allows American families to connect health and wealth. Join us and discover a work experience where the person is valued more than the position. You belong at HealthEquity!
HealthEquity, Inc. is an equal opportunity employer, and we are committed to being an employer where no matter your background or identity – you feel welcome and included. We ensure equal opportunity for all applicants and employees without regard to race, age, color, religion, sex, sexual orientation, gender identity, national origin, status as a qualified individual with a disability, veteran status, or other legally protected characteristics. HealthEquity is a drug-free workplace. For more information about our EEO policy, or about HealthEquity’s applicant disability accommodation, drug-free workplace, background check, and E-Verify policies, please visit our Careers page.
HealthEquity uses Microsoft Copilot to transcribe screening interviews between candidates and their direct Talent Partner for note taking and interview summaries. By scheduling a screening interview with us, you consent to Microsoft Copilot’s AI technology recording and transcribing your interview with your Talent Partner. This information will be reviewed for accuracy and then used by HealthEquity to summarize the interview, ensure accuracy, and facilitate our hiring process. We take privacy seriously. You have the option to opt out. If you wish to opt out of this Microsoft Copilot transcription, please notify your Talent Partner in advance of the interview. If we do not receive an opt-out request from you, we will assume that you consent to the use of Microsoft Copilot.
At HealthEquity, our goal is to save and improve lives by empowering healthcare consumers. This shared purpose inspires everything we do, including how we approach hiring. Our process is designed to get to know the real you: your skills, experiences, and potential to make a difference. We value honesty, originality, and the courage to do the right thing, even when it is not the easiest path. Showing up as your authentic self reflects these values and helps us build something truly remarkable together.
As AI is becoming a common tool throughout the application process, we want to be clear about its appropriate use at HealthEquity. Using AI to support resume writing, research, or interview preparation is perfectly acceptable, provided the content is accurate and genuinely represents your qualifications and skills. For other key parts of our interview process, however, it is important that the ideas, communication, and work you share reflect your own voice, experiences, and thinking. We ask that you participate in our live interviews and complete any assessments without AI assistance unless instructions explicitly indicate otherwise or a specific exception is discussed and approved in advance. This approach ensures fairness, celebrates your individuality, and allows your authentic perspective to shine. Behaviors that do not align with these guidelines may result in disqualification from the hiring process or termination of employment if later discovered. We appreciate your understanding and look forward to learning about the unique contributions only you can bring to HealthEquity.
HealthEquity is committed to your privacy as an applicant for employment. For information on our privacy policies and practices, please visit HealthEquity Privacy.
See all STEM OPT Iam Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT Iam Engineer Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization as an Iam Engineer
Verify your CIP code before applying
IAM Engineering draws from Computer Science, Information Security, and Systems Engineering CIP codes. Confirm your degree's CIP code with your DSO before applying, because a mismatch delays your I-983 approval and can shorten your authorized work period.
Check E-Verify enrollment before accepting offers
An employer who isn't enrolled in E-Verify cannot legally employ you on STEM OPT extension. Search the E-Verify employer search tool by company name before your final interview to avoid accepting an offer you can't use.
Tailor your I-983 to IAM engineering deliverables
Generic training plans get rejected. List specific learning objectives tied to IAM tools you'll use, such as identity lifecycle management, RBAC policy design, or SCIM integration, so the plan demonstrates a direct connection to your STEM degree field.
Target employers with active identity security teams
Use Migrate Mate to filter for employers who have hired STEM OPT candidates in technology and information security roles, giving you a verified starting point instead of applying blind to companies with no track record of supporting OPT extensions.
Use OFLC Wage Search to benchmark your offer
STEM OPT employers must pay you the same wage as similarly situated U.S. workers. Pull the prevailing wage for your specific IAM role and location using OFLC Wage Search before negotiating, so you can flag any offer that falls below the required threshold.
File your extension application 90 days early
USCIS requires your STEM OPT extension application to be filed at least 90 days before your initial OPT expires. Missing that window means a gap in work authorization, and IAM contract roles often can't absorb even a short break in employment eligibility.
Frequently Asked Questions
Does an IAM Engineer role qualify for the STEM OPT extension?
Yes, provided your underlying degree falls under an eligible STEM CIP code such as Computer Science, Information Technology, or Electrical Engineering, and the IAM Engineer role you're hired into is directly related to that field. Your DSO confirms the CIP code match when endorsing your I-20 for the extension. Roles focused on identity governance, access management, or security architecture consistently satisfy the relatedness requirement.
What does the E-Verify requirement mean for IAM Engineer job seekers?
Every employer who hires you on a STEM OPT extension must be actively enrolled in E-Verify, the federal electronic employment eligibility system. This applies regardless of company size or whether the role is remote. Before accepting any IAM Engineer offer, confirm enrollment through the E-Verify employer search. If the company isn't enrolled, they must join E-Verify before your extension start date or you can't legally begin work.
What goes into an I-983 training plan for an IAM Engineer?
The I-983 must map your IAM Engineer duties to specific learning outcomes tied to your STEM degree. Include concrete objectives such as designing role-based access control policies, integrating identity providers using SAML or OIDC, or auditing privileged access workflows. Generic descriptions like 'gain industry experience' are routinely rejected. Your employer's supervisor signs off, and your DSO reviews it before endorsing your I-20 for the extension.
How does cap-gap protection apply if I'm transitioning from STEM OPT to H-1B?
If your employer files an H-1B visa petition on your behalf before your STEM OPT expires and you're selected in the lottery, cap-gap automatically extends your work authorization through September 30 of that year, or until USCIS adjudicates the petition. You can continue working as an IAM Engineer throughout that period without interruption, as long as your employer remains E-Verify enrolled and your I-983 training plan stays current.
Where can I find IAM Engineer roles where employers already support STEM OPT?
Migrate Mate filters IAM Engineer listings by employers who have a documented history of hiring international students on work authorization, so you're not starting from scratch trying to educate hiring managers about E-Verify or STEM OPT rules. Search by role, location, and authorization type to surface employers prepared to move quickly through the I-983 and E-Verify steps without delays from unfamiliarity.