Oak Street Health, part of CVS Health logo

Software Development Engineer (SailPoint Administrator)

Oak Street Health, part of CVS Health

Remotemid$65k–$173kPosted 1h ago

Job description

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

Position Summary

The Software Development Engineer (SDE) will be responsible for designing, developing, testing, and maintaining the enterprise Identity Governance and Administration (IGA) platform that supports CVS Health's Healthcare Delivery (HCD) division, spanning Signify Health, Oak Street Health, and RubiconMD. This role partners closely with Compliance, Identity Architecture, Network Operations, and Security teams to deliver reliable, secure, and auditable identity and access management solutions. The engineer will contribute to core IAM platform services built on SailPoint Identity Security Cloud, including provisioning workflows, lifecycle automation, role-based access control (RBAC), access certification, and compliance reporting, while ensuring adherence to enterprise standards and best practices.

Required Qualifications

  • 3+ years of SailPoint Engineering experience building enterprise-grade applications and services.

  • 2+ years of hands-on SailPoint experience (IdentityNow / Identity Security Cloud).

  • Candidates must be able to independently configure and troubleshoot SailPoint connectors, rules, transforms, and workflows from day one.

  • Hands-on experience with identity provisioning architectures spanning HRIS, directory services, and identity providers (e.g., Workday, Active Directory, Okta).

  • Understanding of software design patterns, scalable system design, and data modeling as applied to identity governance.

  • Experience building and maintaining Joiner/Mover/Leaver/Rehire/Inactive lifecycle workflows and Role-Based Access Control (RBAC) models.

  • Strong analytical, problem-solving, and troubleshooting skills, including the ability to diagnose issues across multiple connected identity systems.

  • Ability to work effectively in Agile/Scrum development environments.

  • Excellent written and verbal communication skills with the ability to collaborate across technical, compliance, and business teams.

Preferred Qualifications

  • Experience supporting SOX, SOC2, or HiTrust compliance programs, including access certification campaigns, Separation of Duties (SoD) reporting, and Periodic Access Reviews (PAR), and NIST framework.

  • Experience in a multi-tenant or multi-company (M&A-integrated) identity environment, including cross-corporate access patterns.

  • Familiarity with Okta Workforce administration and AD-to-IDP provisioning flows (this role is SailPoint-focused; Okta exposure is a plus, not a requirement).

  • Experience developing and consuming RESTful APIs and working with JSON-based integrations.

  • Familiarity with Neo4j or graph-based identity stores and Azure-hosted identity infrastructure.

  • Exposure to healthcare or other highly regulated industries with secure data handling practices.

  • SailPoint IdentityNow/ISC certifications.

  • Experience leading technical initiatives or mentoring engineers on identity governance best practices.

  • Knowledge of CI/CD pipelines, source control systems (Git/GitHub), and automated deployment practices as applied to IAM platform configuration and code.

Education

  • Bachelor's degree in Computer Science, Software Engineering, Information Systems, or a related technical field; or 4+ years of progressive, hands-on experience in Identity and Access Management in lieu of a degree.

  • An equivalent combination of education, professional training, and relevant work experience may be considered.

Key Technologies: SailPoint Identity Security Cloud (ISC/IdentityNow), REST APIs, JSON, Active Directory, Okta Workforce, Workday, Neo4j, Git/GitHub, CI/CD, ServiceNow (self-service access requests), Confluence.

Anticipated Weekly Hours

40

Time Type

Full time

Pay Range

The typical pay range for this role is:

$64,890.00 - $173,040.00

This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above.

Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.

Great benefits for great people

We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.

Additional details about available benefits are provided during the application process and on Benefits Moments.

We anticipate the application window for this opening will close on: 09/11/2026

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.