Staff IT Engineer

Headway· New York, New York, NY, San Francisco, San Francisco, CA, Seattle, Seattle, WA· ashby· pubblicata il 16/06/2026
Indispensabile:FinTechHealthTechSecurityLead

1 in 4 people in the US have a treatable mental health condition, but most providers don't accept insurance, making therapy too expensive for most people. Headway’s mission is to fix this by building a new mental healthcare system everyone can access. We started by solving the biggest barrier to care: insurance. The admin work - credentialing, claims, payment reconciliation - is a nightmare. We've automated that.

But we're going further. Over 75,000 providers across all 50 states run their practice on our software, serving over 1 million patients. We are building the best tools for therapists to run their entire practice, reimagining the experience of finding a therapist, and investing in the platform foundations to enable this at scale. We aren't just a billing layer; we are becoming the platform where care actually happens.

We're a Series D company with $325M+ in funding (a16z, Accel, Spark Capital, etc.), looking for exceptional people to help us achieve this mission. We want your time here to be the most meaningful experience of your career. Join us, and help change mental healthcare for the better.

Identity and access is foundational to how Headway operates securely at scale. In this role you will set the direction for our identity and access program, resolve the hardest architectural problems where identity, endpoint, security, and the broader IT platform intersect, and raise the technical bar for the engineers around you. You will be deepest in IAM, but you will lead well beyond it.

YOU’LL LOVE THIS ROLE IF YOU WANT TO:

  • Set the multi-year direction for identity and access at Headway. Own the IAM strategy and roadmap (lifecycle, JML automation, IdP architecture) as a group-level program tied to business outcomes, not just a set of workflows to run.
  • Represent identity in company-wide engineering and security strategy. Bring a point of view to architecture and platform decisions, and be the person leadership consults on where identity and access should go next.
  • Resolve the hard, cross-domain architectural problems where identity, endpoint, security, and the broader IT platform intersect: API/SCIM/OIDC/SAML integration design, RBAC modeling, and device-to-identity trust. Set the patterns other engineers build on.
  • Lead the org-wide move to least-privilege / RBAC as a change program: define the model, sequence the rollout, manage user impact, and drive cross-functional adoption across pods so it actually sticks.
  • Raise the automation and reliability bar. Architect provisioning, de-provisioning, and access-change automation that eliminates manual toil at scale, and set the standards and guardrails the team builds against, rather than just authoring individual integrations.
  • Own major identity incidents end-to-end. Lead response and postmortems for high-severity identity and access events and turn the learnings into durable reliability and control improvements.
  • Level up the team. Mentor engineers across IT Engineering, set documentation and quality standards, and advise leadership on identity and access risk, tooling, and investment.

YOU MAY BE A GOOD FIT IF YOU:

  • Have 7+ years in IAM / identity engineering in fast-paced SaaS environments supporting a distributed workforce, with deep Okta expertise, and enough breadth across endpoint, security, and IT platform to lead beyond identity alone.
  • Have defined the technical strategy and architecture for identity programs, not just implemented them, including JML automation and SaaS integration via APIs, SCIM, and OIDC/SAML.
  • Have led organization-wide access-control or RBAC deployments as the technical owner, driving cross-functional alignment and managing user impact at scale.
  • Set standards other engineers follow. You've established patterns, guardrails, and documentation practices that outlast any single project.
  • Represent technical decisions to senior stakeholders and leadership, synthesizing complex tradeoffs into clear direction that drives business efficiency.
  • Mentor and grow other engineers, and actively shape team culture, hiring, and onboarding.
  • Lead incident response and reliability improvements for identity-critical systems.
  • Operate with autonomy and methodical ownership, planning and executing group-level work with visibility, and stay current on identity and privacy best practices in a regulated (HIPAA / SOC 2 / HITRUST) environment.

TOOLS WE USE:

  • Identity and Access Management: Okta, Lumos
  • Email and Messaging: Gmail and Slack
  • Document Creation and Collaboration: Google Workspace, Confluence
  • Credential Management: 1Password
  • Ticketing: Jira Service Desk, ZenDesk, Jira Projects
  • Project Planning: Jira
  • Endpoint Management: Iru, InTune, ChromeOS, Kolide

We believe a team's strength is in its people, and we cannot achieve this mission without a team that reflects the diversity of this problem – across race, ethnicity, gender, sexuality, age, national origin, religion, family status, disability, military status, and experience. Headway is committed to the full inclusion of all qualified individuals. As part of this commitment, Headway will ensure that persons with disabilities are provided with reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or receive other benefits and privileges of employment, please inform the recruiter when they contact you to schedule your interview.

Headway participates in E-Verify. To learn more, click here. https://www.e-verify.gov/sites/default/files/everify/posters/EVerifyParticipationPoster.pdf

A notice to Headway applicants: To protect yourself against phishing and recruitment fraud, please note that Headway only accepts applications through our official careers page at https://headway.co/careers. Headway will never refer you to external websites, ask for payment or personal information, or conduct interviews via messaging apps. All official communication will come from a @findheadway.com http://findheadway.com email address. If you are contacted by someone claiming to be from Headway via an unofficial channel, please do not share any information and report it as spam.