Search

Senior SailPoint IAM Engineer / Architect - IAMENGG 26-11213

PublishedPublished: 6/14/2022
Technology

Job Description

Job DescriptionSenior SailPoint IAM Engineer / Architect

Location: NYC, NY
Duration: 12 Months
Work Schedule: 37.5 Hours/Week

Position Overview

We are seeking a highly skilled Senior SailPoint IAM Engineer / Architect to design, engineer, and modernize enterprise Identity and Access Management (IAM) capabilities across hybrid cloud and on-premises environments.

This role combines deep expertise in SailPoint IdentityIQ (IIQ) and SailPoint Identity Security Cloud (ISC) development with IAM architecture leadership. The ideal candidate will have strong experience with identity lifecycle automation, integration patterns, governance frameworks, directory services, and ServiceNow workflow orchestration.

The engineer will serve as a technical authority for identity lifecycle management, access governance, directory integrations, and SailPoint platform architecture while ensuring secure, scalable, and compliant IAM operations aligned with Zero Trust principles.

Key Responsibilities SailPoint IIQ & ISC Development / Administration

  • Design, implement, administer, and maintain SailPoint IdentityIQ and Identity Security Cloud solutions.
  • Develop and automate IAM workflows, connectors, application onboarding, and provisioning processes.
  • Develop and maintain BeanShell rules, custom workflows, lifecycle event logic, task definitions, and plugin modules.
  • Engineer custom connectors, aggregation jobs, reconciliation logic, and provisioning adapters.
  • Build scalable application onboarding frameworks, entitlement schemas, and role models.
  • Implement and optimize certification campaigns, policy enforcement, Segregation of Duties (SoD) controls, and governance reporting.
  • Extend SailPoint IIQ using Java, REST APIs, SCIM, and custom UI components.
  • Support migration from SailPoint IdentityIQ to Identity Security Cloud (ISC).
  • Conduct code reviews to eliminate redundancies and optimize system logic.
  • Test, deploy, and recommend patches and upgrades for IAM platforms.

IAM Architecture & Solution Design

  • Define and maintain end-to-end IAM architecture covering identity sources, directories, governance layers, and provisioning flows.
  • Architect scalable identity lifecycle frameworks supporting Joiner/Mover/Leaver (JML) automation.
  • Align authoritative identity sources and implement attribute-driven access models.
  • Establish RBAC/ABAC frameworks, role-mining strategies, and access-modeling standards.
  • Create architectural diagrams, data-flow maps, and governance models for enterprise IAM programs.
  • Evaluate IAM modernization opportunities, including SaaS-based IAM, passwordless authentication, adaptive risk, and modern IAM workflow capabilities.
  • Lead design reviews, threat-modeling sessions, and IAM roadmap planning with cybersecurity leadership.

Directory & System Integrations

  • Architect and implement integrations with:
    • Active Directory
    • LDAP
    • Microsoft Entra ID (Azure AD)
    • HR systems
    • AWS, Azure, and GCP
    • Cloud applications
    • ServiceNow
  • Develop REST/SOAP integrations, SCIM connectors, and custom provisioning logic.
  • Integrate and administer Microsoft Entra ID, including Privileged Identity Management (PIM).
  • Implement authentication and federation patterns using SAML, OAuth, OIDC, and MFA platforms.
  • Ensure directory hygiene, identity-data quality, and accurate lifecycle management across systems.
  • Manage and integrate APIs, Privileged Access Management (PAM) tools, SailPoint Access History, Access Modeling, and database platforms.

Okta & Citizen IAM

  • Implement and manage Okta solutions.
  • Support Citizen IAM initiatives and external-user identity requirements.
  • Design secure identity experiences for external and customer-facing users.
  • Integrate Okta and other authentication platforms with enterprise IAM and application environments.

ServiceNow Integration & Workflow Engineering

  • Design and maintain ServiceNow IAM workflows, including access requests, approval routing, and fulfillment automation.
  • Integrate SailPoint IIQ with ServiceNow for:
    • Ticket-based provisioning and deprovisioning
    • Automated incident creation for provisioning failures
    • Change-management workflows tied to IAM operations
    • Catalog item governance
    • Entitlement mapping
  • Design automated ticket creation and closure processes.
  • Support provisioning orchestration and incident/change-management alignment.
  • Collaborate with ServiceNow platform teams to align IAM processes with enterprise workflow standards.
  • Optimize ServiceNow → SailPoint → downstream system orchestration for speed, accuracy, and auditability.
  • Support migration or redesign initiatives where ServiceNow serves as the front end for IAM services.

Security & Governance

  • Apply Zero Trust, least privilege, RBAC, ABAC, and identity governance principles to IAM designs.
  • Engineer automated controls supporting compliance requirements and security frameworks.
  • Support governance requirements related to SOX, HIPAA, ISO 27001, and NIST.
  • Identify and address IAM vulnerabilities early in the development lifecycle.
  • Conduct root-cause analysis for provisioning failures, connector issues, workflow errors, and performance bottlenecks.
  • Partner with security architects to align IAM architecture with enterprise cybersecurity strategy.
  • Collaborate with IT stakeholders and business owners to mature RBAC and application-onboarding programs.

Operational Support & Platform Stability

  • Support production SailPoint IIQ environments, including break/fix, patching, upgrades, and performance tuning.
  • Maintain detailed technical documentation, architectural diagrams, and operational runbooks.
  • Monitor and troubleshoot IAM platform performance and reliability.
  • Collaborate with HRIS, infrastructure, ServiceNow, application, and security teams to resolve identity-related issues.
  • Improve identity lifecycle reliability, automation, and operational efficiency.

Required Technical Expertise

  • 5–9 years of IAM engineering experience, with approximately 5–10+ years of SailPoint IdentityIQ development.
  • Strong experience with SailPoint IdentityIQ and Identity Security Cloud.
  • Strong proficiency in:
    • Java
    • BeanShell
    • XML
    • JSON
    • SQL
    • REST APIs
  • Deep understanding of SailPoint IIQ object model, connector frameworks, workflow engine, and plugin architecture.
  • Hands-on experience architecting SailPoint IIQ and ServiceNow integrations.
  • Strong knowledge of directory services, identity stores, and authentication protocols.
  • Experience with Microsoft Entra ID / Azure AD and PIM.
  • Experience with Okta and Citizen IAM is highly desirable.
  • Experience integrating IAM platforms with cloud environments such as AWS, Azure, and GCP.
  • Knowledge of PAM technologies, SCIM, SAML, OAuth, OIDC, and MFA.

Security & Governance Qualifications

  • Strong expertise in identity governance concepts.
  • Experience with RBAC, ABAC, SoD, least privilege, and policy enforcement.
  • Familiarity with security and compliance frameworks, particularly NIST.
  • Experience implementing IAM controls for enterprise security and regulatory compliance.
  • Strong analytical, troubleshooting, communication, and architecture skills.
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...