Cybersecurity IAM Engineer – SailPoint IdentityIQ (IIQ)

TheCorporate LLC

New York (NY)

Hybrid

USD 140,000 - 190,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

TheCorporate LLC is seeking a Cybersecurity IAM Engineer specializing in SailPoint IIQ/ISC to design, develop, and modernize enterprise identity governance across hybrid environments. You will lead lifecycle automation, integration patterns, and governance through ServiceNow workflows and IAM architecture leadership.

Candidate will secure IAM operations, enable RBAC/ABAC, and integrate with Entra ID, OCI, and external user identities while aligning with Zero Trust principles.

Qualifications

  • Design, implement, and maintain SailPoint IIQ and ISC solutions.
  • Develop and automate IAM workflows, connectors, and onboarding.
  • Administer Microsoft Entra ID (Azure AD) and PIM.
  • Integrate IAM with cloud platforms (AWS, Azure, GCP) and Okta.
  • Review code for optimization and early vulnerability detection.

Responsibilities

  • Design, implement, and maintain SailPoint IIQ and ISC solutions.
  • Develop and automate workflows, connectors, and application onboarding.
  • Administer and support Microsoft Entra ID (Azure AD), including PIM.
  • Integrate IAM systems with cloud platforms such as AWS, Azure, or GCP.
  • Implement and manage Okta solutions, focusing on Citizen IAM and external user identity needs.
  • Conduct code reviews to eliminate redundancies and optimize system logic.
  • Collaborate with stakeholders to mature RBAC/ABAC and onboarding programs.
  • Manage APIs, PAM tools, SailPoint Access History, and provisioning automation.
  • Test, deploy, and upgrade IAM systems; migrate IIQ to ISC for upcoming projects.

Skills

SailPoint IIQ
IdentityIQ Development
Identity Security Cloud
Okta
Citizen IAM
RBAC/ABAC
Zero Trust
IAM Architecture
ServiceNow collaboration
Java
BeanShell
REST API development
SCIM
OAuth/OIDC
Azure Entra ID
PIM
PAM

Tools

SailPoint IIQ
IdentityIQ
Identity Security Cloud
ServiceNow
Okta
Azure AD Entra ID
REST
SCIM
Java
BeanShell
PIM
PAM

Job description

Job Title: Cybersecurity IAM Engineer -- SailPoint IdentityIQ (IIQ)

Client Name: MTA

Location: 2 Broadway - MTA Headquarters Hybrid

Duration: Long term

Interview Mode: Phone then Video

Job description:

ONSITE POSITION with option for telecommuting no more then 2 days per week.

The Cybersecurity IAM Engineer / SailPoint IdentityIQ and Identity Security Cloud Developer & Architect is responsible for designing, engineering, and modernizing enterprise identity governance capabilities across hybrid cloud and on prem environments. This role blends deep SailPoint IdentityIQ and Identity Security Cloud development with IAM architecture leadership, including lifecycle automation, integration patterns, governance frameworks, and ServiceNow workflow orchestration.

The engineer will serve as a technical authority for identity lifecycle, access governance, directory integrations, and SailPoint platform architecture---ensuring secure, scalable, and compliant IAM operations aligned with Zero Trust principles.

SailPoint IIQ and ISC Developer/Administrator with Okta and Citizen IAM

We're looking for a talented SailPoint IIQ and ISC Developer/Administrator to join our team. You'll play a key role in developing, administering, and maintaining our identity and access management (IAM) solutions, ensuring secure and efficient access across our organization. Expertise in Okta and Citizen IAM initiatives is a strong plus.

What You’ll Do:
  • Design, implement, and maintain SailPoint IIQ and ISC solutions
  • Develop and automate workflows, connectors, and application onboarding
  • Administer and support Microsoft Entra ID (Azure AD), including Privileged Identity Management (PIM)
  • Integrate IAM systems with cloud platforms such as AWS, Azure, or GCP
  • Implement and manage Okta solutions, with a focus on Citizen IAM and external user identity needs
  • Conduct code reviews to eliminate redundancies and optimize system logic
  • Identify and address IAM vulnerabilities early in the development process
  • Collaborate with IT stakeholders and business owners to mature Role-Based Access Control (RBAC) andapplication onboarding programs
  • Manage and integrate APIs, privilege access management (PAM) tools, SailPoint Access History, SailPoint Access Modeling and database platforms
  • Test, deploy, and recommend patches and upgrades for IAM systems
  • Migration from IIQ to ISC for the upcoming project
SailPoint IdentityIQ Engineering & Development
  • Develop and maintain BeanShell rules, custom workflows, lifecycle event logic, task definitions, and plugin modules.
  • Engineer custom connectors, aggregation jobs, reconciliation logic, and provisioning adapters.
  • Build scalable application onboarding frameworks, entitlement schemas, and role models.
  • Implement and optimize certification campaigns, policy enforcement, SoD controls, and governance reporting.
  • Extend IIQ using Java, REST APIs, SCIM, and custom UI components.
IAM Architecture & Solution Design
  • Define and maintain end to end IAM architecture, including identity sources, directories, governance layers, and provisioning flows.
  • Architect scalable identity lifecycle frameworks supporting joiner/mover/leaver automation, authoritative source alignment, and attribute driven access.
  • Design integration patterns between SailPoint IIQ and ServiceNow, including:
    • Access request workflows
    • Automated ticket creation and closure
    • Provisioning orchestration
    • Incident and change management alignment
    • Catalog item governance and approval routing
  • Establish RBAC/ABAC frameworks, role mining strategies, and access modeling standards.
  • Create architectural diagrams, data flow maps, and governance models for enterprise IAM programs.
  • Evaluate modernization opportunities (e.g., SailPoint SaaS, passwordless, adaptive risk, ServiceNow IAM modules).
  • Lead design reviews, threat modeling sessions, and IAM roadmap planning with cybersecurity leadership.
Integration & Directory Services
  • Architect and implement integrations with Active Directory, LDAP, Azure AD/Entra ID, HR systems, cloud applications, and ServiceNow.
  • Develop REST/SOAP integrations, SCIM connectors, and custom provisioning logic.
  • Implement authentication and federation patterns using SAML, OAuth, OIDC, and MFA platforms.
  • Ensure directory hygiene, identity data quality, and lifecycle accuracy across systems.
ServiceNow Integration & Workflow Engineering
  • Design and maintain ServiceNow IAM workflows, including access request, approval routing, and fulfillment automation.
  • Integrate SailPoint IIQ with ServiceNow for:
    • Ticket based provisioning and deprovisioning
    • Automated incident creation for provisioning failures
    • Change management workflows tied to IAM operations
    • Catalog item governance and entitlement mapping
  • Collaborate with ServiceNow platform owners to ensure alignment between IAM processes and enterprise workflow standards.
  • Optimize ServiceNow to SailPoint to downstream system orchestration for speed, accuracy, and auditability.
  • Support migration or redesign efforts when ServiceNow is used as a front end for IAM services.
Security Engineering & Governance
  • Apply Zero Trust, least privilege, RBAC/ABAC, and governance principles to all IAM designs.
  • Engineer automated controls supporting SOX, HIPAA, ISO 27001, and NIST compliance.
  • Conduct root cause analysis for provisioning failures, connector issues, workflow errors, and performance bottlenecks.
  • Partner with security architects to align IAM architecture with enterprise cybersecurity strategy.
Operational Support & Platform Stability
  • Support production IIQ environments, including break/fix, patching, upgrades, and performance tuning.
  • Maintain detailed technical documentation, architectural diagrams, and operational runbooks.
  • Collaborate with HRIS, infrastructure, ServiceNow, and application teams to resolve identity issues and improve lifecycle reliability.
Technical Expertise
  • 5--9 years in IAM engineering, with 5--10 years of SailPoint IdentityIQ development.
  • Strong proficiency in Java, BeanShell, XML, JSON, SQL, and REST API development.
  • Deep understanding of IIQ object model, connector frameworks, workflow engine, and plugin architecture.
  • Hands on experience architecting integrations between SailPoint IIQ and ServiceNow.
  • Strong knowledge of directory services, identity stores, and authentication protocols.
Security & Governance
  • Expertise in identity governance concepts, RBAC/ABAC, SoD, and policy enforcement.
  • Familiarity with compliance frameworks (NIST)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SailPoint IdentityIQ Architect – C2C requirements– NYC
SailPoint IdentityIQ Architect – C2C requirements– NYC

Tech Mirrors • New York (NY)

Hybrid
USD 120,000 - 160,000
IT Security Operations
IT Security Operations

Creative Solutions Services, LLC • New York (NY)

Hybrid
USD 120,000 - 180,000
Telecommuting up to 2 days per week
Cybersecurity IAM Engineer – SailPoint IdentityIQ (IIQ)
Cybersecurity IAM Engineer – SailPoint IdentityIQ (IIQ)

Infosat IT Services LLC • New York (NY)

Hybrid
USD 140,000 - 190,000
Sailpoint ISC Consultant
Sailpoint ISC Consultant

InterSources Inc • New York (NY)

Hybrid
USD 150,000 - 210,000
IAM Engineer
IAM Engineer

V Group Inc. • New York (NY)

On-site
USD 140,000 - 190,000
Sr IAM Developers - US Location
Sr IAM Developers - US Location

Bridgesoftsol • United States

On-site
USD 100,000 - 130,000
IAM Developer - US Location
IAM Developer - US Location

Bridgesoftsol • United States

On-site
USD 110,000 - 140,000
Senior SailPoint Engineer
Senior SailPoint Engineer

RedMatter Solutions • Washington

On-site
USD 150,000 - 190,000
Senior SailPoint Developer
Senior SailPoint Developer

Delan Associates, Inc • San Francisco (CA)

On-site
USD 140,000 - 200,000
Identity Governance & Administration Engineer
Identity Governance & Administration Engineer

Quarry Consulting • United States

Remote
CAD 90,000 - 120,000