Lead Identity Governance & Administration (IGA) Engineer

Federal Reserve Bank of New York

San Francisco (CA)

On-site

USD 150,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, Vision
Matching 401(k)
Paid vacation/holidays

Job summary

Federal Reserve Bank of San Francisco seeks a Saviynt IGA Lead Engineer/Architect to provide technical leadership, platform ownership, and post-go-live support for a Saviynt IGA environment. Candidate will lead design, mentoring, and long-term strategy across IAM, cybersecurity, data, and systems engineering.

The role emphasizes hands-on Saviynt, enterprise security operations, and audit readiness within a regulated environment.

Qualifications

  • Extensive hands-on experience with Saviynt IGA or comparable SaaS IGA platforms.
  • Strong background in Identity Governance and Administration, IAM, cybersecurity, access control, and enterprise security operations.
  • Experience with Joiner-Mover-Leaver processes, access requests, certifications, provisioning, role management, policy configuration, and application onboarding.
  • Strong understanding of connectors and integrations, including REST APIs, SCIM, JDBC, LDAP, SOAP, flat files, directories, SaaS applications, and enterprise systems.
  • Experience with HR source integrations, Active Directory, Microsoft Entra ID / Azure AD, cloud applications, and hybrid enterprise environments.
  • Strong data architecture and analytical skills, including identity data modeling, correlation, reconciliation, normalization, reporting, and data-quality analysis.
  • Systems engineering experience with production platforms, infrastructure, monitoring, incident management, change control, release management, and operational support.
  • Cybersecurity experience with least privilege, access risk, privileged access, audit controls, compliance, segregation of duties, and secure integration practices.
  • Ability to troubleshoot complex issues across applications, infrastructure, identity data, workflows, connectors, and security controls.
  • Excellent communication, documentation, leadership, training, mentorship, and stakeholder-management skills.

Responsibilities

  • Lead engineering and technical architecture for the SaaS IGA platform.
  • Own platform design, configuration, validation, troubleshooting, production readiness, and post-go-live stabilization.
  • Validate Joiner-Mover-Leaver processes and deprovisioning.
  • Ensure connector stability, account and entitlement aggregation, provisioning, and reconciliation accuracy.
  • Configure and support access workflows, approvals, certifications, roles, policies, and provisioning rules.
  • Partner with IAM, cybersecurity, HR, infrastructure, application owners, audit/compliance, and vendor teams.
  • Lead root-cause analysis and resolution of complex platform, workflow, connector, data, and provisioning issues.
  • Analyze identity, account, and entitlement data to identify risks and improve accuracy.
  • Support audit, compliance, least-privilege, access reviews, privileged access, and segregation-of-duties requirements.
  • Develop technical documentation, playbooks, operating procedures, and knowledge transfer materials.
  • Train and mentor IAM engineers and support teams on Saviynt operations and best practices.
  • Provide strategic recommendations to improve IGA maturity, automation, and security.

Skills

Saviynt IGA
Identity governance
IAM
Leadership

Education

Bachelor's degree in Computer Science or related field

Tools

REST APIs
SCIM
LDAP
JDBC
SOAP
Flat files
Active Directory
Azure AD

Job description

Role Overview

Company Federal Reserve Bank of San Francisco We are seeking a highly experienced Saviynt Identity Governance and Administration (IGA) Lead Engineer / Architect to provide technical leadership, platform ownership, and post-go-live support for our Saviynt IGA environment. This role will serve as the primary technical lead responsible for ensuring the platform is stable, secure, scalable, well documented, and ready for enterprise production operations. The ideal candidate is a seasoned IAM, cybersecurity, data, and systems engineering professional with handson experience in Saviynt or comparable SaaS IGA platforms. This person will lead technical design, train and mentor the internal team, support go-live readiness, and guide the long-term IGA strategy after implementation.

Responsibilities
  • Serve as the lead engineer and technical architect for the SaaS IGA platform.
  • Own platform design, configuration, validation, troubleshooting, production readiness, and post-go-live stabilization.
  • Validate Joiner-Mover-Leaver processes, including onboarding, transfers, terminations, rehires, and deprovisioning.
  • Ensure connector stability, account aggregation, entitlement aggregation, provisioning, deprovisioning, and reconciliation accuracy.
  • Configure and support access request workflows, approval routing, access certifications, role models, policies, and provisioning rules.
  • Partner with IAM, cybersecurity, HR, infrastructure, application owners, audit/compliance, and vendor teams.
  • Lead root-cause analysis and resolution of complex platform, workflow, connector, data, and provisioning issues.
  • Analyze identity data, account data, entitlement data, access models, and provisioning outcomes to identify risks and improve accuracy.
  • Support audit, compliance, least‑privilege, access review, privileged access, and segregation-of-duties requirements.
  • Develop technical documentation, runbooks, operating procedures, support guides, and knowledge transfer materials.
  • Train, mentor, and guide IAM engineers and support teams on Saviynt operations, troubleshooting, and best practices.
  • Provide strategic recommendations to improve IGA maturity, automation, scalability, security, and operational efficiency.
Qualifications
  • Extensive hands‑on experience with Saviynt IGA or comparable SaaS IGA platforms.
  • Strong background in Identity Governance and Administration, IAM, cybersecurity, access control, and enterprise security operations.
  • Experience with Joiner‑Mover‑Leaver processes, access requests, certifications, provisioning, role management, policy configuration, and application onboarding.
  • Strong understanding of connectors and integrations, including REST APIs, SCIM, JDBC, LDAP, SOAP, flat files, directories, SaaS applications, and enterprise systems.
  • Experience with HR source integrations, Active Directory, Microsoft Entra ID / Azure AD, cloud applications, and hybrid enterprise environments.
  • Strong data architecture and analytical skills, including identity data modeling, correlation, reconciliation, normalization, reporting, and data‑quality analysis.
  • Systems engineering experience with production platforms, infrastructure, monitoring, incident management, change control, release management, and operational support.
  • Cybersecurity experience with least privilege, access risk, privileged access, audit controls, compliance, segregation of duties, and secure integration practices.
  • Ability to troubleshoot complex issues across applications, infrastructure, identity data, workflows, connectors, and security controls.
  • Excellent communication, documentation, leadership, training, mentorship, and stakeholder‑management skills.
  • Must be a U.S. Citizen.
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Information Technology, Data Engineering, Systems Engineering, or a related technical field required. Equivalent combination of advanced technical certifications and extensive enterprise IAM/IGA experience may be considered in lieu of a degree.
Preferred Qualifications
  • Saviynt IGA certification required or must be obtained within an agreed period after hire, such as Saviynt Certified IGA Professional, Saviynt Administrator, Saviynt Engineer, Saviynt Architect, or equivalent current Saviynt certification.
  • Other IGA/IAM certifications from vendors such as SailPoint, Okta, Ping Identity, CyberArk, Microsoft, Oracle, or equivalent.
  • Microsoft identity or cloud certifications such as Microsoft Entra ID, Azure Administrator, Azure Security Engineer, or related Microsoft security and identity credentials.
  • Cybersecurity certifications such as CISSP, CISM, CISA, Security+, CCSP, or equivalent.
  • Cloud certifications from AWS, Microsoft Azure, or Google Cloud focused on security, identity, architecture, or systems engineering.
  • Experience leading enterprise Saviynt implementations and post-go-live support.
  • Experience building operational support models for IGA platforms.
  • Experience with role mining, role engineering, access certification campaigns, application onboarding, and audit evidence preparation.
  • Experience working in regulated, audit-driven, or security-sensitive environments.
  • Strong SQL, reporting, data analysis, data governance, or data architecture experience.
  • Experience advising leadership on IAM strategy, IGA roadmap planning, risk reduction, and platform maturity.
Benefits
  • Medical, Dental, Vision, Pre‑tax Flexible Spending Account, Backup Child Care Program, Pre‑Tax Day Care Flexible Spending Account, Paid Family Care Leave, Vacation Days, Sick Days, Paid Holidays, Pet Insurance, Matching 401(k), and Retirement/Pension.
Equal Opportunity Statement

The SF Fed is an Equal Opportunity Employer. The Bank is committed to providing reasonable accommodations to individuals with disabilities to participate in the job application or interview process, perform essential job functions and receive other benefits and privileges of employment. If you need any assistance or accommodations due to a disability, please let us know at sf.hr.recruitment@sf.frb.org.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Identity Governance & Administration (IGA) Engineer
Lead Identity Governance & Administration (IGA) Engineer

Federal Reserve Bank of Boston • Boston (MA)

On-site
USD 164,000 - 263,000
Medical benefits
Dental benefits
Vision benefits
+2
Senior IGA Platform Lead Engineer (Saviynt)
Senior IGA Platform Lead Engineer (Saviynt)

Federal Reserve Bank of Boston • Boston (MA)

On-site
USD 164,000 - 263,000
Medical benefits
Dental benefits
Vision benefits
+2
Saviynt IGA Lead Architect & Platform Owner
Saviynt IGA Lead Architect & Platform Owner

Federal Reserve Bank of New York • San Francisco (CA)

On-site
USD 150,000 - 230,000
Medical, Dental, Vision
Matching 401(k)
Paid vacation/holidays
Saviynt IAM Staff Augmentation - Senior Identity & Access Management Engineer
Saviynt IAM Staff Augmentation - Senior Identity & Access Management Engineer

Vytwo Technologies Inc. • Prosper (TX)

On-site
Flexible work from home
Lead Architect (IGA/IAM) - Expert Services EMEA
Lead Architect (IGA/IAM) - Expert Services EMEA

Saviynt • Oregon (WI)

Hybrid
USD 120,000 - 150,000
Lead Architect (IGA/IAM) - Expert Services EMEA
Lead Architect (IGA/IAM) - Expert Services EMEA

Saviynt • Amsterdam (OH)

On-site
USD 120,000 - 150,000
Lead Architect (IGA/IAM) - Expert Services EMEA
Lead Architect (IGA/IAM) - Expert Services EMEA

Saviynt • London (OH)

On-site
USD 120,000 - 160,000
Saviynt Identity Governance Engineer
Saviynt Identity Governance Engineer

Motion Recruitment • Irving (TX)

Hybrid
USD 120,000 - 170,000
IAM SME
IAM SME

Tata Consultancy Services • New York (NY)

On-site
USD 120,000 - 130,000
Discretionary Annual Incentive
Comprehensive Medical Coverage
Vacation and Sick Leave
+2
Lead IAM Security Engineer- Saviynt IGA
Lead IAM Security Engineer- Saviynt IGA

Strategic Staffing Solutions • Lutz (FL)

On-site
USD 125,000 - 180,000