Lead Identity Security Engineer – SailPoint ISC

Cognizant

New York (NY)

On-site

USD 115,000 - 134,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical/Dental/Vision/Life Insurance
Paid holidays plus Paid Time Off
401(k) plan and contributions
Disability insurance
Paid Parental Leave
Employee Stock Purchase Plan

Job summary

Cognizant is seeking a Lead Identity Security Architect to drive enterprise IAM and governance initiatives across IGA, ITDR, PAM, and PBAC. You will architect, implement, and oversee SailPoint ISC, CrowdStrike Identity Protection, and related platforms to strengthen identity security and threat visibility.

The role requires a strategic leader with hands-on expertise in identity risk monitoring, integration with AD/Entra ID, and SIEM, plus strong stakeholder engagement to guide security

Qualifications

  • 8+ years of experience in Identity & Access Management, Identity Governance, Cybersecurity Architecture, or Identity Security Engineering.
  • Deep expertise in SailPoint Identity Security Cloud (ISC) implementation, integration, governance, and access lifecycle management.
  • Hands‑on experience with CrowdStrike Identity Protection, ITDR capabilities, and identity risk monitoring.
  • Strong understanding of Privileged Access Management (CyberArk, BeyondTrust, Delinea, or equivalent PAM solutions).
  • Experience implementing identity security controls using SAML, OAuth 2.0, OpenID Connect (OIDC), SCIM, and modern federation protocols.
  • Expertise in identity threat detection, incident response, threat hunting, and security monitoring use case development.
  • Experience integrating IAM, IGA, PAM, Active Directory, Entra ID, and SIEM platforms within enterprise environments.
  • Strong knowledge of policy‑based access control, role management, identity governance, and compliance requirements.
  • Experience working in Agile delivery environments and leading cross‑functional security transformation initiatives.
  • Excellent stakeholder management, executive communication, technical leadership, and governance experience.
  • Relevant certifications in SailPoint, CyberArk, SC‑300, CISSP, CISM, or equivalent identity and security technologies are highly desirable.

Responsibilities

  • Lead enterprise Identity Security initiatives covering IGA, ITDR, PAM, and PBAC capabilities.
  • Define and execute the Identity Security strategy, roadmap, architecture, and implementation approach aligned with business and security objectives.
  • Provide architectural oversight and technical leadership for SailPoint ISC, CrowdStrike Identity Protection, and related Identity Security platforms.
  • Design and implement identity risk signal integrations across SailPoint ISC, CrowdStrike Identity Protection, Active Directory, Microsoft Entra ID, PAM solutions, and existing security platforms.
  • Develop and operationalize identity threat detection and response capabilities to identify account compromise, privilege escalation, lateral movement, insider threats, and credential abuse.
  • Lead detection engineering activities including use case design, correlation logic, monitoring content development, alert tuning, and optimization.
  • Drive SIEM integrations to enhance identity-centric threat analytics, monitoring, dashboards, and threat-hunting capabilities.
  • Establish workflow automation, orchestration, and response mechanisms to accelerate identity-related incident remediation.
  • Guide the implementation of PBAC models, access governance frameworks, entitlement management, and risk-based access controls.
  • Lead PAM onboarding, integration, governance, monitoring, and operational processes across enterprise privileged accounts.
  • Partner with executive stakeholders and governance forums to provide program updates, risk visibility, and strategic guidance.
  • Develop operational runbooks, playbooks, architecture documentation, testing plans, and transition-to-support deliverables.

Skills

IAM expertise
IGA expertise
Identity security monitoring
PAM knowledge
Executive stakeholder communication

Tools

SailPoint ISC
CrowdStrike Identity Protection
Active Directory
Microsoft Entra ID
PAM solutions
SIEM integration

Job description

Practice - CIS - Cloud, Infrastructure, and Security Services

About Cloud Infrastructure & Security Services: Cognizant’s Cloud, Infrastructure, and Security Services Practice (CIS), is all about embracing digital transformation by driving core modernization holistically across layers. We help customers transform infrastructure and workplace to meet the rapidly evolving needs of the digital era. Our holistic approach delivers key results for our customers by achieving cloud driven modernization and workplace and operational transformation to run the business in a secure environment.

Job Summary

We are seeking a Lead Identity Security Architect to drive enterprise Identity Security initiatives across Identity Governance & Administration (IGA), Identity Threat Detection & Response (ITDR), Privileged Access Management (PAM), and Policy-Based Access Control (PBAC). This role will lead the implementation and integration of SailPoint Identity Security Cloud (ISC), CrowdStrike Identity Protection, PAM platforms, and identity security monitoring capabilities. The ideal candidate will combine strong technical expertise with strategic leadership to define identity security roadmaps, improve threat visibility, enhance governance controls, and strengthen enterprise cyber resilience.

In this role, you will:
  • Lead enterprise Identity Security initiatives covering IGA, ITDR, PAM, and Policy-Based Access Control (PBAC) capabilities.
  • Define and execute the Identity Security strategy, roadmap, architecture, and implementation approach aligned with business and security objectives.
  • Provide architectural oversight and technical leadership for SailPoint ISC, CrowdStrike Identity Protection, and related Identity Security platforms.
  • Design and implement identity risk signal integrations across SailPoint ISC, CrowdStrike Identity Protection, Active Directory, Microsoft Entra ID, PAM solutions, and existing security platforms.
  • Develop and operationalize identity threat detection and response capabilities to identify account compromise, privilege escalation, lateral movement, insider threats, and credential abuse.
  • Lead detection engineering activities including use case design, correlation logic, monitoring content development, alert tuning, and optimization.
  • Drive SIEM integrations to enhance identity-centric threat analytics, monitoring, dashboards, and threat-hunting capabilities.
  • Establish workflow automation, orchestration, and response mechanisms to accelerate identity-related incident remediation.
  • Guide the implementation of PBAC models, access governance frameworks, entitlement management, and risk-based access controls.
  • Lead PAM onboarding, integration, governance, monitoring, and operational processes across enterprise privileged accounts.
  • Partner with executive stakeholders and governance forums to provide program updates, risk visibility, and strategic guidance.
  • Develop operational runbooks, playbooks, architecture documentation, testing plans, and transition-to-support deliverables.
What you need to have to be considered
  • 8+ years of experience in Identity & Access Management (IAM), Identity Governance, Cybersecurity Architecture, or Identity Security Engineering.
  • Deep expertise in SailPoint Identity Security Cloud (ISC) implementation, integration, governance, and access lifecycle management.
  • Hands‑on experience with CrowdStrike Identity Protection, ITDR capabilities, and identity risk monitoring.
  • Strong understanding of Privileged Access Management (CyberArk, BeyondTrust, Delinea, or equivalent PAM solutions).
  • Experience implementing identity security controls using SAML, OAuth 2.0, OpenID Connect (OIDC), SCIM, and modern federation protocols.
  • Expertise in identity threat detection, incident response, threat hunting, and security monitoring use case development.
  • Experience integrating IAM, IGA, PAM, Active Directory, Entra ID, and SIEM platforms within enterprise environments.
  • Strong knowledge of policy‑based access control, role management, identity governance, and compliance requirements.
  • Experience working in Agile delivery environments and leading cross‑functional security transformation initiatives.
  • Excellent stakeholder management, executive communication, technical leadership, and governance experience.
  • Relevant certifications in SailPoint, CyberArk, SC‑300, CISSP, CISM, or equivalent identity and security technologies are highly desirable.

#LI-EF1

#CB

#Ind123

Applications will be accepted until 30 Sep 2026.

Salary and Other Compensation:

The annual salary for this position is between $[ 114,500 - 134,000] depending on experience and other qualifications of the successful candidate.

This position is also eligible for Cognizant’s discretionary annual incentive program, based on performance and subject to the terms of Cognizant’s applicable plans.

Benefits: Cognizant offers the following benefits for this position, subject to applicable eligibility requirements:

  • Medical/Dental/Vision/Life Insurance
  • Paid holidays plus Paid Time Off
  • 401(k) plan and contributions
  • Long‑term/Short‑term Disability
  • Paid Parental Leave
  • Employee Stock Purchase Plan
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Cloud Security Engineer
Lead Cloud Security Engineer

Cognizant • New York (NY)

On-site
USD 115,000 - 134,000
Medical/Dental/Vision/Life Insurance
Paid holidays
401(k) plan
+3
Sr Identity Access Management Engineer
Sr Identity Access Management Engineer

Vizient • Chicago (IL)

On-site
USD 77,000 - 135,000
Comprehensive benefits plan
Incentive eligible
Senior Identity Security Architect – IGA, PAM & ITDR Lead
Senior Identity Security Architect – IGA, PAM & ITDR Lead

Cognizant • New York (NY)

On-site
USD 115,000 - 134,000
Medical/Dental/Vision/Life Insurance
Paid holidays plus Paid Time Off
401(k) plan and contributions
+3
Senior Identity Security Engineer – SailPoint IIQ/ISC
Senior Identity Security Engineer – SailPoint IIQ/ISC

Infosys Limited • Raleigh (NC)

On-site
USD 81,000 - 106,000
Disability benefits
Health & dependent care accounts
Insurance options
+1
Senior SailPoint ISC Developer
Senior SailPoint ISC Developer

Veriipro • Irving (TX)

On-site
USD 140,000 - 180,000
Senior Sailpoint IAM Engineer
Senior Sailpoint IAM Engineer

The MathWorks, Inc. • Natick (MA)

Hybrid
USD 150,000 - 190,000
IAM SailPoint Administrator
IAM SailPoint Administrator

RL Canning • Chicago (IL)

On-site
USD 115,000 - 125,000
Short-Term Disability Insurance
AD&D and Life Insurance
401(k) with matching
+2
Identity Governance and Administration (IGA) Engineer
Identity Governance and Administration (IGA) Engineer

Capgemini Government Solutions • San Antonio (TX)

On-site
USD 110,000 - 125,000
Cyber Security Engineer II - SailPoint (Remote)
Cyber Security Engineer II - SailPoint (Remote)

First Citizens Bank • North Carolina

On-site
USD 105,000 - 160,000
Cybersecurity Engineer - Threat Management
Cybersecurity Engineer - Threat Management

Cognizant • New York (NY)

On-site
USD 115,000 - 134,000
Medical benefits
PTO & holidays
401(k) plan
+3