Principal Engineer, Cybersecurity, IGA - Remote

Stryker Corporation

Kalamazoo (MI)

Hybrid

Confidential

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Stryker Corporation is seeking a Principal Engineer to design and operate enterprise IGA platforms, ensuring secure identity governance across the organization. You will implement lifecycle workflows, SSO/MFA, and access controls, partnering with senior stakeholders to translate requirements into scalable identity architecture.

The role requires deep experience with IGA/IAM environments, strong scripting skills, and a focus on compliance with industry standards.

Qualifications

  • Bachelor's degree or equivalent practical experience in a relevant field.
  • 8+ years in IT or cybersecurity.
  • 5+ years engineering and operating IGA/IAM environments.

Responsibilities

  • Build, configure, and operate enterprise IGA platforms (SailPoint, Saviynt, Entra ID Governance).
  • Develop identity lifecycle workflows and automated provisioning/deprovisioning.
  • Implement access requests, RBAC, and recertification campaigns; ensure SOX/HIPAA/NIST compliance.

Skills

IGA platforms
Active Directory
SailPoint
Saviynt
Entra ID
RBAC
SAML
OAuth
OIDC
PowerShell
Microsoft Graph
REST APIs

Education

Bachelor's degree in CS/Cybersecurity/IS/Engineering

Tools

SCIM
Microsoft Graph

Job description

## Principal Engineer, Cybersecurity, IGA - RemoteApply: Michigan, Kalamazoo 4100 East Milham Rd: Full time: Posted Today: R573257Work Flexibility: Remote**Preference will be given to candidates residing in the Eastern or Central time zones.**As an IGA Principal Engineer, you will build and operate enterprise identity governance, authentication, and authorization services that protect access across the organization. You will partner with senior business, application, and infrastructure stakeholders to translate requirements into scalable identity architecture, standards, and controls.**WHAT YOU WILL DO****Technical Responsibilities:*** Build, configure, and operate enterprise IGA platforms, including SailPoint, Saviynt, or Microsoft Entra ID Governance, with supporting directory and authentication services.* Engineer identity lifecycle workflows for joiners, movers, and leavers, including automated provisioning and deprovisioning.* Implement and maintain access requests, approval workflows, access certification and recertification campaigns, RBAC models, role mining, and segregation-of-duties rules.* Configure authoritative sources, identity reconciliation, and identity data quality remediation.* Implement SSO, MFA, federation, and risk-based authentication using SAML, OAuth, OpenID Connect, and SCIM.* Develop PowerShell, Microsoft Graph, REST API, and SCIM automations and integrations to onboard applications to IGA services.* Produce identity reporting, integration governance, and audit evidence for access-related controls.* Troubleshoot IGA, provisioning, and directory issues; maintain documentation; and execute IAM controls supporting SOX, HIPAA, ISO 27001, and NIST CSF compliance.**Knowledge and Capabilities:*** Gather requirements from senior business, application, and infrastructure stakeholders and provide scope and architecture consultation.* Define, communicate, and embed enterprise identity governance standards, patterns, and controls with senior stakeholders.* Analyze complex identity issues, communicate technical concepts clearly, and maintain precise configuration and governance practices.**WHAT YOU NEED****Required Qualifications*** Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related discipline, or equivalent practical experience.* Minimum 8 years of experience in IT or cybersecurity.* Minimum 5 years of hands-on experience engineering and operating IGA or IAM environments.* Experience with SailPoint, Saviynt, or Microsoft Entra ID Governance, plus Active Directory and Microsoft Entra ID.* Experience with identity lifecycle management, provisioning and deprovisioning, access certification, RBAC, and segregation-of-duties enforcement.* Working knowledge of SAML, OAuth, OpenID Connect, and SCIM.* Experience with PowerShell, Microsoft Graph, or REST APIs.**Preferred Qualifications*** SailPoint IdentityIQ or IdentityNow Engineer, Saviynt, Microsoft Certified: Identity and Access Administrator Associate (SC-300), or CISSP certification.**United States of America Pay Ranges:*** **USN**: $135,600 - $225,900 USD Annual* **US5**: $142,400 - $237,200 USD Annual* **US10**: $149,200 - $248,500 USD Annual* **US15**: $155,900 - $259,800 USD Annual* **US20**: $162,700 - $271,100 USD Annual* **US30**: $176,300 - $293,700 USD AnnualView the U.S. work location and transparency guide to find the pay range for your location.Travel Percentage: NoneStryker Corporation is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, gender identity, sexual orientation, national origin, disability, or protected veteran status. Stryker is an EO employer – M/F/Veteran/Disability.Stryker Corporation will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Architect, Cybersecurity, Identity Security - Remote
Architect, Cybersecurity, Identity Security - Remote

Stryker Corporation • Kalamazoo (MI)

Hybrid
Confidential
Manager, Cybersecurity, Non-Human Identity Security - Remote
Manager, Cybersecurity, Non-Human Identity Security - Remote

Stryker Corporation • Kalamazoo (MI)

Hybrid
Confidential
Senior Manager, Cybersecurity, AI SOC & Crisis Management - Remote
Senior Manager, Cybersecurity, AI SOC & Crisis Management - Remote

Stryker Corporation • Kalamazoo (MI)

Hybrid
Confidential
Senior Manager, Cybersecurity, CTEM & Vulnerability Intelligence - Remote
Senior Manager, Cybersecurity, CTEM & Vulnerability Intelligence - Remote

Stryker Corporation • Kalamazoo (MI)

Hybrid
Confidential
Senior Manager, Cybersecurity, Metrics & Reporting - Remote
Senior Manager, Cybersecurity, Metrics & Reporting - Remote

Stryker Corporation • Kalamazoo (MI)

Hybrid
Confidential
Manager, Cybersecurity, Quantitative Risk - Remote
Manager, Cybersecurity, Quantitative Risk - Remote

Stryker Corporation • Kalamazoo (MI)

Hybrid
Confidential
Manager, Cybersecurity, Privileged Access Management - Remote
Manager, Cybersecurity, Privileged Access Management - Remote

Stryker Corporation • Kalamazoo (MI)

Hybrid
Confidential
Associate Manager, Logistics - BPE
Associate Manager, Logistics - BPE

Stryker Corporation • Portage (MI), Northern (KY)

Hybrid
Confidential
Staff Software Engineer
Staff Software Engineer

Stryker Corporation • San Jose (CA)

Hybrid
Confidential
Sr Manufacturing Engineer
Sr Manufacturing Engineer

Stryker Corporation • Kalamazoo (MI)

Hybrid
Confidential