Senior Identity & Access Management Engineer

greatamerica

Cedar Rapids (IA)

On-site

USD 110,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

GreatAmerica Financial Services seeks a Senior Identity & Access Management Engineer to design, implement, and enhance identity governance and privileged access across SailPoint, CyberArk, and Okta. You will develop automated identity lifecycle workflows and RBAC models, integrate enterprise identity providers, and support SOX/ICFR evidence generation in a collaborative security-focused environment.

The role emphasizes automation, governance maturity, and cross-team partnership with Security,

Qualifications

  • 5+ years hands-on IAM engineering or admin roles.
  • 3+ years with SailPoint IdentityIQ/IdentityNow incl. lifecycle workflows & connectors.
  • Experience designing RBAC models and role governance.
  • Experience with CyberArk PAM including vaulting and onboarding.
  • Strong PowerShell and REST API automation for entitlement and auditing.
  • Proven ability to automate access requests, approvals, and fulfillment.
  • Experience automating JML provisioning across enterprise systems.
  • Preferred: Okta as identity provider with SSO/MFA and SCIM provisioning; depth in two of SailPoint/CyberArk/Okta; ability to deepen the third.

Responsibilities

  • Build and maintain automated identity lifecycle workflows and connectors.
  • Design and roll out RBAC models with ongoing governance.
  • Integrate and administer Okta as the enterprise identity provider (SSO, MFA, SCIM).
  • Implement CyberArk PAM and privileged access controls.
  • Support migration from CyberArk PAS to Privilege Cloud and related procedures.
  • Develop self-service and automated access request workflows.
  • Automate joiner, mover, and leaver provisioning across systems.
  • Run access certification campaigns and produce audit evidence for ICFR.

Skills

IAM engineering
SailPoint IdentityIQ/IdentityNow
RBAC design & governance
CyberArk PAM
PowerShell scripting
REST API automation
JML provisioning automation

Tools

SailPoint (IdentityIQ/IdentityNow)
CyberArk PAM
Okta
ServiceNow

Job description

GreatAmerica Financial Services is a highly successful entrepreneurial company providing equipment financing to businesses across the United States. Our exemplary customer service, our principle-centered business philosophy and our team-based operating approach are key to our success and growth.

We are looking to add a key member to our Identity & Access Management Team!

The Senior Identity & Access Management (IAM) Engineer is responsible for designing, implementing, and continuously enhancing GreatAmerica's identity governance, access management, and privileged access capabilities. This role serves as a senior technical specialist, ensuring identity and access controls are secure, scalable, automated, and aligned with regulatory, audit, and risk management requirements.

Working across SailPoint, CyberArk, Okta, and related technologies, the Senior IAM Engineer develops and maintains enterprise identity lifecycle processes, role-based access controls, privileged access solutions, and authentication services. The role partners closely with Security, Audit, Compliance, Infrastructure, and Application teams to translate security and control requirements into effective technical solutions while advancing automation, operational efficiency, and governance maturity.

The Senior IAM Engineer plays a key role in strengthening GreatAmerica's identity security program by improving access governance, supporting regulatory compliance, reducing access-related risk, and ensuring the reliability and effectiveness of identity services across the organization.

As a Senior IAM Engineer, you will:
  • Build and maintain automated identity lifecycle workflows, certification campaigns, and connectors within SailPoint IdentityNow, including connector development and integration with enterprise applications (ServiceNow, ILS).
  • Design, build, and roll out role-based access control (RBAC) models, including role mining, role engineering, and ongoing role lifecycle governance.
  • Integrate and administer Okta as the enterprise identity provider, including single sign-on (SSO), multi-factor authentication (MFA), and lifecycle management through SCIM provisioning.
  • Implement and support CyberArk privileged access management (PAM), including credential vaulting, session isolation and monitoring, just-in-time (JIT) elevation policy administration, elimination of standing privileges, and privileged account onboarding.
  • Support the migration from self-hosted CyberArk PAS to CyberArk Privilege Cloud, report and integration transition, and updates to operational procedures.
  • Develop self-service and automated access request workflows spanning request intake, approval routing, and fulfillment.
  • Automate joiner, mover, and leaver (JML) provisioning and deprovisioning processes across enterprise systems to ensure timely and accurate access changes.
  • Execute recurring access certification campaigns and quarterly configuration reviews (privileged access, password and authentication settings), producing audit-ready evidence for ICFR logical access controls.
  • Support SOX-related access controls, segregation of duties (SoD) enforcement, and the generation of audit evidence for Internal Control over Financial Reporting (ICFR).
  • Develop PowerShell and REST API automation for entitlement extracts, reconciliation, reporting, and audit evidence generation.
  • Apply FFIEC IT examination handbook guidance to identity governance, access control design, and third-party access risk.
  • Partner with security, audit, compliance, and application teams to translate control requirements into engineered, testable technical solutions.
  • Troubleshoot, tune, and document IAM integrations and workflows to ensure reliability, performance, and auditability.
To be successful, you will need:
  • 5+ years of hands-on experience in Identity and Access Management engineering or administration roles.
  • 3+ years of direct, hands-on experience with SailPoint (IdentityIQ and/or IdentityNow), including lifecycle workflows, certification campaigns, and connector development or integration.
  • Demonstrated experience designing and deploying RBAC models, including role mining, role engineering, and role lifecycle governance.
  • Working experience with CyberArk PAM, including vaulting, session isolation and monitoring, and privileged account onboarding.
  • Strong PowerShell scripting and REST API experience for automation, entitlement extracts, reconciliation, and audit evidence generation.
  • Proven ability to build access request automation covering requests, approvals, and fulfillment.
  • Experience automating JML provisioning and deprovisioning across multiple enterprise systems.
Preferred
  • Practical experience integrating and administering Okta as an identity provider, including SSO, MFA, and SCIM-based lifecycle provisioning (depth in two of SailPoint / CyberArk / Okta required; ability to develop depth in the third).
  • Experience in a financial services environment, with a solid understandi
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IAM Engineer: RBAC, PAM & Identity Automation
Senior IAM Engineer: RBAC, PAM & Identity Automation

GreatAmerica Bank National Association • Cedar Rapids (IA)

Hybrid
USD 120,000 - 150,000
Health Insurance
Hybrid work arrangements
401(k) and Company Match
+2
Senior Identity & Access Management Engineer
Senior Identity & Access Management Engineer

Jobtailor • Iowa (LA)

On-site
USD 120,000 - 160,000
Senior Identity & Access Management Engineer
Senior Identity & Access Management Engineer

GreatAmerica Bank National Association • Cedar Rapids (IA)

Hybrid
USD 120,000 - 150,000
Health Insurance
Hybrid work arrangements
401(k) and Company Match
+2
Senior IAM Engineer - SailPoint, Okta & PAM Automation
Senior IAM Engineer - SailPoint, Okta & PAM Automation

greatamerica • Cedar Rapids (IA)

On-site
USD 110,000 - 150,000
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000
IAM Engineer-
IAM Engineer-

Associates Systems LLC • Irving (TX)

On-site
USD 120,000 - 160,000
Senior IAM Engineer
Senior IAM Engineer

Total Quality Logistics • Cincinnati (OH)

Hybrid
USD 120,000 - 180,000
Hybrid work model
Relocation assistance
Health, dental, vision
Lead Security Engineer
Lead Security Engineer

Genworth • Lynchburg (VA)

Hybrid
USD 130,000 - 160,000
Lead Security Engineer
Lead Security Engineer

Genworth North America Corporation • United States

Hybrid
USD 120,000 - 160,000
Senior IAM Engineer #3285
Senior IAM Engineer #3285

Genius Road, LLC • Austin (TX)

On-site
USD 120,000 - 150,000