Senior Identity & Access Management Engineer

GreatAmerica

Des Moines (IA)

Hybrid

USD 120,000 - 170,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid work arrangements
401(k) with company match
Annual profit sharing
Paid time off

Job summary

GreatAmerica is seeking a Senior IAM Engineer to design, implement, and continually enhance identity governance and access controls across SailPoint, Okta and CyberArk ecosystems. You will influence automation, governance maturity, and regulatory alignment.

The role partners with Security, Audit, Compliance, Infrastructure and Applications teams to deliver scalable identity services and audit-ready evidence. Strong scripting and RBAC design are essential.

Qualifications

  • 5+ years of hands-on IAM engineering or administration experience.
  • 3+ years with SailPoint (IdentityIQ/IdentityNow) including lifecycle workflows and connectors.
  • Experience designing and deploying RBAC models and role lifecycle governance.
  • Working experience with CyberArk PAM including vaulting and privileged onboarding.
  • Strong PowerShell scripting and REST API experience for automation and audit evidence generation.
  • Experience building automated access request workflows across enterprise systems.

Responsibilities

  • Build and maintain automated identity lifecycle workflows and connectors for SailPoint IdentityNow/IdentityIQ.
  • Design and roll out RBAC models including role mining and lifecycle governance.
  • Integrate and administer Okta as enterprise identity provider with SSO/MFA and SCIM provisioning.
  • Implement CyberArk PAM including vaulting, session isolation, and JIT elevation policy administration.
  • Develop self-service and automated access request workflows from intake to fulfillment.
  • Automate joiner/mover/leaver provisioning and deprovisioning across enterprise systems.
  • Support SOX/ICFR access controls and generate audit evidence for ICFR.

Skills

RBAC design
PowerShell scripting
REST API automation
JML provisioning
SOX/ICFR awareness
Automation

Education

Bachelor's degree in cybersecurity or CS

Tools

SailPoint IdentityIQ/IdentityNow
Okta
CyberArk PAM
ServiceNow

Job description

GreatAmerica is a highly successful entrepreneurial company providing equipment financing to businesses across the United States. Our exemplary customer service, our principle-centered business philosophy and our team-based operating approach are key to our success and growth. We have also recently become a bank!

We are looking to add a key member to our Identity & Access Management Team!

The Senior Identity & Access Management (IAM) Engineer is responsible for designing, implementing, and continuously enhancing GreatAmerica's identity governance, access management, and privileged access capabilities. This role serves as a senior technical specialist, ensuring identity and access controls are secure, scalable, automated, and aligned with regulatory, audit, and risk management requirements.

Working across SailPoint, CyberArk, Okta, and related technologies, the Senior IAM Engineer develops and maintains enterprise identity lifecycle processes, role-based access controls, privileged access solutions, and authentication services. The role partners closely with Security, Audit, Compliance, Infrastructure, and Application teams to translate security and control requirements into effective technical solutions while advancing automation, operational efficiency, and governance maturity.

The Senior IAM Engineer plays a key role in strengthening GreatAmerica's identity security program by improving access governance, supporting regulatory compliance, reducing access-related risk, and ensuring the reliability and effectiveness of identity services across the organization.

As a Senior IAM Engineer, You Will
  • Build and maintain automated identity lifecycle workflows, certification campaigns, and connectors within SailPoint IdentityNow, including connector development and integration with enterprise applications (ServiceNow, ILS).
  • Design, build, and roll out role-based access control (RBAC) models, including role mining, role engineering, and ongoing role lifecycle governance.
  • Integrate and administer Okta as the enterprise identity provider, including single sign-on (SSO), multi-factor authentication (MFA), and lifecycle management through SCIM provisioning.
  • Implement and support CyberArk privileged access management (PAM), including credential vaulting, session isolation and monitoring, just-in-time (JIT) elevation policy administration, elimination of standing privileges, and privileged account onboarding.
  • Support the migration from self-hosted CyberArk PAS to CyberArk Privilege Cloud, report and integration transition, and updates to operational procedures.
  • Develop self-service and automated access request workflows spanning request intake, approval routing and fulfillment.
  • Automate joiner, mover, and leaver (JML) provisioning and deprovisioning processes across enterprise systems to ensure timely and accurate access changes.
  • Execute recurring access certification campaigns and quarterly configuration reviews (privileged access, password and authentication settings), producing audit-ready evidence for ICFR logical access controls.
  • Support SOX-related access controls, segregation of duties (SoD) enforcement, and the generation of audit evidence for Internal Control over Financial Reporting (ICFR).
  • Develop PowerShell and REST API automation for entitlement extracts, reconciliation, reporting and audit evidence generation.
  • Apply FFIEC IT examination handbook guidance to identity governance, access control design and third-party access risk.
  • Partner with security, audit, compliance and application teams to translate control requirements into engineered testable technical solutions.
  • Troubleshoot, tune, and document IAM integrations and workflows to ensure reliability, performance and auditability.
Required

To be successful, you will need:

  • 5+ years of hands‑on experience in Identity and Access Management engineering or administration roles.
  • 3+ years of direct, hands‑on experience with SailPoint (IdentityIQ and/or IdentityNow), including lifecycle workflows, certification campaigns and connector development or integration.
  • Demonstrated experience designing and deploying RBAC models, including role mining, role engineering and role lifecycle governance.
  • Working experience with CyberArk PAM, including vaulting, session isolation and monitoring and privileged account onboarding.
  • Strong PowerShell scripting and REST API experience for automation, entitlement extracts, reconciliation and audit evidence generation.
  • Proven ability to build access request automation covering requests, approvals and fulfillment.
  • Experience automating JML provisioning and deprovisioning across multiple enterprise systems.
Preferred
  • Practical experience integrating and administering Okta as an identity provider, including SSO, MFA and SCIM-based lifecycle provisioning (depth in two of SailPoint / CyberArk / Okta required; ability to develop depth in the third).
  • Experience in a financial services environment, with a solid understanding of the regulatory and control landscape applicable to banking or financial institutions.
  • Experience supporting ICFR and SOX access controls, including segregation of duties and audit evidence preparation.
  • Familiarity with FFIEC IT examination guidance as it relates to identity governance and logical access.
Education
  • Bachelor's degree with a major in cybersecurity, computer science or related field preferred, but not required. Information security experience may be substituted for requisite education.
Certifications
  • Preferred, not required: SailPoint Certified IdentityNow/IdentityIQ Engineer; CyberArk Defender or Sentry; Okta Certified Professional or Administrator; CISSP or equivalent.
Financial Benefits
  • Competitive Compensation
  • Monthly Bonuses for Eligible Employees
  • 401(k) and Company Match
  • Annual Profit SharingPaid Time Off
Health, Wellbeing, And Family Planning Benefits
  • Paid Vacation
  • Paid Sick Days
  • Paid Holidays
  • Gym Reimbursement
  • Health Insurance
  • Dental Insurance
  • Vision Insurance
  • Short-Term and Long-Term Disability
  • Company Paid Life Insurance
  • Flexible Spending Accounts (FSA)
  • Health Savings Accounts (HSA)
  • Employee Assistance Program
  • Parental Leave
Education And Career Planning Benefits
  • Tuition Assistance
  • Networking Opportunities
  • Leadership Development Opportunities
Perks
  • Paid Parking
  • Service Awards
  • Hybrid work arrangements
  • Business casual environment
  • A strong organizational culture focused on our greatest asset: you!

Please note, applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment visa.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Identity & Access Management Engineer
Senior Identity & Access Management Engineer

GreatAmerica • Cedar Rapids (IA)

On-site
USD 120,000 - 190,000
Monthly bonuses
401(k) and company match
Annual profit sharing
+11
Senior Identity & Access Management Engineer
Senior Identity & Access Management Engineer

GreatAmerica • Town of Texas (WI)

On-site
USD 140,000 - 190,000
401(k) match
Profit sharing
Paid time off
+3
Senior Identity & Access Management Engineer
Senior Identity & Access Management Engineer

GreatAmerica Bank National Association • Cedar Rapids (IA)

Hybrid
USD 120,000 - 150,000
Health Insurance
Hybrid work arrangements
401(k) and Company Match
+2
Senior Identity & Access Management Engineer
Senior Identity & Access Management Engineer

GreatAmerica Financial Services Corporation • Iowa (LA), Northern (KY)

Hybrid
USD 120,000 - 170,000
Hybrid work arrangements
Health insurance
401(k) and company match
+1
Senior Software Engineer
Senior Software Engineer

GreatAmerica • Cedar Rapids (IA)

Hybrid
USD 120,000 - 180,000
Paid Parking
Service Awards
Hybrid work arrangements
+2
Senior Software Engineer
Senior Software Engineer

GreatAmerica • Des Moines (IA)

Hybrid
USD 110,000 - 170,000
Paid Parking
Service Awards
Hybrid work arrangements
+2
Senior Software Engineer
Senior Software Engineer

GreatAmerica • Dallas (TX)

On-site
USD 120,000 - 180,000
Health Insurance
401(k) Matching
Paid Time Off
+1
Manager - IAM Engineering and Integration
Manager - IAM Engineering and Integration

GM Financial • Arlington (TX)

Hybrid
USD 140,000 - 170,000
401K matching
Training & development
Principal Engineering Leader
Principal Engineering Leader

GreatAmerica • Town of Texas (WI)

Hybrid
USD 140,000 - 190,000
Hybrid work arrangements
Paid Parking
Service Awards
+1
Principal Engineering Leader
Principal Engineering Leader

GreatAmerica • Des Moines (IA)

Hybrid
USD 150,000 - 210,000
Hybrid work arrangements
Paid Parking
Service Awards
+2