Senior Identity & Access Management Engineer

Jobtailor

Iowa (LA)

On-site

USD 120,000 - 160,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an experienced IAM engineer to design, implement, and enhance identity governance, access management, and privileged access capabilities across enterprise systems.

You will work with SailPoint IdentityNow/IdentityIQ, CyberArk PAM, Okta, ServiceNow, and ILS to build RBAC models, automation via PowerShell and REST APIs, and certification campaigns for ICFR/SOX compliance.

Qualifications

  • 5+ years of hands-on IAM engineering/administration.
  • 3+ years with SailPoint IdentityNow/IdentityIQ including lifecycle workflows and connectors.
  • Experience designing RBAC models with role mining/engineering and lifecycle governance.
  • Hands-on CyberArk PAM experience including vaulting, monitoring, onboarding.
  • Strong PowerShell scripting and REST API automation for entitlement data and audit evidence generation.

Responsibilities

  • Design and implement identity governance, access management, and privileged access capabilities.
  • Develop automated identity lifecycle workflows and certification campaigns.
  • Integrate with enterprise apps (ServiceNow, ILS) and administer Okta (SSO, MFA, SCIM).
  • Build RBAC models, role mining, and role lifecycle governance.
  • Automate JML provisioning and deprovisioning across systems.
  • Support ICFR and SOX access controls with audit-ready evidence.

Skills

SailPoint IdentityNow
RBAC Design
PowerShell
REST API
Okta Administration
CyberArk PAM
JML Provisioning
SOX/ICFR
FFIEC Guidance

Education

Bachelor's degree in CS or related field

Tools

SailPoint IdentityNow/IdentityIQ
CyberArk PAM
Okta
ServiceNow
ILS

Job description

Design, implement, and continuously enhance identity governance, access management, and privileged access capabilities.
Build and maintain automated identity lifecycle workflows, certification campaigns, and connectors within SailPoint IdentityNow.
Develop integrations with enterprise applications including ServiceNow and ILS.
Design, build, and roll out RBAC models, including role mining, role engineering, and role lifecycle governance.
Integrate and administer Okta, including SSO, MFA, and SCIM provisioning.
Implement and support CyberArk PAM, including credential vaulting, session isolation and monitoring, JIT elevation policies, and privileged account onboarding.
Support migration from self-hosted CyberArk PAS to CyberArk Privilege Cloud.
Develop self-service and automated access request workflows.
Automate joiner, mover, and leaver provisioning and deprovisioning across enterprise systems.
Execute access certification campaigns and quarterly configuration reviews, producing audit-ready evidence for ICFR logical access controls.
Support SOX-related access controls, segregation of duties enforcement, and ICFR audit evidence generation.
Develop PowerShell and REST API automation for entitlement extracts, reconciliation, reporting, and audit evidence.
Apply FFIEC IT examination handbook guidance to identity governance, access control design, and third-party access risk.
Partner with security, audit, compliance, infrastructure, and application teams to translate control requirements into technical solutions.
Troubleshoot, tune, and document IAM integrations and workflows for reliability, performance, and auditability.

Requirements
  • 5+ years of hands-on experience in Identity and Access Management engineering or administration roles.
  • 3+ years of direct, hands-on experience with SailPoint (IdentityIQ and/or IdentityNow), including lifecycle workflows, certification campaigns, and connector development or integration.
  • Demonstrated experience designing and deploying RBAC models, including role mining, role engineering, and role lifecycle governance.
  • Working experience with CyberArk PAM, including vaulting, session isolation and monitoring, and privileged account onboarding.
  • Strong PowerShell scripting and REST API experience for automation, entitlement extracts, reconciliation, and audit evidence generation.
  • Proven ability to build access request automation covering requests, approvals, and fulfillment.
  • Experience automating JML provisioning and deprovisioning across multiple enterprise systems.
  • Practical experience integrating and administering Okta as an identity provider, including SSO, MFA, and SCIM-based lifecycle provisioning preferred.
  • Experience in a financial services environment preferred.
  • Experience supporting ICFR and SOX access controls, including segregation of duties and audit evidence preparation, preferred.
  • Familiarity with FFIEC IT examination guidance preferred.
  • Bachelor's degree with a major in cybersecurity, computer science or related field preferred, but not required.
  • Information security experience may be substituted for requisite education.
  • Must be authorized to work for any employer in the U.S.; employment visa sponsorship is unavailable.
  • Preferred certifications include SailPoint Certified IdentityNow/IdentityIQ Engineer, CyberArk Defender or Sentry, Okta Certified Professional or Administrator, and CISSP or equivalent.
Core Competencies

Demonstrates expertise in Identity and Access Management engineering, with a strong focus on SailPoint IdentityNow, CyberArk PAM, and automation through PowerShell and REST APIs. Proven ability to design and implement RBAC models and manage access controls in compliance with SOX and ICFR standards.

Highest-signal resume keywords
  • SailPoint IdentityNow
  • CyberArk PAM
  • PowerShell Scripting
  • RBAC Model Design
  • Okta Administration
ATS Optimization Keywords
Hard Skills
  • Identity Governance
  • Access Management
  • Privileged Access Management
  • Lifecycle Workflows
  • Certification Campaigns
  • Role Mining
  • Role Engineering
  • JML Provisioning
  • REST API Automation
  • Entitlement Reconciliation
Certifications & Qualifications
  • SailPoint Certified IdentityNow/IdentityIQ Engineer
  • CyberArk Defender
  • CyberArk Sentry
  • Okta Certified Professional
  • CISSP
Industry Keywords
  • ICFR
  • SOX
  • FFIEC IT Examination Guidance
  • Financial Services
Tools & Technologies
  • SailPoint
  • CyberArk
  • Okta
  • ServiceNow
  • ILS
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Identity and Access Management Specialist
Senior Identity and Access Management Specialist

Jobtailor • Washington

On-site
USD 120,000 - 150,000
Lead Engineer, IAM Platform Engineering
Lead Engineer, IAM Platform Engineering

Jobtailor • Pennsylvania

On-site
USD 150,000 - 190,000
IAM Executive Advisor – Information Security
IAM Executive Advisor – Information Security

Jobtailor • Indianapolis (IN), Town of Montana (WI)

On-site
USD 120,000 - 180,000
Senior Identity & Access Management Engineer
Senior Identity & Access Management Engineer

greatamerica • Cedar Rapids (IA)

On-site
USD 110,000 - 150,000
Sr IAM Developers - US Location
Sr IAM Developers - US Location

Bridgesoftsol • United States

On-site
USD 100,000 - 130,000
IT Security Lead – Identity & Access
IT Security Lead – Identity & Access

Jobtailor • Connecticut

On-site
USD 120,000 - 180,000
IAM Engineer
IAM Engineer

Jobtailor • Alabama

On-site
USD 90,000 - 130,000
Senior Technology Security Engineer (IAM)
Senior Technology Security Engineer (IAM)

Pointwest-North America • Des Moines (IA)

On-site
USD 100,000 - 130,000
Sr Identity and Access Management Analyst
Sr Identity and Access Management Analyst

Chicago Bridge & Iron Company • The Woodlands (TX)

On-site
USD 100,000 - 130,000
Lead Security Engineer
Lead Security Engineer

Genworth • Lynchburg (VA)

Hybrid
USD 130,000 - 160,000