Senior IGA Engineer / SaaS Identity Governance & Administration (Saviynt) Engineer

Federal Reserve Bank of New York

San Francisco (CA)

On-site

USD 147,000 - 234,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical, Dental, Vision
Matching 401(k)
Paid Holidays

Job summary

Federal Reserve Bank of Richmond is seeking a Senior IGA Engineer to design, build, and maintain Saviynt EIC-based Identity Governance & Administration capabilities. You will implement JML lifecycle automation, provisioning, deprovisioning, and access controls across SaaS, cloud, and on-prem applications.

The role emphasizes hands-on development with RBAC, SoD, and entitlement governance, plus integration via REST, SCIM, and SQL.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, Engineering, or equivalent experience.
  • 5+ years of professional experience in IAM, IGA, security engineering, or related identity disciplines.
  • 2+ years of Saviynt engineering/development experience, preferably with Saviynt EIC.
  • Experience integrating SaaS, directories, databases and cloud platforms.
  • Proficiency with RESTful APIs, JSON, SQL, data transformations.
  • Experience with SCIM and identity integration patterns; LDAP/AD concepts expected.

Responsibilities

  • Design, configure, develop, test, deploy, and maintain Saviynt EIC solutions for enterprise IGA use cases.
  • Build JML lifecycle processes, automated provisioning/deprovisioning, and termination controls.
  • Develop access request workflows, entitlement governance, roles, and delegated administration.
  • Create and troubleshoot Saviynt workflows, rules, analytics, and provisioning actions.
  • Onboard SaaS, cloud, database, directory, and enterprise apps using Saviynt connectors.
  • Implement and support RBAC, SoD, and least-privilege patterns.
  • Collaborate with IAM architecture, cybersecurity, and engineering teams to deliver end-to-end identity solutions.

Skills

Saviynt EIC
REST APIs
JSON
SQL
SCIM
Identity lifecycle automation
RBAC
SoD controls
Troubleshooting
Java/Groovy/Python/PowerShell

Education

Bachelor's degree in CS/IT/Cybersecurity/IS/Engineering

Tools

Saviynt EIC
LDAP/Active Directory

Job description

CompanyFederal Reserve Bank of RichmondWhen you join the Federal Reserve—the nation's central bank—you’ll play a key role, collaborating with leading tech professionals to strengthen and protect our economic, financial and payments systems. We invest in contemporary and emerging technology each year to support the Federal Reserve and our economy, and we’re building a dynamic and diverse team for our future.The Senior IGA Engineer is responsible for designing, developing, integrating, testing, deploying, and supporting enterprise Identity Governance & Administration capabilities, with primary emphasis on Saviynt EIC. The role requires strong hands-on development skills across identity lifecycle management, access requests, provisioning, certifications, role/access modeling, application onboarding, APIs, connectors, workflows, and production troubleshooting. The engineer will translate security and business requirements into scalable, supportable IGA solutions across SaaS, cloud, and enterprise applications.Essential Responsibilities:Design, configure, develop, test, deploy, and maintain Saviynt EIC solutions supporting enterprise IGA use cases.Build and enhance Joiner/Mover/Leaver (JML) lifecycle processes, birthright access, automated provisioning/deprovisioning, and termination controls.Configure and develop access request workflows, approval chains, entitlement governance, access policies, roles, user manager structures, and delegated administration.Develop and maintain access certification campaigns, reviewer logic, escalation paths, remediation workflows, and certification reporting.Onboard SaaS, cloud, database, directory, and enterprise applications using Saviynt connectors and custom integration patterns.Develop integrations using REST APIs, SCIM, JDBC/SQL, web services, file-based feeds, scripting, and other supported integration methods.Create and troubleshoot Saviynt workflows, rules, analytics, jobs, tasks, connection configurations, imports, provisioning actions, and technical controls.Implement and support RBAC, role engineering, entitlement structures, access policies, Segregation of Duties (SoD) controls, and least-privilege patterns.Diagnose complex identity data, provisioning, reconciliation, connector, API, workflow, and performance issues across non-production and production environments.Create reusable engineering patterns, technical documentation, configuration standards, runbooks, test evidence, and deployment procedures.Partner with IAM architecture, cybersecurity, application owners, infrastructure, HR, audit, and engineering teams to deliver end-to-end identity solutions.Participate in code/configuration reviews, release management, incident/problem management, root-cause analysis, and continuous platform improvement.Mentor engineers and provide technical leadership on Saviynt implementation patterns, troubleshooting, and engineering quality.RequirementsHands-on Saviynt EIC development and configuration experience delivering production IGA capabilities at enterprise scale.Ability to independently develop, configure, test, troubleshoot, and support Saviynt—not solely gather requirements, administer campaigns, or provide program governance.Demonstrated experience building Saviynt application integrations and resolving connector, API, data mapping, reconciliation, import, and provisioning issues.Hands-on implementation of identity lifecycle automation, including JML events, account creation, access changes, deprovisioning, and termination processing.Hands-on experience with access requests, approval workflows, certifications, entitlement governance, and provisioning workflows.Strong REST API, JSON, SQL, and integration troubleshooting skills.Production support experience, including incident diagnosis, log analysis, root-cause analysis, defect remediation, and controlled releases.Strong understanding of IAM/IGA principles including least privilege, RBAC, SoD, access governance, authoritative sources, identity correlation, and lifecycle controls.QualificationsBachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, Engineering, or a closely related technical discipline or equivalent relevant experience5+ years of professional experience in IAM, IGA, security engineering, application integration, or related identity engineering disciplines.2+ years of recent, hands-on Saviynt engineering/development experience, preferably with Saviynt EIC.Experience integrating heterogeneous applications, including SaaS applications, directories, databases, cloud platforms, and custom/internal systems.Proficiency with RESTful APIs, JSON, SQL, data transformations, authentication methods, and API troubleshooting tools.Experience with SCIM and common identity integration patterns; familiarity with LDAP/Active Directory concepts is expected.Experience with source-of-truth / authoritative identity feeds such as HR systems and with identity correlation and data quality remediation.Ability to analyze complex technical problems across identity data, IGA platform configuration, target applications, and downstream provisioning components.Experience working through software/engineering lifecycle activities: requirements refinement, design, build, test, peer review, deployment, documentation, and production support.Strong written and verbal communication skills with the ability to work effectively across security, engineering, application, audit, and business teams.Preferred skills:Current Saviynt technical certification or formal Saviynt implementation training.Experience with another enterprise IGA platform (for example SailPoint) in addition to Saviynt.Experience with major cloud platforms such as AWS, Microsoft Azure, or Google Cloud and their identity/security integration patterns.Experience integrating HR platforms such as Workday or other authoritative identity sources.Experience with Privileged Access Management (PAM), non-human/service identities, or machine identity governance.Experience with CI/CD, Infrastructure-as-Code, automated testing, or DevSecOps practices applied to IAM/IGA engineering.Experience with Java/Groovy/Python/PowerShell or comparable scripting/programming used for integrations and automation.Experience supporting regulatory or audit-driven access controls in environments subject to SOX, PCI DSS, HIPAA, financial-services, or similar requirements.Experience with enterprise role engineering, access modeling, entitlement rationalization, and SoD rule design.Experience leading complex application onboarding initiatives or mentoring IGA engineers.Locations:The selected candidate will reside within a reasonable commuting distance, as defined by the employing Reserve Bank, and will work full-time onsite.Eligible Locations for Hire: Boston, MA- New York, NY- Philadelphia, PA- Cleveland, OH- Richmond, VA- Atlanta, GA- Chicago, IL- St. Louis, MO- Minneapolis, MN- Kansas City, MO- Dallas, TX- San Francisco, CAThe following Reserve Bank locations are preferred due to the concentration of System IT team members in these locations: San Francisco, CA & Richmond, VABase Salary Range: Min: $146,700 Mid: $190,500 Max: $234,300 (Location: San Francisco)The listed salary is applicable to 12th District/San Francisco. Final offers are determined by factors including the candidate’s qualifications, internal alignment considerations, district assignment, and geographic location.Sponsorship:Individuals who need immigration sponsorship now or in the future are not eligible for this position.Must be a U.S Citizen or a Green card holder with intent to become a U.S Citizen.We offer a wonderful benefits package including: Medical, Dental, Vision, Pre-tax Flexible Spending Account, Backup Child Care Program, Pre-Tax Day Care Flexible Spending Account, Paid Family Care Leave, Vacation Days, Sick Days, Paid Holidays, Pet Insurance, Matching 401(k), and Retirement/Pension.The Bank is committed to providing reasonable accommodations to individuals with disabilities to participate in the job application or interview process, perform essential job functions and receive other benefits and privileges of employment. The SF Fed is an Equal Opportunity Employer. If you need any assistance or accommodations due to a disability, please let us know at sf.hr.recruitment@sf.frb.org.Full Time / Part TimeFull timeRegular / TemporaryRegularJob Exempt (Yes / No)YesJob CategoryInformation Technology Family GroupWork ShiftFirst (United States of America)The Federal Reserve Banks are committed to equal employment opportunity for employees and job applicants in compliance with applicable law and to an environment where employees are valued for their differences.Always verify and apply to jobs on Federal Reserve System Careers (https://rb.wd5.myworkdayjobs.com/FRS) or through verified Federal Reserve Bank social media channels.Privacy Notice
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IGA Engineer / SaaS Identity Governance & Administration (Saviynt) Engineer
Senior IGA Engineer / SaaS Identity Governance & Administration (Saviynt) Engineer

Federal Reserve Bank of Boston • Boston (MA)

On-site
USD 147,000 - 234,000
Medical insurance
Dental insurance
Vision insurance
+10
Senior IGA Engineer / SaaS Identity Governance & Administration (Saviynt) Engineer
Senior IGA Engineer / SaaS Identity Governance & Administration (Saviynt) Engineer

Federal Reserve System • San Francisco (CA)

On-site
USD 147,000 - 234,000
Medical
Dental
Vision
+1
Lead Identity Governance & Administration (IGA) Engineer
Lead Identity Governance & Administration (IGA) Engineer

Federal Reserve System • San Francisco (CA)

On-site
CAD 227,000 - 363,000
Medical
Dental
Vision
+4
File Transfer System Administrator
File Transfer System Administrator

Federal Reserve Bank of New York • Richmond (VA)

On-site
USD 104,000 - 123,000
Lead Site Reliability Engineer
Lead Site Reliability Engineer

Federal Reserve Bank of New York • San Francisco (CA)

On-site
USD 147,000 - 234,000
Lead Site Reliability Engineer
Lead Site Reliability Engineer

Federal Reserve Bank of San Francisco • Richmond (VA)

On-site
USD 147,000 - 234,000
Lead Site Reliability Engineer
Lead Site Reliability Engineer

Federal Reserve Bank of San Francisco • San Francisco (CA)

On-site
USD 147,000 - 234,000
System IT Strategy, Delivery, and Performance Officer
System IT Strategy, Delivery, and Performance Officer

Federal Reserve Bank of San Francisco • San Francisco (CA)

On-site
USD 302,000 - 483,000
System IT Strategy, Delivery, and Performance Officer
System IT Strategy, Delivery, and Performance Officer

Federal Reserve Bank of San Francisco • New York (NY)

On-site
USD 302,000 - 483,000
System IT Strategy, Delivery, and Performance Officer
System IT Strategy, Delivery, and Performance Officer

Federal Reserve Bank of San Francisco • Atlanta (GA)

On-site
USD 302,000 - 483,000