Sr Identity & Access Governance (IGA) Engineer (Sailpoint)

Charles Schwab

Phoenix (AZ)

On-site

USD 140,000 - 180,000

Full time

16 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401(k) with company match
Paid time off and sabbatical
Parental leave and family benefits
Tuition reimbursement
Health, dental, and vision insurance

Job summary

Charles Schwab’s Cybersecurity Services (SCS), Office of the CISO, seeks a Senior Identity Governance & Administration Engineer to deliver and manage enterprise IGA programs across on-prem and cloud. You will drive automation, lifecycle management, and policy enforcement with a focus on RBAC/ABAC and least-privilege, collaborating across security, architecture, and application teams.

You will design complex integrations, implement IGA extensions using Java/Python, and mentor junior engineers

Qualifications

  • Bachelor’s degree in Computer Science, Engineering, or a related technical field (or equivalent practical experience).
  • 6+ years of experience in Identity & Access Management, with strong depth in Identity Governance & Administration (IGA).
  • Hands-on experience with enterprise IGA platforms (e.g., SailPoint or equivalent).
  • Proven experience delivering large-scale IGA implementations in enterprise environments.
  • Strong development and automation experience with Java/J2EE, BeanShell, Python, REST APIs, and scripting languages.
  • Experience integrating IGA solutions across LDAP/AD, SSO/Federation platforms, cloud services, data platforms, and PAM tools.
  • Security governance knowledge: RBAC/ABAC, SoD, least privilege, entitlement lifecycle management, access certification.
  • Experience driving automation and AI-enabled capabilities within IAM or security platforms.
  • Cloud identity architectures and standards (SCIM, OAuth2, OIDC, SAML).
  • Experience in Agile / SAFe environments; Jira and Confluence proficient.
  • Ability to translate business, security, compliance, and AI platform requirements into scalable IGA solutions.
  • Excellent written and verbal communication skills; able to influence stakeholders.
  • Self-directed, organized, and able to manage multiple priorities in a regulated environment.

Responsibilities

  • Serve as a Senior IGA Engineer, owning design, implementation, automation, and operational maturity of enterprise IGA across on-prem and cloud.
  • Lead delivery of IGA solutions (e.g., SailPoint) supporting lifecycle, access requests, certifications, and policy enforcement.
  • Drive IGA automation and AI readiness to reduce manual operations and scale governance.
  • Use AI and analytics to enhance risk detection, recommendations, and entitlement rationalization.
  • Protect AI systems through IGA controls, least privilege, and auditable access management.
  • Partner with Security Architecture, IAM Governance, Infrastructure, and Applications teams on end-to-end IGA solutions.
  • Design and implement complex integrations using REST APIs, connectors, SCIM, and event messaging.
  • Develop custom IGA extensions with Java, BeanShell, Python, and scripting technologies.
  • Lead access model design and optimization (RBAC/ABAC, entitlement consolidation, token bloat reduction).
  • Provide senior technical leadership for IAM upgrades, cloud migrations, and security remediation.
  • Collaborate with audit, risk, and compliance to ensure SOX/SOC alignment and remediation of gaps.
  • Work with Scrum Masters, Product Owners, and Project Managers in Agile/SAFe delivery from design to production.
  • Support cross-IAM activities with LDAP, AD, SSO/federation, and PAM teams; produce runbooks and architecture docs.

Skills

IGA engineering
Automation
Java/J2EE
Python
REST APIs
OAuth/OIDC/SAML
Jira/Confluence
Agile/SAFe
Cloud identity

Education

Bachelor’s degree in Computer Science, Engineering, or a related technical field

Tools

SailPoint
LDAP/AD
SCIM
Jira
Confluence

Job description

Your opportunity


At Schwab, you are empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us “challenge the status quo” and transform the finance industry together.


We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location(s).


In Schwab Cybersecurity Services (SCS), Office of CISO, we provide platforms, services, and security operations capabilities which enable the firm to produce successful client and shareholder outcomes securely and safely. Securing our IT assets, data, and access to applications is the core of who we are and what we do. We ensure only the appropriate entities have access to IT resources and that we adhere to best practices and standards to ensure a safe and compliant environment is maintained.


Identity and Access Management has an opening for a Security Engineer to deliver and manage large, complex Identity and Access Management programs in the area of Identity Governance & Administration. The individual will ensure adherence to policy and provide leadership to the implementation of leading-edge technology to position the organization for success – improving efficiency, increasing security posture, and supporting growth of the firm’s Identity and Access Management (IAM) Program.


What You’ll Do


  • Serve as a Senior Identity Governance & Administration (IGA) Engineer, owning the design, implementation, automation, and operational maturity of enterprise IGA solutions across on‑prem and cloud environments.

  • Lead the delivery of IGA solutions (e.g., SailPoint and other enterprise cloud based IGA platforms), supporting identity lifecycle (Joiner/Mover/Leaver), access requests, certifications, and policy enforcement.

  • Drive IGA automation and AI readiness, leveraging workflow automation, event‑driven integrations, and analytics to reduce manual operations, improve access accuracy, and scale identity governance.

  • Leverage AI and advanced analytics within IGA solutions to enhance risk detection, access recommendations, certification efficiency, and entitlement rationalization.

  • Use IGA controls to protect AI systems and workloads, ensuring proper identity lifecycle governance, least privilege access, model/service ownership controls, and auditable access to AI platforms and data.

  • Act as a technical authority and design partner to Security Architecture, IAM Governance, Infrastructure, and Application teams to define end‑to‑end identity and access solutions.

  • Design and implement complex integrations with applications, data platforms, AI services, and infrastructure using REST APIs, connectors, SCIM, flat files, and event messaging.

  • Develop and maintain custom IGA extensions including rules, workflows, transforms, and integrations using Java, BeanShell, Python, and scripting technologies.

  • Lead access model design and optimization, including RBAC/ABAC strategies, entitlement consolidation, token bloat reduction, and least‑privilege enforcement.

  • Provide senior technical leadership for IGA upgrades, cloud migrations, platform enhancements, and security remediation initiatives.

  • Partner with audit, risk, and compliance teams to ensure alignment with security controls and regulatory requirements (e.g., SOX, SOC), proactively identifying and remediating gaps.

  • Collaborate with Scrum Masters, Product Owners, and Project Managers to deliver solutions through Agile / SAFe execution models from design through production.

  • Provide cross‑IAM support and guidance, collaborating with teams responsible for LDAP, Active Directory, SSO/federation, and Privileged Access Management (PAM) tools.

  • Produce and own technical architecture documentation, standards, and operational runbooks, and mentor junior engineers to raise overall team capability.

  • Contribute to the IAM and IGA strategy and roadmap, including future‑state capabilities for cloud identity, AI‑driven governance, and integrated IAM platforms.


Required Qualifications


  • Bachelor’s degree in Computer Science, Engineering, or a related technical field (or equivalent practical experience).

  • 6+ years of experience in Identity & Access Management, with strong depth in Identity Governance & Administration (IGA).

  • Hands‑on experience with enterprise IGA platforms (e.g., SailPoint or equivalent), including lifecycle management, access requests, certifications, and policy enforcement.

  • Proven experience delivering large‑scale IGA implementations, cloud migrations, upgrades, and complex customizations in enterprise environments.

  • Strong development and automation experience with Java/J2EE, BeanShell, Python, REST APIs, and scripting languages.

  • Experience integrating IGA solutions across LDAP/Active Directory, SSO/Federation platforms, cloud services, data platforms, and PAM tools.

  • Solid understanding of identity governance principles: RBAC/ABAC, SoD, least privilege, entitlement lifecycle management, and access certification frameworks.

  • Experience driving automation and AI‑enabled capabilities within IAM or security platforms (analytics, recommendation engines, workflow optimization).

  • Working knowledge of cloud identity architectures and standards (SCIM, OAuth2, OIDC, SAML).

  • Experience operating in Agile / SAFe environments, with proficiency in tools such as Jira and Confluence.

  • Strong ability to translate business, security, compliance, and AI platform requirements into scalable IGA technical solutions.

  • Excellent written and verbal communication skills, with the ability to influence technical and non‑technical stakeholders.

  • Self‑directed, highly organized, and able to manage multiple priorities in a complex, regulated environment.


Preferred Qualifications


  • Security or IAM certifications such as CISSP, CISM, SailPoint certification, or equivalent.

  • Experience integrating IGA with Privileged Access Management (PAM) solutions.

  • Exposure to governing access to AI/ML platforms, data pipelines, or automation services.


What’s in it for you

At Schwab, you’re empowered to shape your future. We champion your growth through meaningful work, continuous learning, and a culture of trust and collaboration—so you can build the skills to make a lasting impact. Our Hybrid Work and Flexibility approach balances our ongoing commitment to workplace flexibility, serving our clients, and our strong belief in the value of being together in person on a regular basis.


We offer a competitive benefits package that takes care of the whole you – both today and in the future:



  • 401(k) with company match and Employee stock purchase plan

  • Paid time for vacation, volunteering, and 28-day sabbatical after every 5 years of service for eligible positions

  • Paid parental leave and family building benefits

  • Tuition reimbursement

  • Health, dental, and vision insurance

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Identity & Access Governance (IGA) Engineer (Sailpoint)
Sr Identity & Access Governance (IGA) Engineer (Sailpoint)

Charles Schwab • Southlake (TX)

On-site
USD 140,000 - 190,000
401(k) match
Parental leave
Sabbatical
+2
Manager, Security Development & Engineering
Manager, Security Development & Engineering

Charles Schwab Corporation • Westlake (TX)

Hybrid
USD 110,000 - 170,000
401(k) matching
Employee stock purchase plan
Paid vacation
+3
Manager, Security Development & Engineering
Manager, Security Development & Engineering

Charles Schwab • Westlake (TX)

Hybrid
USD 120,000 - 170,000
401(k) with company match
Employee stock purchase plan
Paid vacation and volunteering
+2
Senior Security Design Architect
Senior Security Design Architect

Charles Schwab • Southlake (TX)

On-site
USD 150,000 - 210,000
Senior Security Design Architect
Senior Security Design Architect

Charles Schwab • Austin (TX)

Hybrid
USD 150,000 - 190,000
401(k) match
Sabbatical after 5 years
Parental leave
+2
Senior Software Engineer - Enterprise Architecture & AI Solutions Engineering
Senior Software Engineer - Enterprise Architecture & AI Solutions Engineering

Charles Schwab • Southlake (TX)

On-site
USD 140,000 - 190,000
401(k) with company match
Paid time for vacation
Parental leave and family benefits
+1
ITSM Administrator
ITSM Administrator

Charles Schwab • Phoenix (AZ)

Hybrid
USD 110,000 - 160,000
401(k) with company match
Employee stock purchase plan
Paid time off and sabbatical after 5+
+4
Sr. Manager Data Management
Sr. Manager Data Management

Charles Schwab • Austin (TX)

On-site
USD 120,000 - 160,000
Senior AI Engineer, AI.x
Senior AI Engineer, AI.x

Charles Schwab • San Francisco (CA)

On-site
USD 180,000 - 250,000
401(k) with company match
Employee stock purchase plan
Sabbatical after 5 years of service
+2
ITSM Administrator
ITSM Administrator

Charles Schwab • Austin (TX)

Hybrid
USD 90,000 - 140,000
401(k) with company match
Paid vacation and volunteering
Parental leave and family benefits
+2