Sr Identity & Access Management Engineer (IAM)

Early Warning

Chicago (IL)

Hybrid

USD 150,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid work model

Job summary

Early Warning in Chicago is seeking a Senior IAM Engineer to lead the Saviynt Enterprise Identity Cloud platform, architecting access models and governance controls in a regulated financial technology environment. This role is hands-on and requires deep expertise in identity and access management.

You will design and automate identity lifecycle, configure attestations, SoD rules, RBAC/ABAC, and integrate with AD, Entra ID, Okta, and cloud services, while partnering with security, audit, and

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Information Security, or related field.
  • Minimum 5 years of progressive experience in identity and access management with hands-on IGA deployment.
  • Deep expertise with Saviynt Enterprise Identity Cloud and supporting directory services and SSO.

Responsibilities

  • Owns Saviynt EIC platform architecture, configuration, and operations including access request, certification, and lifecycle management.
  • Designs and maintains identity governance controls including attestations, SoD rules, RBAC/ABAC, and least privilege enforcement.
  • Automates identity lifecycle events and integrations using Python, PowerShell, and REST APIs.
  • Collaborates with audit, risk, and compliance to support regulatory controls and evidence collection.

Skills

Saviynt EIC
PowerShell
Python
SQL
RBAC/ABAC
REST APIs
Active Directory
Entra ID
Okta

Education

Bachelor's degree in Computer Science, Information Technology, Information Security, or related field

Tools

Saviynt EIC
Postman

Job description

At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze®, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses. Early Warning follows a hybrid work model to allow for a more collaborative working environment. Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.

Overall Purpose

The Senior IAM Engineer sits within the Identity Platform Operations team, part of the broader Identity and Access Management department, and serves as the technical anchor for Early Warning’s Identity Governance and Administration (IGA) platform. This role leads the discovery, design, delivery, and operational health of Saviynt Enterprise Identity Cloud (EIC) and the governance controls that determine how identities are provisioned, certified, and constrained across a regulated financial technology environment. This is a hands on, deeply specialized position rather than a generalist infrastructure role. The engineer is accountable for architecting access models, hardening segregation of duties controls, maintaining accurate technical documentation of supported systems, participating in audit and compliance activities, and serving as a subject matter expert in identity and access management. The role also carries a mandate to prototype new solutions to identity challenges, optimize existing systems, and evaluate emerging technologies as they become available.

Essential Functions
Platform Ownership and Engineering

Owns the architecture, configuration, and operations of the Saviynt EIC platform, including access request, certification, and lifecycle management modules. Provides operational excellence for the identity governance platform including version maintenance, vulnerability management, patching, and overall platform health. Proactively monitors and maintains identity platform security assurances such as threat detection, user behavior analytics, and privileged user monitoring. Builds and manages connectors and integrations across directories, cloud platforms, databases, and enterprise applications, including Active Directory, Entra ID, Okta, ServiceNow, Workday, SAP, cloud infrastructure, and custom REST based endpoints. Authors PowerShell, Python, and other scripts to automate repetitive tasks and extend platform capability.

Governance, Controls, and Risk

Designs and maintains identity governance controls including access certification and attestation campaigns, segregation of duties (SoD) rulesets, role based and attribute based access models (RBAC and ABAC), and least privilege enforcement. Automates the full identity lifecycle covering joiner, mover, and leaver events, including provisioning, deprovisioning, and access reconciliation, minimizing manual intervention and standing access. Ensures just in time and just enough access is enforced without hindering productivity or user experience. Develops and tunes workflows, rules, analytics, and reporting to detect access risk and drive remediation. Partners with internal audit, risk, and compliance to support control testing and evidence collection for regulatory frameworks relevant to financial services, including SOX, PCI DSS, GLBA, and related audit obligations.

Design, Delivery, and Quality

Gathers requirements from business, security, and audit stakeholders, decomposes them into discrete technical components, and translates them into usable solutions incorporated into platform design. Establishes repeatable and reusable frameworks, patterns, and reference designs so that solutions scale consistently rather than being rebuilt for each use case. Plans and executes both manual and automated testing across configurations, integrations, and workflows, validating that solutions meet functional, security, and compliance requirements before release. Leads root cause analysis and resolution of complex identity issues spanning provisioning failures, entitlement drift, and integration breaks. Defines technical standards, patterns, and documentation that make the platform sustainable and repeatable as it scales.

Collaboration and Leadership

Continuously evaluates the IAM organizational structure, system configuration, and application integrations, provides recommendations for operational and security enhancements. Collaborates with Enterprise Architects, Security Architects, and Application Architects to drive adoption of IAM best practices and to support documentation standards. Develops relationships with business and technology stakeholders to ensure on time delivery. Actively participates in team stand up, technical engineering discussions, change control process, audit activities, business continuity efforts, and on call rotation. Mentors, coaches, and trains junior systems engineers, and models a strong sense of responsibility, ownership, and pride in delivering quality results. Contributes to the broader identity roadmap, advising leadership on platform strategy, emerging risks, and modernization opportunities. Supports the company’s commitment to risk management and to protecting the integrity and confidentiality of systems and data.

Identity Governance Focus

Progressive experience and advanced proficiency with Saviynt Enterprise Identity Cloud, including connector development, workflow configuration, rule and role engineering, and certification campaign design and execution. Expert understanding of identity governance administration constructs including attestations, analytics, connectors, rules, users, accounts, account ownership, roles, entitlements, entitlement ownership, security systems, and endpoints. DevOps support for IGA solutions to include incident and request management and implementation of new functionality including new integrations. Experience integrating IGA solutions with two or more platforms such as Active Directory, Entra ID, Okta, Workday, ServiceNow, and Amazon Web Services. Working knowledge of SQL, REST, SOAP, JSON, XML, Groovy, and PowerShell. Experience developing and testing new integrations and configurations, including API testing through tools such as Postman.

Minimum Qualifications

Education and experience typically obtained through completion of a Bachelor’s degree in Computer Science, Information Technology, Information Systems, Information Assurance, Cybersecurity or a related field, or equivalent work experience. Typically a minimum 5 years of progressive relevant experience in identity and access management, including hands on implementation and operation of enterprise IGA platforms in production. Minimum 3 years of hands on production experience with Saviynt Enterprise Identity Cloud, or equivalent depth in a comparable enterprise IGA platform with demonstrated ability to transition to Saviynt. Deep command of identity governance principles including access certification, segregation of duties, RBAC and ABAC design, entitlement management, and least privilege enforcement. Proven experience designing and automating identity lifecycle processes across heterogeneous systems. Strong working knowledge of core identity and access concepts including directory services, authentication, and federation (SAML, OIDC, OAuth), single sign on, multi factor authentication, and identity lifecycle management. Proficiency with scripting and integration technologies including Python, PowerShell, SQL, and REST APIs. Demonstrated testing experience across both manual and automated approaches, including test planning, execution, and validation of integrations and workflows against functional and security requirements. Strong requirements engineering ability, including eliciting requirements, decomposing complex needs into discrete components, and translating them into usable solutions and design. Demonstrated experience supporting audit and compliance requirements in a regulated environment. Track record of operating at a senior engineering level, including owning technical solutions end to end, resolving ambiguous problems independently, and influencing partners and stakeholders. Ability to perform duties independently, without direct supervision and detailed guidance. Ability to work in a fast paced dynamic environment that often requires shifting priorities. Strong organizational and time management skills with the ability to communicate and collaborate effectively with team members and cross functional teams. Comfortable working in Windows and macOS end user compute environments. Background and drug screen.

Preferred Qualifications

Direct experience in financial services, financial technology, or another highly regulated industry. Saviynt certification or equivalent demonstrated expertise. Effective delivery in a highly regulated environment such as PCI DSS. Exposure to complementary IGA and IAM tooling such as SailPoint, Oracle Identity Manager, CyberArk, Delinea, or Okta, and familiarity with privileged access management concepts. Microsoft Azure and AWS cloud experience, including governing access to cloud workloads. Proficiency with Active Directory PKI, key management, certificate authority, or related platforms. Experience working within Agile or SAFe delivery models and CMMI aligned process maturity. Ability to drive strategy sessions for the planning, development, and delivery of work efforts

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Saviynt IAM Staff Augmentation - Senior Identity & Access Management Engineer
Saviynt IAM Staff Augmentation - Senior Identity & Access Management Engineer

Vytwo Technologies Inc. • Prosper (TX)

On-site
USD 110,208 - 165,312
Flexible work from home
Saviynt IAM Staff Augmentation - Senior Identity & Access Management Engineer
Saviynt IAM Staff Augmentation - Senior Identity & Access Management Engineer

Vytwo • Prosper (TX)

On-site
USD 100,000 - 130,000
Saviynt EIC Support Engineer
Saviynt EIC Support Engineer

AvetixCyber • Dallas (TX)

On-site
USD 140,000 - 190,000
Saviynt EIC Engineer
Saviynt EIC Engineer

Adidev Technologies Inc • Jersey City (NJ)

On-site
USD 120,000 - 160,000
Senior Technical Consultant - Identity & Access Management - IGA Saviynt
Senior Technical Consultant - Identity & Access Management - IGA Saviynt

IBM • Dallas (TX)

On-site
USD 120,000 - 190,000
Cybersecurity Saviynt L3
Cybersecurity Saviynt L3

AppLab Systems, Inc • Jersey City (NJ)

On-site
USD 120,000 - 160,000
Identity Security Practice - Director, Professional Services - Chicago
Identity Security Practice - Director, Professional Services - Chicago

Saviynt • Chicago (IL)

On-site
USD 220,000 - 250,000
Competitive total rewards package
Learning and development opportunities
Discretionary bonus plan
Saviynt Engineer
Saviynt Engineer

Experis Technology Group • Philadelphia

On-site
USD 90,000 - 96,000
Competitive pay rate
Ongoing learning & development
Diversity & inclusion culture
+2
IAM Engineer-
IAM Engineer-

Associates Systems LLC • Irving (TX)

On-site
USD 120,000 - 160,000
Identity Security Practice - Director, Professional Services - NYC
Identity Security Practice - Director, Professional Services - NYC

Saviynt • New York (NY)

On-site
USD 220,000 - 250,000
Competitive Total Rewards Package
Learning and Development Opportunities
Discretionary Bonus Plan
+1