Comcast Cybersecurity: Principal IAM Engineer (SailPoint)
Role details
Job location
Tech stack
Job description
The IAM Principal Engineer is responsible for driving the development, maintenance, and continuous improvement of the identity and access management program, delivering secure and scalable access solutions for myComcastAccess service. This role actively manages day-to-day engineering, support, and maintenance activities across all IAM technologies, ensuring operational excellence and system reliability. As a subject matter expert, the engineer develops custom solutions on identity management, privileged access management, and broader information security best practices, collaborating across technology domains to uphold enterprise security standards., We're hiring a Principal Engineer to architect, build, and operate enterprise IAM at scale. You'll anchor our SailPoint IdentityIQ platform , lead hands-on engineering, and mentor a small team of specialized developers. This is a builder's role - deep technical work paired with development ownership.
What You'll Do
- Own and advance the SailPoint IdentityIQ platform - workflows, rules, connectors, provisioning policies, and forms.
- Architect and develop scalable IAM solutions across identity federation, directory services, and multi-source synchronization.
- Design and deliver automation and access governance for enterprise needs.
- Integrate IAM with the broader security stack - MFA, PAM, AD/LDAP, and cloud identity providers.
- Mentor a small team of engineers; provide technical and strategic guidance to ensure successful delivery.
- Lead POCs, capacity planning, and end-to-end testing for new system capabilities and integrations.
Requirements
- 10+ years in IAM engineering, with deep, hands-on SailPoint IdentityIQ expertise (config + code).
- Strong IAM architecture fundamentals: authentication, authorization, federation, and lifecycle (JML).
- Solid working knowledge of LDAP, Active Directory, MFA, and Privileged Access Management (PAM).
- Programming proficiency in Java and BeanShell, plus SQL / RDBMS.
- Bachelor's in Computer Science, Computer Engineering, or a related technical field., * Radiant Logic (RadiantOne FID / VDS, Global Sync) - virtual directory, Federated Identity Management (FIM), identity correlation & synchronization.
- Experience with one or more of: Okta, Ping, ForgeRock, CyberArk, Microsoft Entra ID / Azure AD.
- Cloud identity on Azure, AWS, or GCP; Kubernetes / Helm deployment experience.
- Web services development (REST APIs, JSON).
Skills Architecture Development, Core Java, Identity Access Management (IAM), SailPoint IdentityIQ, Bachelor's Degree: Computer and Information Science (Required)
While possessing the stated degree is preferred, Comcast also may consider applicants who hold some combination of coursework and experience, or who have extensive related professional experience.
Benefits & conditions
Primary Location Pay Range: $142,361.11 - $213,541.67