Saviynt Administrator/Architect

A Houston Company LLC
Spring, TX, United States
12 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$104,000.0 - $145,600.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory Amazon Web Services Microsoft Azure Software as a Service Cloud Computing Program Optimization Human Resources Information System (HRIS) Identity and Access Management Java Database Connectivity JSON Python (Programming Language) OAuth
+15 more
Open Systems Interconnection (OSI) OpenID Windows PowerShell Role-Based Access Control Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) SQL Databases User Provisioning Software Google Cloud Okta Cyberark Api Design SailPoint Restful APIs

Job description

The IAM Architect will serve as the technical and strategic leader for the organization’s Identity & Access Management program, with a primary focus on Saviynt EIC. This role is responsible for designing IAM architectures, implementing governance controls, integrating identity systems, and ensuring secure, compliant access across cloud and on-prem environments. The ideal candidate has hands-on Saviynt experience, strong architectural skills, and a deep understanding of modern identity ecosystems., Identity Architecture & Strategy

  • Develop and maintain the enterprise IAM architecture, standards, and roadmap.
  • Lead design of identity lifecycle processes (Joiner/Mover/Leaver), access governance, and role-based access models.
  • Architect scalable solutions leveraging Saviynt EIC, Azure AD/Entra ID, and hybrid identity platforms.
  • Enforce IAM policies, security controls, and compliance frameworks (CMMC and NIST 800-171).

Saviynt Engineering & Governance

  • Architect and configure Saviynt modules including:
  • Identity Lifecycle Management
  • Access Request & Workflow
  • Access Certification
  • Role Mining & Role Engineering
  • SOD (Segregation of Duties)
  • Application Onboarding
  • Design Saviynt analytics, dashboards, and custom controls.
  • Build and optimize Saviynt connectors (REST, JDBC, AD, Azure, SaaS apps).
  • Lead Saviynt upgrades, migrations, and platform optimization.

Integration & Automation

  • Integrate Saviynt with HRIS, directory services, cloud apps, and security platforms.
  • Design API-based workflows and automation for provisioning/deprovisioning.
  • Implement modern authentication and authorization patterns (SAML, OAuth, OIDC, SCIM).

Security & Compliance

  • Ensure IAM architecture aligns with Zero Trust principles.
  • Drive continuous improvement in access governance, privileged access, and identity hygiene.
  • Support audit, compliance, and risk assessments with Saviynt reporting and controls.

Leadership & Collaboration

  • Serve as IAM subject matter expert across IT, Security, and business teams.
  • Lead technical design sessions, architecture reviews, and roadmap planning.

Requirements

  • 5 - 10+ years in Identity & Access Management.
  • 3 - 5+ years hands-on Saviynt EIC experience (architecture preferred).
  • Strong understanding of:
  • Entra ID / Azure AD
  • SSO, MFA, Conditional Access
  • RBAC, ABAC, SOD
  • Identity lifecycle automation
  • Experience with REST APIs, JSON, PowerShell, Python, SQL.
  • Familiarity with cloud platforms (Azure, AWS, GCP).
  • Strong documentation, communication, and architectural design skills., * Saviynt Certified Architect or Engineer.
  • Experience in regulated environments (GCC, GCC High, FedRAMP, DoD).
  • Knowledge of Saviynt, CyberArk, Okta, or other IAM/PAM platforms.
  • Experience with microservices, Zero Trust, and modern identity patterns.

TOOLS & TECHNOLOGIES:

  • Saviynt EIC
  • Entra ID
  • Active Directory
  • SCIM, SAML, OAuth, OIDC
  • PowerShell, Python
  • SQL, REST APIs
  • Ivanti ITSM platform
  • Cloud identity services (Azure), * Cloud platforms: 3 years (Preferred)
  • REST APIs, JSON, PowerShell, Python, SQL: 3 years (Preferred)
  • Saviynt EIC : 3 years (Preferred)
  • Identity & Access Management: 5 years (Preferred)
  • Entra ID/Azure AD: 3 years (Preferred)
  • SSO, MFA, Conditional Access: 3 years (Preferred)
  • RBAC,ABAC, SOD: 3 years (Preferred)

Benefits & conditions

Pulled from the full job description 401(k) Health insurance 401(k) matching Vision insurance Dental insurance Life insurance Disability insurance, OSI provides technical services on either a project basis, long-term support basis or permanent basis for midsize to Fortune 500 companies located in the Houston area. Since 1989, we have placed employees in all levels of support and services ranging from entry-level technicians to high-level application programmers. OSI offers a compensation package including:

  • Compensation: OSI consistently pays a higher percentage of gross billing rate than its competitors; in most cases up to 75% of the client’s billing rate
  • Medical Insurance: Company paid medical insurance; optional coverage available for spouse and children
  • Long term Disability
  • 401K
  • Workers Compensation Insurance For more information on OSI, please visit our website at www.osihouston.com.

Job Types: Full-time, Contract

Pay: $50.00 - $70.00 per hour, * 401(k)

  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Life insurance
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:03 min

Distinguishing type definition constructs from data validation routines

Clemens Vasters Clemens Vasters · WWC 2025

Videos

See all

Related articles

See all