Sr Systems Engineer - IAM

Early Warning®
Chicago, IL, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Systems Engineering Cloud Computing Identity and Access Management Python (Programming Language) Apache Maven OAuth OpenID PCI Data Security Standards Windows PowerShell Role-Based Access Control Security Assertion Markup Language (SAML)
+11 more
SAP (Applications) SQL Databases Software Vulnerability Management Scripting Cloud Platform System Okta Enterprise Integration SailPoint Restful APIs Workday Servicenow

Job description

Experteer Overview In this role, you will own and evolve the Saviynt Enterprise Identity Cloud platform to govern access across a regulated financial tech environment. You’ll work within the Identity Platform Engineering team to design, deploy, and operate IdAM capabilities, driving security, compliance, and efficiency. You’ll partner with audit, risk, and cross-functional teams to implement robust identity controls and lifecycle management. This is a hands-on, design-to-ops role with a focus on impact and modernization. Compensation / Benefits * Own the Saviynt EIC platform architecture, config, and operations including access lifecycle and certification modules * Maintain platform health and security through patching, vulnerability management, and threat monitoring * Develop connectors to directories and cloud apps (AD, Entra ID, Okta, ServiceNow, Workday, SAP) and custom REST endpoints * Automate tasks with PowerShell, Python, and other scripts to extend platform capabilities * Design and maintain identity governance controls (SoD, RBAC/ABAC, least privilege) and automate lifecycle (joiner/mover/leaver) processes * Implement just-in-time access and enforce least privilege without impacting productivity * Develop workflows, analytics, and reporting to detect access risk and drive remediation * Collaborate with internal audit, risk, and compliance on control testing and evidence for SOX/PCI DSS/GLBA * Plan and validate solutions with manual and automated testing before releases * Mentor junior engineers and contribute to identity roadmap and modernization opportunities Tasks * Bachelor’s degree in a related field or equivalent work experience * 5+ years in identity and access management with hands-on IGA platform experience * 3+ years with Saviynt Enterprise Identity Cloud (or equivalent) in production * Deep knowledge of identity governance concepts including attestations, SoD, RBAC/ABAC, entitlement management, and least privilege * Strong scripting and integration skills (Python, PowerShell, SQL, REST) * Experience with SSO, MFA, authentication/federation (SAML, OIDC, OAuth) * Proven ability to design automated identity lifecycle processes across heterogeneous systems * Experience supporting audit and regulatory compliance in financial services * Ability to work independently in a dynamic environment and manage priorities * Windows and macOS familiarity * Background check and drug screen Key requirements * Healthcare coverage * 401(k) with company match * Paid time off and holidays * Paid parental leave * Maven Family Planning * Discretionary incentive plan

Requirements

field and maintain identity governance controls (SoD, RBAC/ABAC, least privilege) and automate lifecycle (joiner/mover/leaver) processes * Implement just-in-time access and enforce least privilege without impacting productivity * Develop workflows, analytics, and reporting to detect access risk and drive remediation * Collaborate with internal audit, risk, and compliance on control testing and evidence for SOX/PCI DSS/GLBA * Plan and validate solutions with manual and automated testing before releases * Mentor junior engineers and contribute to identity roadmap and modernization opportunities Tasks * Bachelor’s degree in a related field or equivalent work experience * 5+ years in identity and access management with hands-on IGA platform experience * 3+ years with Saviynt Enterprise Identity Cloud (or equivalent) in production * Deep knowledge of identity governance concepts including attestations, SoD, RBAC/ABAC, entitlement management, and least privilege * Strong scripting and aaaaaaaaa on skills (Python, PowerShell, SQL, REST) * Experience with SSO, MFA, authentication/federation (SAML, OIDC, OAuth) * Proven ability to design automated identity lifecycle processes across heterogeneous systems * Experience supporting audit and regulatory compliance in financial services * Ability to work independently in a dynamic environment and manage priorities * Windows and macOS familiarity * Background check and drug screen Key requirements * Healthcare coverage * 401(k) with company match * Paid time off and holidays * Paid parental leave * Maven Family Planning * Discretionary incentive plan

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all