> Markdown version of [/jobs/ext/1959340-sr-systems-engineer-iam](https://www.wearedevelopers.com/jobs/ext/1959340-sr-systems-engineer-iam). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr Systems Engineer - IAM - **Company:** Early Warning® - **Location:** Chicago, IL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Systems Engineering, Cloud Computing, Identity and Access Management, Python (Programming Language), Apache Maven, OAuth, OpenID, PCI Data Security Standards, Windows PowerShell, Role-Based Access Control, Security Assertion Markup Language (SAML), SAP (Applications), SQL Databases, Software Vulnerability Management, Scripting, Cloud Platform System, Okta, Enterprise Integration, SailPoint, Restful APIs, Workday, Servicenow - **Published:** August 6, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/sr-systems-engineer-iam-60664-chicago-il-usa-58811648 ## About the Role field and maintain identity governance controls (SoD, RBAC/ABAC, least privilege) and automate lifecycle (joiner/mover/leaver) processes * Implement just-in-time access and enforce least privilege without impacting productivity * Develop workflows, analytics, and reporting to detect access risk and drive remediation * Collaborate with internal audit, risk, and compliance on control testing and evidence for SOX/PCI DSS/GLBA * Plan and validate solutions with manual and automated testing before releases * Mentor junior engineers and contribute to identity roadmap and modernization opportunities Tasks * Bachelor's degree in a related field or equivalent work experience * 5+ years in identity and access management with hands-on IGA platform experience * 3+ years with Saviynt Enterprise Identity Cloud (or equivalent) in production * Deep knowledge of identity governance concepts including attestations, SoD, RBAC/ABAC, entitlement management, and least privilege * Strong scripting and aaaaaaaaa on skills (Python, PowerShell, SQL, REST) * Experience with SSO, MFA, authentication/federation (SAML, OIDC, OAuth) * Proven ability to design automated identity lifecycle processes across heterogeneous systems * Experience supporting audit and regulatory compliance in financial services * Ability to work independently in a dynamic environment and manage priorities * Windows and macOS familiarity * Background check and drug screen Key requirements * Healthcare coverage * 401(k) with company match * Paid time off and holidays * Paid parental leave * Maven Family Planning * Discretionary incentive plan ## Description Experteer Overview In this role, you will own and evolve the Saviynt Enterprise Identity Cloud platform to govern access across a regulated financial tech environment. You'll work within the Identity Platform Engineering team to design, deploy, and operate IdAM capabilities, driving security, compliance, and efficiency. You'll partner with audit, risk, and cross-functional teams to implement robust identity controls and lifecycle management. This is a hands-on, design-to-ops role with a focus on impact and modernization. Compensation / Benefits * Own the Saviynt EIC platform architecture, config, and operations including access lifecycle and certification modules * Maintain platform health and security through patching, vulnerability management, and threat monitoring * Develop connectors to directories and cloud apps (AD, Entra ID, Okta, ServiceNow, Workday, SAP) and custom REST endpoints * Automate tasks with PowerShell, Python, and other scripts to extend platform capabilities * Design and maintain identity governance controls (SoD, RBAC/ABAC, least privilege) and automate lifecycle (joiner/mover/leaver) processes * Implement just-in-time access and enforce least privilege without impacting productivity * Develop workflows, analytics, and reporting to detect access risk and drive remediation * Collaborate with internal audit, risk, and compliance on control testing and evidence for SOX/PCI DSS/GLBA * Plan and validate solutions with manual and automated testing before releases * Mentor junior engineers and contribute to identity roadmap and modernization opportunities Tasks * Bachelor's degree in a related field or equivalent work experience * 5+ years in identity and access management with hands-on IGA platform experience * 3+ years with Saviynt Enterprise Identity Cloud (or equivalent) in production * Deep knowledge of identity governance concepts including attestations, SoD, RBAC/ABAC, entitlement management, and least privilege * Strong scripting and integration skills (Python, PowerShell, SQL, REST) * Experience with SSO, MFA, authentication/federation (SAML, OIDC, OAuth) * Proven ability to design automated identity lifecycle processes across heterogeneous systems * Experience supporting audit and regulatory compliance in financial services * Ability to work independently in a dynamic environment and manage priorities * Windows and macOS familiarity * Background check and drug screen Key requirements * Healthcare coverage * 401(k) with company match * Paid time off and holidays * Paid parental leave * Maven Family Planning * Discretionary incentive plan ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)