Identity Governance and Administration (IGA) Engineer

Capgemini
San Antonio, TX, United States
3 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$110,000.0 - $125,000.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Active Directory Amazon Web Services Application Integration Architecture Microsoft Azure Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security Databases Computer Engineering Relational Databases
+29 more
Identity and Access Management Java Database Connectivity Lightweight Directory Access Protocols (LDAP) PostgreSQL Microsoft SQL Server OAuth OpenID Oracle (Applications) Performance Tuning Ping (Networking Utility) Public Key Infrastructure Role-Based Access Control Cloud Services Zero Trust Network Access Security Assertion Markup Language (SAML) SQL Databases Systems Integration Web Services Extensible Markup Language (XML) Google Cloud Enterprise Software Applications Delivery Pipeline Git Information Technology SailPoint Restful APIs Software Version Control BeanShell Devsecops

Job description

Capgemini Government Solutions (CGS) LLC Identity Governance and Administration (IGA) Engineer is responsible for designing, deploying, configuring, and supporting enterprise-wide Identity Governance and Administration (IGA) solutions using the SailPoint platform (IdentityIQ and/or Identity Security Cloud). This role plays a critical part in strengthening enterprise cybersecurity postures, automating the identity lifecycle (Joiner/Mover/Leaver workflows), enforcing Role-Based Access Control (RBAC), and aligning identity operations with federal mandates and Zero Trust Architecture (ZTA) initiatives. Working closely with security architects, systems administrators, and application owners, the SailPoint Engineer ensures seamless integration, compliance automation, and robust operational resilience., As Identity Governance and Administration (IGA) Engineer, you will be responsible for:

  • Design, configure, deploy, and maintain SailPoint IdentityIQ (IIQ) or SailPoint Identity Security Cloud platforms. Develop custom workflows, rules, forms, policies, and Beanshell/Java scripts.
  • Integrate enterprise applications, databases, directories (Active Directory, Entra ID, LDAP), and cloud services with SailPoint using out-of-the-box and custom web services/REST APIs/SCIM connectors.
  • Build and maintain automated provisioning and de-provisioning processes for Joiner, Mover, and Leaver (JML) events across hybrid infrastructures.
  • Configure and manage periodic access certification campaigns, entitlement catalog structures, and Separation of Duties (SoD) enforcement policies.
  • Support the design, implementation, and maintenance of Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) models to reduce over-privileged user access.
  • Perform system health checks, performance tuning, patching, version upgrades, and database maintenance across non-production and production SailPoint environments.
  • Ensure SailPoint configurations align with DoD/Federal cybersecurity standards (STIG compliance, NIST SP 800-53 controls) and support Authority to Operate (ATO) assessments.
  • Serve as the senior technical escalation point for complex provisioning errors, identity synchronization bugs, connector failures, and performance bottlenecks.

Requirements

  • Have an active Secret or higher-level Government security clearance that requires U.S. citizenship
  • Bachelor?s degree in computer science, Cybersecurity, Information Technology, Computer Engineering, or a related technical discipline.
  • Minimum of six (6) years of dedicated experience in Identity and Access Management (IAM), with at least four (4) years of hands-on engineering, configuration, and administration of SailPoint IdentityIQ or SailPoint Identity Security Cloud.
  • Active CompTIA Security+ CE certification (or higher DoD 8570/8140 IAT Level II compliant certification, such as CYSA+, GSEC, or CISSP).
  • Superior analytical, troubleshooting, and collaboration skills, with a proven history of managing complex technical deliverables independently.

Technical Expertise:

  • Advanced capability in developing Java, BeanShell, and XML components within the SailPoint IdentityIQ framework.
  • Demonstrated experience building RESTful APIs, SCIM interfaces, JDBC connectors, and custom application integrations.
  • Deep understanding of core identity protocols and directories: SAML 2.0, OAuth, OIDC, Active Directory, LDAP, and PKI/CAC/PIV integrations.
  • Solid working knowledge of relational database management systems (Oracle, SQL Server, PostgreSQL) and SQL query writing.
  • Direct experience implementing SailPoint solutions within Federal/DoD ICAM programs or Zero Trust Architecture (ZTA) environments.
  • Experience with cloud platforms (AWS, Microsoft Azure, Google Cloud Platform) and containerized application deployments.
  • Familiarity with DevSecOps, automated CI/CD deployment pipelines, and version control systems (Git).
  • Hands-on integration experience pairing SailPoint with Privileged Access Management (PAM) tools (e.g., BeyondTrust) or Identity Providers (e.g. Ping, Entra ID)

Benefits & conditions

Capgemini discloses salary range information in compliance with state and local pay transparency obligations. The disclosed range represents the lowest to highest salary we, in good faith, believe we would pay for this role at the time of this posting, although we may ultimately pay more or less than the disclosed range, and the range may be modified in the future. The disclosed range takes into account the wide range of factors that are considered in making compensation decisions including, but not limited to, geographic location, relevant education, qualifications, certifications, experience, skills, seniority, performance, sales or revenue-based metrics, and business or organizational needs. At Capgemini, it is not typical for an individual to be hired at or near the top of the range for their role. The base salary range for the tagged location is $110K-$125K

This role may be eligible for other compensation including variable compensation, bonus, or commission. Full-time regular employees are eligible for paid time off, medical/dental/vision insurance, 401(k), and any other benefits to eligible employees.

Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, or any other form of compensation that are allocable to a particular employee remains in the Company’s sole discretion unless and until paid and may be modified at the Company?s sole discretion, consistent with the law.

About the company

Capgemini is a global business and technology transformation partner, helping organizations to accelerate their dual transition to a digital and sustainable world, while creating tangible impact for enterprises and society. It is a responsible and diverse group of 340,000 team members in more than 50 countries. With its strong over 55-year heritage, Capgemini is trusted by its clients to unlock the value of technology to address the entire breadth of their business needs. It delivers end-to-end services and solutions leveraging strengths from strategy and design to engineering, all fueled by its market leading capabilities in AI, generative AI, cloud and data, combined with its deep industry expertise and partner ecosystem. The Group reported 2024 global revenues of ?22.1 billion.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all