IAM Engineer- Irvine, CA or Irving, TX or Henderson, NV (Onsite)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+9 more
Job description
Client needs a senior hands-on IAM Engineer III who can become the internal technical owner for a new IGA platform. They do not have IGA in production today and are evaluating solutions like Saviynt and ObserveID. This person will support implementation with the vendor, then own configuration, integrations, operations, access reviews, lifecycle workflows, governance, and compliance long-term. The strongest candidates will have true IGA platform ownership, API-heavy integration experience, PowerShell/Python automation, ISO/HIPAA exposure, and a proven ability to operate in a very fast-paced onsite environment. Important
-
The right candidate will be the technical product owner and primary system owner for the IGA platform.
-
This hire will support implementation, integrations, access governance, day-to-day operations, compliance, and stakeholder management.
Core Responsibilities
-
Act as the technical product owner and system owner for the chosen IGA platform.
-
Partner with the selected IGA vendor and implementation team to deploy IGA across PDS.
-
Own configuration, ongoing maintenance, upgrades, enhancements, and operational support after go-live.
-
Build, manage, and troubleshoot application integrations into the IGA platform.
-
Develop and maintain APIs required for IGA integrations across enterprise applications.
-
Support user lifecycle management workflows, including joiner, mover, and leaver processes.
-
Coordinate and execute access reviews and certification campaigns across the organization.
-
Support RBAC, entitlement governance, least-privilege access models, and segregation-of-duties controls.
-
Participate heavily in change control, governance, approvals, and compliance workflows.
-
Partner with application owners, Security, IAM, Compliance, Privacy, Clinical Informatics, and broader IT stakeholders.
-
Maintain documentation, workflow maps, control evidence, SOPs, and operational procedures.
- Help operationalize controls tied to HIPAA, ISO, and other applicable security/compliance frameworks., The strongest candidate is a senior hands-on IAM/IGA engineer who has owned a platform, not merely supported one as a narrow team contributor. PDS needs someone who can operate as an engineer during implementation and then transition into technical product owner/system owner after implementation.
-
Mid-sized or mid-market enterprise background preferred.
-
Enough scale and complexity to have varied applications, compliance, governance, and stakeholder needs.
-
Not so large that the candidate only owned a tiny piece of the stack.
-
Healthcare or regulated enterprise exposure preferred.
- Comfort wearing multiple hats: engineer, platform owner, implementation partner, integration owner, support escalation point, and governance partner.
Candidate Profiles to Avoid
-
Generic IAM engineers without meaningful IGA depth.
-
Provisioning/helpdesk-only IAM candidates.
-
Architect-only or advisory-only candidates who are not hands-on.
-
Candidates from very small shops with limited complexity.
-
Candidates from massive enterprises who only owned a narrow function.
-
Candidates who cannot interview in person.
-
Candidates without API/integration and automation depth.
- Candidates who only used IGA tools lightly but never owned or administered them., Join a leading organization dedicated to safeguarding digital assets and ensuring robust security across its platforms. We are partnering with Aquent to find top talent to enhance …
- 3 hours ago, Hands-on Senior Identity and Access Management Engineer to join a growing cybersecurity team supporting a large enterprise environment. This individual will serve as the dedicated …
- 12 days ago +
Requirements
-
6+ years of enterprise IAM experience, with meaningful hands-on identity governance exposure.
-
Direct IGA platform experience, ideally Saviynt, ObserveID, SailPoint, Okta Lifecycle Management, Microsoft Entra Identity Governance, or similar.
-
Experience as a technical system owner, primary admin, or major implementation contributor for an IGA platform.
-
Strong understanding of identity lifecycle management, access governance, RBAC, access certifications, and entitlement management.
-
Hands-on IGA integration experience using REST APIs, SCIM, SAML, OAuth/OIDC, LDAP, or related standards.
-
Strong PowerShell, Python, or equivalent automation experience applied to IAM/IGA workflows.
-
Comfort building, maintaining, and troubleshooting APIs for application integrations.
-
Experience supporting compliance-driven environments, especially ISO and HIPAA.
-
Ability to work in a fast-paced, high-volume, multi-stakeholder environment.
-
Comfort being the internal go-to SME where the buck stops for IGA.
-
Ability to work onsite full-time in Irvine, Dallas, or Henderson.
-
No current or future H-1B sponsorship requirement.
Strong Nice-to-Haves
-
Previous IGA platform implementation from the ground up.
-
Saviynt experience.
-
ObserveID experience.
-
SailPoint or other transferable enterprise IGA experience.
-
Healthcare, dental, medical, life sciences, or other regulated enterprise background.
-
EHR/EMR exposure such as Epic or Cerner.
-
Experience with SaaS security posture tools such as Grip Security, Valence Security, or similar.
-
PAM exposure, especially CyberArk.
-
CISSP, CISM, CISA, Okta certifications, Microsoft Entra SC-300, or vendor-specific IGA certifications.
-
Experience supporting ISO 27001 audit evidence, especially access control evidence.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Why Attend a Developer Event in 2026?
Fully Remote Software Engineer Jobs