Cybersecurity IAM Engineer / SailPoint IdentityIQ and Identity Security Cloud Developer & Architect

Innovee Consulting LLC
New York, NY, United States
8 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Active Directory Application Programming Interfaces (APIs) Amazon Web Services Authentication Protocols Microsoft Azure Software as a Service Cloud Computing Cloud Engineering Code Review Cyber Security Databases
+28 more
Multi-Factor Authentication Human Resources Information System (HRIS) Identity and Access Management JSON Lightweight Directory Access Protocols (LDAP) OAuth Object-Oriented Software Development OpenID Performance Tuning Role-Based Access Control Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Simple Object Access Protocol (SOAP) SQL Databases Data Streaming Systems Integration Extensible Markup Language (XML) Google Cloud Okta Power Platform Integration HybridCloud HR Software Material UI SailPoint Restful APIs BeanShell Servicenow

Job description

Role: Cybersecurity IAM Engineer / SailPoint IdentityIQ and Identity Security Cloud Developer & Architect, The Cybersecurity IAM Engineer / SailPoint IdentityIQ and Identity Security Cloud Developer & Architect is responsible for designing, engineering, and modernizing enterprise identity governance capabilities across hybrid cloud and on prem environments. This role blends deep SailPoint IdentityIQ and Identity Security Cloud development with IAM architecture leadership, including lifecycle automation, integration patterns, governance frameworks, and ServiceNow workflow orchestration.

The engineer will serve as a technical authority for identity lifecycle, access governance, directory integrations, and SailPoint platform architecture-ensuring secure, scalable, and compliant IAM operations aligned with Zero Trust principles.

SailPoint IIQ and ISC Developer/Administrator with Okta and Citizen IAM We’re looking for a talented SailPoint IIQ and ISC Developer/Administrator to join our team. You’ll play a key role in developing, administering, and maintaining our identity and access management (IAM) solutions, ensuring secure and efficient access across our organization. Expertise in Okta and Citizen IAM initiatives is a strong plus., * Design, implement, and maintain SailPoint IIQ and ISC solutions

  • Develop and automate workflows, connectors, and application onboarding
  • Administer and support Microsoft Entra ID (Azure AD), including Privileged Identity Management (PIM)
  • Integrate IAM systems with cloud platforms such as AWS, Azure, or Google Cloud Platform
  • Implement and manage Okta solutions, with a focus on Citizen IAM and external user identity needs
  • Conduct code reviews to eliminate redundancies and optimize system logic
  • Identify and address IAM vulnerabilities early in the development process
  • Collaborate with IT stakeholders and business owners to mature Role-Based Access Control (RBAC) andapplication onboarding programs
  • Manage and integrate APIs, privilege access management (PAM) tools, SailPoint Access History, SailPoint Access Modeling and database platforms
  • Test, deploy, and recommend patches and upgrades for IAM systems
  • Migration from IIQ to ISC for the upcoming project
  1. SailPoint IdentityIQ Engineering & Development:
  • Develop and maintain BeanShell rules, custom workflows, lifecycle event logic, task definitions, and plugin modules.
  • Engineer custom connectors, aggregation jobs, reconciliation logic, and provisioning adapters.
  • Build scalable application onboarding frameworks, entitlement schemas, and role models.
  • Implement and optimize certification campaigns, policy enforcement, SoD controls, and governance reporting.
  • Extend IIQ using Java, REST APIs, SCIM, and custom UI components.
  1. IAM Architecture & Solution Design:
  • Define and maintain end to end IAM architecture, including identity sources, directories, governance layers, and provisioning flows.
  • Architect scalable identity lifecycle frameworks supporting joiner/mover/leaver automation, authoritative source alignment, and attribute driven access.
  • Design integration patterns between SailPoint IIQ and ServiceNow, including:
  • Access request workflows
  • Automated ticket creation and closure
  • Provisioning orchestration
  • Incident and change management alignment
  • Catalog item governance and approval routing
  • Establish RBAC/ABAC frameworks, role mining strategies, and access modeling standards.
  • Create architectural diagrams, data flow maps, and governance models for enterprise IAM programs.
  • Evaluate modernization opportunities (e.g., SailPoint SaaS, passwordless, adaptive risk, ServiceNow IAM modules).
  • Lead design reviews, threat modeling sessions, and IAM roadmap planning with cybersecurity leadership.
  1. Integration & Directory Services
  • Architect and implement integrations with Active Directory, LDAP, Azure AD/Entra ID, HR systems, cloud applications, and ServiceNow.
  • Develop REST/SOAP integrations, SCIM connectors, and custom provisioning logic.
  • Implement authentication and federation patterns using SAML, OAuth, OIDC, and MFA platforms.
  • Ensure directory hygiene, identity data quality, and lifecycle accuracy across systems.
  1. ServiceNow Integration & Workflow Engineering
  • Design and maintain ServiceNow IAM workflows, including access request, approval routing, and fulfillment automation.
  • Integrate SailPoint IIQ with ServiceNow for:
  • Ticket based provisioning and deprovisioning
  • Automated incident creation for provisioning failures
  • Change management workflows tied to IAM operations
  • Catalog item governance and entitlement mapping
  • Collaborate with ServiceNow platform owners to ensure alignment between IAM processes and enterprise workflow standards.
  • Optimize ServiceNow * SailPoint * downstream system orchestration for speed, accuracy, and auditability.
  • Support migration or redesign efforts when ServiceNow is used as a front end for IAM services., + Engineer automated controls supporting SOX, HIPAA, ISO 27001, and NIST compliance.
  • Conduct root cause analysis for provisioning failures, connector issues, workflow errors, and performance bottlenecks.
  • Partner with security architects to align IAM architecture with enterprise cybersecurity strategy.
  1. Operational Support & Platform Stability

*

  • Support production IIQ environments, including break/fix, patching, upgrades, and performance tuning.
  • Maintain detailed technical documentation, architectural diagrams, and operational runbooks.
  • Collaborate with HRIS, infrastructure, ServiceNow, and application teams to resolve identity issues and improve lifecycle reliability.

Requirements

  • 5-9 years in IAM engineering, with 5-10+ years of SailPoint IdentityIQ development.
  • Strong proficiency in Java, BeanShell, XML, JSON, SQL, and REST API development.
  • Deep understanding of IIQ object model, connector frameworks, workflow engine, and plugin architecture.
  • Hands on experience architecting integrations between SailPoint IIQ and ServiceNow.
  • Strong knowledge of directory services, identity stores, and authentication protocols. Security & Governance

  • Expertise in identity governance concepts, RBAC/ABAC, SoD, and policy enforcement.
  • Familiarity with compliance frameworks (NIST)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

Videos

See all

Related articles

See all