Senior Identity Governance and Administration (IGA) Engineer (SailPoint)

Leidos, Inc.
Tampa, FL, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$131,300.0 - $237,350.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory CompTIA Security+ Data Stores Identity and Access Management Lightweight Directory Access Protocols (LDAP) NIPRNet Role-Based Access Control Azure Active Directory Zero Trust Network Access Simple Object Access Protocol (SOAP) SC Clearance Customer Identity Access Management
+2 more
HR Software SailPoint

Job description

Leidos is seeking a highly skilled Senior Identity Governance and Administration (IGA) Engineer to join the Zero Trust execution team at U.S. Special Operations Command (USSOCOM). In a Zero Trust architecture, identity is the new perimeter, and this role is responsible for building and maintaining the ā€œsource of truthā€ that governs access to the Command’s most critical data.

As the IGA Engineer, you will lead the implementation and configuration of SailPoint across the NIPR, SIPR, and Top-Secret networks. You will move beyond basic account provisioning to implement a sophisticated Attribute-Based Access Control (ABAC) model. You will be responsible for defining and managing the lifecycle of ā€œTrust Attributesā€ (such as clearance level, training status, and job role) that are consumed by downstream enforcement tools like Microsoft Purview and Kiteworks. Your work ensures that when a user’s status changes, their access to sensitive data is updated instantly-even in air-gapped environments, * SailPoint Architecture & Configuration: Lead the design, deployment, and ongoing management of SailPoint IdentityNow (or IIQ) to automate the full identity lifecycle (Joiner, Mover, Leaver) across hybrid and on-premises environments.

  • ABAC Attribute Management: Define and manage the schema for ā€œTrust Attributesā€ (e.g., Clearance, COI, Project Codes) within SailPoint, ensuring they align with the NIST 8112 metadata standard for consumption by policy decision points.
  • Air-Gapped Identity Operations: Manage the offline instance of SailPoint on the Top-Secret network, developing the workflows to import ā€œAttribute Manifestsā€ and ensure that identity data remains synchronized with the low-side source of truth.
  • Access Certification: Configure and execute automated access certification campaigns for critical data repositories and privileged roles, ensuring compliance with DoD audit requirements.
  • Role Modeling: Work with mission owners to define Technical Roles and Business Roles within SailPoint, replacing broad, static Active Directory groups with granular, policy-driven access roles.

Requirements

  • BS and 12 - 15 years of prior relevant experience or Masters with 10 - 13 years of prior relevant experience. Additional 4 years experience can be substituted without a degree.
  • Active Top-Secret clearance with SCI eligibility.

Required Experience & Skills

  • 10+ years hands-on experience designing, implementing, and administering SailPoint (IdentityNow or IdentityIQ) in a large enterprise environment.
  • Experience working on high-visibility or mission critical aspects of a given program and performs all functional duties independently
  • Deep understanding Identity Lifecycle Management, the Joiner-Mover-Leaver (JML) process and experience automating provisioning/deprovisioning workflows connected to HR systems and Active Directory.
  • Strong knowledge of Active Directory, LDAP, and Azure Active Directory (Entra ID) structures and management.
  • Proven experience of Governance Principles, working with Role-Based Access Control (RBAC) modeling, Separation of Duties (SoD) policy creation, and access certification
  • experience overseeing the efforts of less senior staff and/or be responsible for the efforts of all staff assigned to a specific job.
  • CompTIA Security+ CE (or higher) to meet DoD 8570 IAT Level II requirements.

Preferred Experience & Skills

  • Experience implementing Attribute-Based Access Control (ABAC) strategies.
  • Familiarity with DoD Identity, Credential, and Access Management (ICAM) reference designs.
  • Knowledge of integration protocols such as REST, SCIM, and SOAP.
  • Experience supporting USSOCOM or other DoD agencies.

Certifications (Preferred)

  • SailPoint Certified IdentityNow Engineer or SailPoint Certified IdentityIQ Engineer.
  • Certified Identity and Access Manager (CIAM) or CISA.

Benefits & conditions

Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

About the company

If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 - and moving faster than anyone else dares., Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:20 min

Decoupling user data with decentralized web nodes

Angie Jones Angie Jones Ā· WWC 2023

2:08 min

Managing complex structures and corporate guidelines

Alexandra Petri Ā· WWC 2023

1:32 min

Understanding fast, accurate, and big data store trade-offs

Philipp Krenn Ā· WWC 2022

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 Ā· Coffee With Developers

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter Ā· WWC 2024

1:07 min

Introduction to OpenSearch and data management

Olena Kutsenko Ā· WWC 2022

Videos

See all

Related articles

See all