Architect, implement, and maintain automated IAM solutions spanning on-premises and cloud environments, with a focus on enterprise-scale Active Directory and SailPoint integrations.
Develop and optimize automation scripts, workflows, and connectors (using PowerShell, BeanShell, Python, etc.) to streamline user provisioning/deprovisioning, group management, access reviews, and certifications.
Lead integration projects between SailPoint (IdentityNow/IdentityIQ), Active Directory (including Azure AD), and cloud security solutions (e.g., Zscaler, Okta, AWS IAM, Azure Security, etc.).
Design, deploy, and manage automated access controls and RBAC policies, ensuring compliance with security and privacy regulations (SOX, GDPR, HIPAA, etc.).
Serve as the subject matter expert for Active Directory, including schema management, GPOs, privileged access, domain trust relationships, and hybrid identity synchronization.
Automate and orchestrate processes across cloud security tools, facilitating secure user onboarding/offboarding, privilege management, and audit trail generation.
Troubleshoot complex IAM and directory synchronization issues and lead root-cause analysis for incidents involving identity or access failures.
Partner with other IT, cloud, and security engineering teams to drive automation best practices and cross-platform security initiatives.
Maintain comprehensive documentation for architectures, workflows, procedures, and configuration changes in the IAM ecosystem.
Lead IAM-related audit support, evidence collection, and remediation activities using automated tools and reporting.
Requirements
Bachelor's or master's degree in computer science, Information Security, or a related technical field.
7+ years of progressively responsible experience in enterprise IAM engineering, with significant automation responsibility.
Expert-level knowledge of Active Directory (user and group management, GPO, delegation, AD security, hybrid/cloud sync).
Advanced, hands-on experience with SailPoint (IdentityNow or IdentityIQ), especially in automating identity lifecycle workflows, custom connector development, and policy enforcement.
Proven ability to automate IAM and security administration via scripting (PowerShell, Python, BeanShell, or similar).
Demonstrated experience automating tasks within leading cloud security platforms (e.g., AWS IAM, Azure AD, Zscaler, Okta, Google Workspace, etc.).
Strong understanding of identity protocols (LDAP, SAML, OIDC, OAuth2.0, SCIM) and integration patterns for cloud and on-premises systems.
Solid grasp of RBAC, least-privilege approaches, and regulatory/compliance drivers in enterprise IAM practice.
Experience with Infrastructure as Code (IaC), CI/CD pipelines, or SOAR platforms a plus.
SailPoint Certified Engineer (IdentityNow or IdentityIQ) and Microsoft Certified: Identity and Access Administrator or similar is a plus.
Experience with identity governance, privileged access management (PAM), and multi-cloud IAM strategies is a plus.
Benefits
Comprehensive health benefits, life and disability insurance, and fertility and family-forming support programs
Generous paid time off, paid holidays, volunteer time off, and quarterly self-care days and no meeting days
Tuition and reading reimbursement programs to support your continuous learning and professional growth
Thrive Global Wellness Program, confidential Employee Assistance Program (EAP), as well as One to One Wellness Coaching
Employee programs—including Employee Resource Groups (ERGs), GoTo Gives, and our charitable matching program—to amplify your connection and impact.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
Active DirectorySailPointPowerShellPythonBeanShellRBACIdentity protocolsInfrastructure as CodeCI/CD pipelinesautomation scripting