About The Position

The IAM SailPoint Administrator is responsible for the day-to-day administration, configuration, and operational support of Cook County Health’s Identity Governance & Administration (IGA) platforms, including SailPoint Identity Security Cloud (ISC) and Non-Employee Risk Management (NERM). This role ensures secure, compliant, and efficient identity lifecycle operations by managing provisioning workflows, entitlement governance, certification campaigns, and user-access–level directory operations. The IAM SailPoint Administrator partners with IAM leadership, HRIS, IT, and application owners to maintain accurate identity data, streamline access processes, and support the modernization of the IAM program in alignment with HIPAA, NIST, Zero Trust, and internal governance requirements.

Requirements

  • Strong understanding of IGA methodologies and IAM best practices.
  • High attention to detail and data accuracy
  • Ability to manage multiple priorities in a fast-paced environment
  • Clear and professional communication skills
  • Commitment to secure, compliant, and efficient identity operations
  • Collaborative mindset with cross-functional teams
  • Ability to explain IAM concepts to technical and non-technical individuals.
  • Bachelor’s degree in information technology (IT), Computer Science, Cybersecurity, or a related field OR equivalent experience.
  • 3-5+ years of experience supporting Identity & Access Management or IGA platforms.
  • Hands-on experience with SailPoint Identity Security Cloud and Non-Employee Risk Management (NERM).
  • Strong understanding of identity lifecycle management, RBAC/ABAC, SoD, and access governance.
  • Experience with Active Directory user administration, Entra ID, LDAP, SCIM, SSO, MFA, and HRIS systems.
  • Strong analytical and troubleshooting skills.
  • Ability to work in a complex, unionized healthcare environment.

Nice To Haves

  • SailPoint Identity Security Administrator certification.
  • Experience with Cerner, Epic or other EMR identity models.
  • Experience with cloud identity platforms (Entra ID, AWS IAM, GCP IAM).
  • Experience with PowerShell for operational automation (light scripting only).
  • Experience with Postman.
  • Familiarity with healthcare regulatory requirements (HIPAA, HITECH).
  • Experience supporting identity operations in regulated industries (healthcare or financial).

Responsibilities

  • Administer and maintain SailPoint ISC configurations, including Identity Profiles, Access Profiles, Roles, Policies, and Lifecycle Event triggers.
  • Configure and support provisioning workflows, approval chains, and automated lifecycle events (Joiner–Mover–Leaver).
  • Develop and maintain SailPoint Rules (Before/After Provisioning, Aggregation, Correlation).
  • Maintain identity attribute mappings, correlation logic, authoritative source configurations, and identity data quality.
  • Monitor and troubleshoot provisioning failures, connector alerts, and identity synchronization issues.
  • Support connector configuration and maintenance for Active Directory, Entra ID, Epic, FreshService, HRIS, and other enterprise applications (cloud/on-prem).
  • Maintain documentation for configurations, workflows, and operational procedures.
  • Assist with onboarding new applications into SailPoint, including schema review, entitlement harvesting, and basic connector configuration.
  • Collaborate with application owners to define entitlements, roles, and access policies.
  • Validate provisioning, deprovisioning, and access governance readiness for onboarded applications.
  • Support testing of SAML, OAuth2, OIDC, SCIM, and REST-based integrations (no engineering or custom development).
  • Configure and support access certification campaigns (manager, application owner, role-based).
  • Maintain RBAC/ABAC models and support role lifecycle activities.
  • Monitor identity risks such as orphaned accounts, excessive access, and stale entitlements.
  • Support audit and compliance activities (HIPAA, SOX, PCI, ISO 27001) through evidence collection, reporting, and remediation tracking.
  • Ensure IAM processes align with internal governance, regulatory requirements, and Zero Trust principles.
  • Manage user-access-level AD and Entra ID operations, including: account provisioning/deprovisioning group membership updates directory attribute maintenance
  • Support identity data flows between SailPoint, AD, Entra ID, HRIS, and downstream systems.
  • Troubleshoot user-level directory synchronization issues and access discrepancies.
  • Maintain clean, accurate directory structures for identity lifecycle operations.
  • Monitor SailPoint system health, job schedules, queue performance, and connector throughput.
  • Maintain dashboards and reporting for identity lifecycle metrics and operational KPIs.
  • Document operational procedures, troubleshooting steps, and configuration changes.

Benefits

  • Wellbeing programs & work-life balance - integration and passion sharing events.
  • Opportunities for professional growth and career advancement.
  • Remote and hybrid working possibilities.
  • Benefits platform –culture, shopping, sport, etc.
  • Continuous learning programs and online courses.
  • Possibility to participate to charity and eco initiatives.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service