Identity Management Engineer

Stony Brook UniversityTown of Brookhaven, NY
Hybrid

About The Position

The Identity Management Engineer is tasked with implementing, maintaining, extending, and troubleshooting the university’s identity management platform and associated technologies. This position is also expected to drive user adoption and educate stakeholders on the value of identity governance. The Identity Management Engineer must have the ability to communicate with others effectively.

Requirements

  • Bachelor’s Degree. In lieu of the Bachelor's degree, a combination of directly related full-time experience supporting Identity and Access Management services and education totaling nine [9] ​years may be considered.
  • Five [5]+ years of dedicated experience in Identity and Access Management (IAM).
  • Experience working with Identity Governance and Administration (IGA).
  • Experience administering and configuring SailPoint Identity Security Cloud (ISC), SailPoint IIQ, Saviynt or similar platforms; including managing identity profiles, access profiles, roles, and transforms.
  • Experience developing programming code.
  • Experience with key identity management and access concepts and principles such as least privilege, privileged access, segregation of duties, role-based access control (RBAC), authentication, authorization, and user lifecycle workflows (Joiner/Mover/Leaver).
  • Experience with IAM technologies and infrastructure, such as single sign-on (SSO), directory federation, SAML, OAuth, multi-factor authentication, user provisioning and self-service, account creation, and management; entitlement review certification and management; enterprise directory architecture and design, and onboarding applications.

Nice To Haves

  • Advanced Degree.
  • Familiarity with SailPoint Non-Employee Risk Management (NERM) for managing the lifecycle of contractors, guests, researchers, and vendors.
  • Experience configuring and deploying self-service Access Request portals and designing Access Certification (user access review) campaigns.
  • An active cyber security or other relevant certification, such as CISSP, CISM, or IDM-specific.
  • Experience onboarding applications and integrating disparate systems using REST APIs, SCIM, JSON, and web services.
  • Experience programming/scripting experience in PL/SQL, Powershell, Linux shell, Java, and/or Perl, Python, JavaScript.
  • Experience working with identity management within a complex University or Medical Center environment.
  • Experience gathering requirements, document workflows (Standard Operating Procedures, runbooks), and translating business needs into technical IAM rules.
  • Experience developing technical and administrative documentation and diagrams.
  • Familiarity with regulations and frameworks such as HIPAA, FERPA, NIST, GDPR, etc.
  • Experience managing complex "multi-persona" identities unique to universities (e.g., users transitioning between student, staff, adjunct faculty, and alumni) and familiarity compliance regulations and frameworks such as FERPA HIPAA, NIST, GDPR, etc.

Responsibilities

  • Implement and develop technologies and processes to enable stable and secure enterprise-wide identity management (IDM) functions. This includes provisioning new user accounts, establishing unique credentials, de-provisioning accounts, self-service password management, and integrating directories and databases for authentication and authorization services.
  • Implement third-party IDM systems and assist in migrating legacy systems to new technologies.
  • Collaborate with vendors and consultants to install, configure, integrate, and test new systems, and upgrade existing ones.
  • Design and maintain custom applications used for IDM functions.
  • Monitor system performance, apply patches, update system configuration, and identify address security vulnerabilities.
  • Integrate IDM solutions with existing systems, applications, and directories, ensuring seamless interoperability and data synchronization across the organization's IT ecosystem.
  • Oversee data integrity by ensuring authoritative sources and target systems are integrated, with identity data normalized and reliable.
  • Implement technology and processes for managing the lifecycle of digital identities, including user provisioning, de-provisioning, role-based access control (RBAC), and recertification campaigns to ensure efficient governance and compliance.
  • Work closely with service owners to ensure the identity management platform integrates seamlessly with Single Sign-On (SSO) and modern protocols such as OAuth, SAML, and OpenID Connect, streamlining user authentication and access across multiple applications and platforms.
  • Implement and enforce robust security measures, such as multi-factor authentication (MFA), encryption, and least privilege access controls, to protect sensitive identity-related data and mitigate the risk of unauthorized access or data breaches.
  • Establish monitoring and auditing mechanisms to detect security incidents, track user activity, and assess the effectiveness of IDM controls, supporting continuous improvement and compliance validation.
  • Ensure that systems and procedures adhere to security best practices and comply with all relevant university policies regarding information security, change management, and communications.
  • Collaborate with cross-functional teams, including IT, security, compliance, and business units, to gather requirements, assess technical feasibility, and ensure alignment with business objectives.
  • Assist end-users and IT support staff with access-related issues, providing high-quality customer service at all times.
  • Fully document implementation and configuration details, ensuring alignment with regulatory requirements and industry best practices while addressing organizational security and compliance needs.
  • Other duties or projects as assigned as appropriate to rank and department mission.

Benefits

  • SUNY implemented a hybrid telecommuting pilot program. This position has been approved to participate in the pilot, which allows for up to 5 remote days per pay period.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service