IT Security Operations

New Wave PeopleManhattan, NY
Hybrid

About The Position

The Cybersecurity IAM Engineer / SailPoint IdentityIQ and Identity Security Cloud Developer & Architect is responsible for designing, engineering, and modernizing enterprise identity governance capabilities across hybrid cloud and on prem environments. This role blends deep SailPoint IdentityIQ and Identity Security Cloud development with IAM architecture leadership, including lifecycle automation, integration patterns, governance frameworks, and ServiceNow workflow orchestration. The engineer will serve as a technical authority for identity lifecycle, access governance, directory integrations, and SailPoint platform architecture—ensuring secure, scalable, and compliant IAM operations aligned with Zero Trust principles. SailPoint IIQ and ISC Developer/Administrator with Okta and Citizen IAM We're looking for a talented SailPoint IIQ and ISC Developer/Administrator to join our team. You'll play a key role in developing, administering, and maintaining our identity and access management (IAM) solutions, ensuring secure and efficient access across our organization. Expertise in Okta and Citizen IAM initiatives is a strong plus.

Requirements

  • 5–9 years in IAM engineering, with 5–10+ years of SailPoint IdentityIQ development.
  • Strong proficiency in Java, BeanShell, XML, JSON, SQL, and REST API development.
  • Deep understanding of IIQ object model, connector frameworks, workflow engine, and plugin architecture.
  • Hands on experience architecting integrations between SailPoint IIQ and ServiceNow.
  • Strong knowledge of directory services, identity stores, and authentication protocols.
  • Expertise in identity governance concepts, RBAC/ABAC, SoD, and policy enforcement.
  • Familiarity with compliance frameworks (NIST)
  • Proper footwear required to perform tasks in a safe manner.

Nice To Haves

  • Okta and Citizen IAM expertise
  • Experience with Microsoft Entra ID (Azure AD), including Privileged Identity Management (PIM)
  • Experience integrating IAM systems with cloud platforms such as AWS, Azure, or GCP
  • Experience with Okta solutions, with a focus on Citizen IAM and external user identity needs
  • Experience managing and integrating APIs, privilege access management (PAM) tools, SailPoint Access History, SailPoint Access Modeling and database platforms
  • Experience with migration from IIQ to ISC
  • Experience with SailPoint Identity Security Cloud (ISC)
  • Experience with ServiceNow workflow orchestration
  • Experience with Zero Trust principles
  • Experience with SOX, HIPAA, ISO 27001 compliance frameworks

Responsibilities

  • Design, implement, and maintain SailPoint IIQ and ISC solutions
  • Develop and automate workflows, connectors, and application onboarding
  • Administer and support Microsoft Entra ID (Azure AD), including Privileged Identity Management (PIM)
  • Integrate IAM systems with cloud platforms such as AWS, Azure, or GCP
  • Implement and manage Okta solutions, with a focus on Citizen IAM and external user identity needs
  • Conduct code reviews to eliminate redundancies and optimize system logic
  • Identify and address IAM vulnerabilities early in the development process
  • Collaborate with IT stakeholders and business owners to mature Role-Based Access Control (RBAC) and application onboarding programs
  • Manage and integrate APIs, privilege access management (PAM) tools, SailPoint Access History, SailPoint Access Modeling and database platforms
  • Test, deploy, and recommend patches and upgrades for IAM systems
  • Migration from IIQ to ISC for the upcoming project
  • Develop and maintain BeanShell rules, custom workflows, lifecycle event logic, task definitions, and plugin modules.
  • Engineer custom connectors, aggregation jobs, reconciliation logic, and provisioning adapters.
  • Build scalable application onboarding frameworks, entitlement schemas, and role models.
  • Implement and optimize certification campaigns, policy enforcement, SoD controls, and governance reporting.
  • Extend IIQ using Java, REST APIs, SCIM, and custom UI components.
  • Define and maintain end to end IAM architecture, including identity sources, directories, governance layers, and provisioning flows.
  • Architect scalable identity lifecycle frameworks supporting joiner/mover/leaver automation, authoritative source alignment, and attribute driven access.
  • Design integration patterns between SailPoint IIQ and ServiceNow, including: Access request workflows, Automated ticket creation and closure, Provisioning orchestration, Incident and change management alignment, Catalog item governance and approval routing
  • Establish RBAC/ABAC frameworks, role mining strategies, and access modeling standards.
  • Create architectural diagrams, data flow maps, and governance models for enterprise IAM programs.
  • Evaluate modernization opportunities (e.g., SailPoint SaaS, passwordless, adaptive risk, ServiceNow IAM modules).
  • Lead design reviews, threat modeling sessions, and IAM roadmap planning with cybersecurity leadership.
  • Architect and implement integrations with Active Directory, LDAP, Azure AD/Entra ID, HR systems, cloud applications, and ServiceNow.
  • Develop REST/SOAP integrations, SCIM connectors, and custom provisioning logic.
  • Implement authentication and federation patterns using SAML, OAuth, OIDC, and MFA platforms.
  • Ensure directory hygiene, identity data quality, and lifecycle accuracy across systems.
  • Design and maintain ServiceNow IAM workflows, including access request, approval routing, and fulfillment automation.
  • Integrate SailPoint IIQ with ServiceNow for: Ticket based provisioning and deprovisioning, Automated incident creation for provisioning failures, Change management workflows tied to IAM operations, Catalog item governance and entitlement mapping
  • Collaborate with ServiceNow platform owners to ensure alignment between IAM processes and enterprise workflow standards.
  • Optimize ServiceNow → SailPoint → downstream system orchestration for speed, accuracy, and auditability.
  • Support migration or redesign efforts when ServiceNow is used as a front end for IAM services.
  • Apply Zero Trust, least privilege, RBAC/ABAC, and governance principles to all IAM designs.
  • Engineer automated controls supporting SOX, HIPAA, ISO 27001, and NIST compliance.
  • Conduct root cause analysis for provisioning failures, connector issues, workflow errors, and performance bottlenecks.
  • Partner with security architects to align IAM architecture with enterprise cybersecurity strategy.
  • Support production IIQ environments, including break/fix, patching, upgrades, and performance tuning.
  • Maintain detailed technical documentation, architectural diagrams, and operational runbooks.
  • Collaborate with HRIS, infrastructure, ServiceNow, and application teams to resolve identity issues and improve lifecycle reliability.

Benefits

  • Salary commensurate with scope of work job experience
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service