Senior Identity & Access Management Engineer

GreatAmerica Financial ServicesCedar Rapids, IA
Hybrid

About The Position

GreatAmerica Financial Services is seeking a Senior Identity & Access Management (IAM) Engineer to join their team. This role is responsible for designing, implementing, and enhancing the company's identity governance, access management, and privileged access capabilities. The engineer will act as a senior technical specialist, ensuring that identity and access controls are secure, scalable, automated, and meet regulatory, audit, and risk management requirements. The position involves working with technologies such as SailPoint, CyberArk, and Okta to develop enterprise identity lifecycle processes, role-based access controls, privileged access solutions, and authentication services. Collaboration with Security, Audit, Compliance, Infrastructure, and Application teams is crucial to translate security requirements into technical solutions, driving automation, operational efficiency, and governance maturity. The Senior IAM Engineer will play a vital role in improving access governance, supporting regulatory compliance, reducing access-related risks, and ensuring the reliability of identity services across the organization.

Requirements

  • 5+ years of hands-on experience in Identity and Access Management engineering or administration roles.
  • 3+ years of direct, hands-on experience with SailPoint (IdentityIQ and/or IdentityNow), including lifecycle workflows, certification campaigns, and connector development or integration.
  • Demonstrated experience designing and deploying RBAC models, including role mining, role engineering, and role lifecycle governance.
  • Working experience with CyberArk PAM, including vaulting, session isolation and monitoring, and privileged account onboarding.
  • Strong PowerShell scripting and REST API experience for automation, entitlement extracts, reconciliation, and audit evidence generation.
  • Proven ability to build access request automation covering requests, approvals, and fulfillment.
  • Experience automating JML provisioning and deprovisioning across multiple enterprise systems.

Nice To Haves

  • Practical experience integrating and administering Okta as an identity provider, including SSO, MFA, and SCIM-based lifecycle provisioning (depth in two of SailPoint / CyberArk / Okta required; ability to develop depth in the third).
  • Experience in a financial services environment, with a solid understanding of the regulatory and control landscape applicable to banking or financial institutions.
  • Experience supporting ICFR and SOX access controls, including segregation of duties and audit evidence preparation.
  • Familiarity with FFIEC IT examination guidance as it relates to identity governance and logical access.
  • SailPoint Certified IdentityNow/IdentityIQ Engineer
  • CyberArk Defender or Sentry
  • Okta Certified Professional or Administrator
  • CISSP or equivalent

Responsibilities

  • Build and maintain automated identity lifecycle workflows, certification campaigns, and connectors within SailPoint IdentityNow, including connector development and integration with enterprise applications (ServiceNow, ILS).
  • Design, build, and roll out role-based access control (RBAC) models, including role mining, role engineering, and ongoing role lifecycle governance.
  • Integrate and administer Okta as the enterprise identity provider, including single sign-on (SSO), multi-factor authentication (MFA), and lifecycle management through SCIM provisioning.
  • Implement and support CyberArk privileged access management (PAM), including credential vaulting, session isolation and monitoring, just-in-time (JIT) elevation policy administration, elimination of standing privileges, and privileged account onboarding.
  • Support the migration from self-hosted CyberArk PAS to CyberArk Privilege Cloud, report and integration transition, and updates to operational procedures.
  • Develop self-service and automated access request workflows spanning request intake, approval routing, and fulfillment.
  • Automate joiner, mover, and leaver (JML) provisioning and deprovisioning processes across enterprise systems to ensure timely and accurate access changes.
  • Execute recurring access certification campaigns and quarterly configuration reviews (privileged access, password and authentication settings), producing audit-ready evidence for ICFR logical access controls.
  • Support SOX-related access controls, segregation of duties (SoD) enforcement, and the generation of audit evidence for Internal Control over Financial Reporting (ICFR).
  • Develop PowerShell and REST API automation for entitlement extracts, reconciliation, reporting, and audit evidence generation.
  • Apply FFIEC IT examination handbook guidance to identity governance, access control design, and third-party access risk.
  • Partner with security, audit, compliance, and application teams to translate control requirements into engineered, testable technical solutions.
  • Troubleshoot, tune, and document IAM integrations and workflows to ensure reliability, performance, and auditability.

Benefits

  • Competitive Compensation
  • Monthly Bonuses for Eligible Employees
  • 401(k) and Company Match
  • Annual Profit Sharing
  • Paid Vacation
  • Paid Sick Days
  • Ten (10) Paid Holidays per year
  • Gym Reimbursement
  • Health Insurance
  • Dental Insurance
  • Vision Insurance
  • Short-Term and Long Term Disability
  • Company Paid Life Insurance
  • Flexible Spending Accounts (FSA)
  • Health Savings Accounts (HSA)
  • Employee Assistance Program
  • Parental Leave
  • Tuition Assistance
  • Networking Opportunities
  • Leadership Development Opportunities
  • Paid Parking
  • Service Awards
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service