Sr Systems Engineer - IAM

Early Warning®Chicago, IL
$122,000 - $149,000Hybrid

About The Position

The Senior Systems Engineer - IAM is a technical anchor for Early Warning's Identity Governance and Administration (IGA) platform, specifically Saviynt Enterprise Identity Cloud (EIC). This role leads the discovery, design, delivery, and operational health of the platform and its governance controls within a regulated financial technology environment. It is a hands-on, specialized position focused on architecting access models, hardening segregation of duties controls, maintaining technical documentation, participating in audits, and serving as a subject matter expert in identity and access management. The role also involves prototyping new solutions, optimizing existing systems, and evaluating emerging technologies.

Requirements

  • Progressive experience and advanced proficiency with Saviynt Enterprise Identity Cloud, including connector development, workflow configuration, rule and role engineering, and certification campaign design and execution.
  • Expert understanding of identity governance administration constructs including attestations, analytics, connectors, rules, users, accounts, account ownership, roles, entitlements, entitlement ownership, security systems, and endpoints.
  • DevOps support for IGA solutions to include incident and request management and implementation of new functionality including new integrations.
  • Experience integrating IGA solutions with two or more platforms such as Active Directory, Entra ID, Okta, Workday, ServiceNow, and Amazon Web Services.
  • Working knowledge of SQL, REST, SOAP, JSON, XML, Groovy, and PowerShell.
  • Experience developing and testing new integrations and configurations, including API testing through tools such as Postman.
  • Bachelor's degree in Computer Science, Information Technology, Information Systems, Information Assurance, Cybersecurity or a related field, or equivalent work experience.
  • Typically a minimum 5 years of progressive relevant experience in identity and access management, including hands on implementation and operation of enterprise IGA platforms in production.
  • Minimum 3 years of hands on production experience with Saviynt Enterprise Identity Cloud, or equivalent depth in a comparable enterprise IGA platform with demonstrated ability to transition to Saviynt.
  • Deep command of identity governance principles including access certification, segregation of duties, RBAC and ABAC design, entitlement management, and least privilege enforcement.
  • Proven experience designing and automating identity lifecycle processes across heterogeneous systems.
  • Strong working knowledge of core identity and access concepts including directory services, authentication, and federation (SAML, OIDC, OAuth), single sign on, multi factor authentication, and identity lifecycle management.
  • Proficiency with scripting and integration technologies including Python, PowerShell, SQL, and REST APIs.
  • Demonstrated testing experience across both manual and automated approaches, including test planning, execution, and validation of integrations and workflows against functional and security requirements.
  • Strong requirements engineering ability, including eliciting requirements, decomposing complex needs into discrete components, and translating them into usable solutions and design.
  • Demonstrated experience supporting audit and compliance requirements in a regulated environment.
  • Track record of operating at a senior engineering level, including owning technical solutions end to end, resolving ambiguous problems independently, and influencing partners and stakeholders.
  • Ability to perform duties independently, without direct supervision and detailed guidance.
  • Ability to work in a fast paced dynamic environment that often requires shifting priorities.
  • Strong organizational and time management skills with the ability to communicate and collaborate effectively with team members and cross functional teams.
  • Comfortable working in Windows and macOS end user compute environments.
  • Eligibility to work in the United States for any employer at the date of hire.
  • Must pass a background and drug screen.

Nice To Haves

  • Direct experience in financial services, financial technology, or another highly regulated industry.
  • Saviynt certification or equivalent demonstrated expertise.
  • Effective delivery in a highly regulated environment such as PCI DSS.
  • Exposure to complementary IGA and IAM tooling such as SailPoint, Oracle Identity Manager, CyberArk, Delinea, or Okta, and familiarity with privileged access management concepts.
  • Microsoft Azure and AWS cloud experience, including governing access to cloud workloads.
  • Proficiency with Active Directory PKI, key management, certificate authority, or related platforms.
  • Experience working within Agile or SAFe delivery models and CMMI aligned process maturity.
  • Ability to drive strategy sessions for the planning, development, and delivery of work efforts.
  • Other IAM or information security role based certifications.

Responsibilities

  • Owns the architecture, configuration, and operations of the Saviynt EIC platform, including access request, certification, and lifecycle management modules.
  • Provides operational excellence for the identity governance platform including version maintenance, vulnerability management, patching, and overall platform health.
  • Proactively monitors and maintains identity platform security assurances such as threat detection, user behavior analytics, and privileged user monitoring.
  • Builds and manages connectors and integrations across directories, cloud platforms, databases, and enterprise applications, including Active Directory, Entra ID, Okta, ServiceNow, Workday, SAP, cloud infrastructure, and custom REST based endpoints.
  • Authors PowerShell, Python, and other scripts to automate repetitive tasks and extend platform capability.
  • Designs and maintains identity governance controls including access certification and attestation campaigns, segregation of duties (SoD) rulesets, role based and attribute based access models (RBAC and ABAC), and least privilege enforcement.
  • Automates the full identity lifecycle covering joiner, mover, and leaver events, including provisioning, deprovisioning, and access reconciliation, minimizing manual intervention and standing access.
  • Ensures just in time and just enough access is enforced without hindering productivity or user experience.
  • Develops and tunes workflows, rules, analytics, and reporting to detect access risk and drive remediation.
  • Partners with internal audit, risk, and compliance to support control testing and evidence collection for regulatory frameworks relevant to financial services, including SOX, PCI DSS, GLBA, and related audit obligations.
  • Gathers requirements from business, security, and audit stakeholders, decomposes them into discrete technical components, and translates them into usable solutions incorporated into platform design.
  • Establishes repeatable and reusable frameworks, patterns, and reference designs so that solutions scale consistently rather than being rebuilt for each use case.
  • Plans and executes both manual and automated testing across configurations, integrations, and workflows, validating that solutions meet functional, security, and compliance requirements before release.
  • Leads root cause analysis and resolution of complex identity issues spanning provisioning failures, entitlement drift, and integration breaks.
  • Defines technical standards, patterns, and documentation that make the platform sustainable and repeatable as it scales.
  • Continuously evaluates the IAM organizational structure, system configuration, and application integrations, and provides recommendations for operational and security enhancements.
  • Collaborates with Enterprise Architects, Security Architects, and Application Architects to drive adoption of IAM best practices and to support documentation standards.
  • Develops relationships with business and technology stakeholders to ensure on time delivery.
  • Actively participates in team stand up, technical engineering discussions, change control process, audit activities, business continuity efforts, and on call rotation.
  • Mentors, coaches, and trains junior systems engineers, and models a strong sense of responsibility, ownership, and pride in delivering quality results.
  • Contributes to the broader identity roadmap, advising leadership on platform strategy, emerging risks, and modernization opportunities.
  • Supports the company's commitment to risk management and to protecting the integrity and confidentiality of systems and data.

Benefits

  • Competitive medical (PPO/HDHP), dental, and vision plans
  • Company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
  • 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility for the 401(k) Retirement Plan
  • Flexible Time Off for Exempt (salaried) employees
  • Generous PTO for Non-Exempt (hourly) employees
  • 11 paid company holidays
  • Paid volunteer day
  • 12 weeks of Paid Parental Leave
  • Maven Family Planning – provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service