Data Engineer Jobs

6,868 jobs found — updated daily

Lead IAM Provisioning Engineer- SailPoint/ CyberArk/ PKI / Entra ID

NTT DATA ServicesPlano, TX
$89,300 - $124,000Remote

About The Position

This SailPoint-Focused L3 Senior User Provisioning Engineer is a technical leader for identity lifecycle, entitlement engineering, and privileged access across enterprise IGA/PAM and cloud identity platforms. This role owns complex SailPoint and CyberArk integrations, designs Entra ID identity flows, manages PKI and certificate automation, and drives reliability, auditability, and automation across provisioning processes. The L3 engineer resolves escalated incidents, leads root‑cause remediation, and mentors L2/L1 staff.

Requirements

  • 5+ years of hands‑on IAM experience with progressive responsibility in provisioning and identity engineering.
  • Proven, practical experience with SailPoint (IGA) and CyberArk (PAM) implementations.
  • Deep operational knowledge of Entra ID / Azure AD and identity synchronization patterns.
  • Strong understanding of PKI concepts and hands‑on certificate management.
  • Proficient with identity protocols: SCIM, SAML, OAuth/OIDC, MFA.
  • Advanced scripting and automation skills: PowerShell, Python, Bash; experience with Terraform or CloudFormation.
  • Experience with ITSM/ticketing tools (ServiceNow, Jira) and SLA management.
  • Demonstrated ability to perform complex troubleshooting and deliver durable engineering fixes.

Nice To Haves

  • Experience integrating HR systems (Workday, SuccessFactors) with IGA.
  • Familiarity with Kubernetes RBAC, secrets management (Vault, Key Vault), and DevSecOps CI/CD integration.
  • Certifications: SailPoint, CyberArk, Microsoft Identity/Entra, CISSP, or equivalent.

Responsibilities

  • Technical ownership of user lifecycle and entitlement engineering across Active Directory, Entra ID, SaaS apps, and custom systems.
  • SailPoint IGA leadership: design, implement, and tune connectors, provisioning policies, role engineering, reconciliation, and certification campaigns.
  • CyberArk PAM stewardship: onboard targets, manage vault policies, implement credential rotation, and support privileged session controls.
  • PKI and certificate lifecycle: architect and operate certificate issuance, renewal, revocation, and automation for service identities and TLS endpoints.
  • Cloud identity engineering: design Entra ID conditional access, cross‑tenant syncs, and entitlement models; coordinate with AWS/GCP IAM as needed.
  • Automation and infrastructure as code: develop and maintain SCIM/SAML/OIDC connectors, PowerShell/Python scripts, and Terraform/IaC for repeatable provisioning patterns.
  • Incident response and RCA: lead Tier‑3 troubleshooting for provisioning failures, perform root‑cause analysis, implement permanent fixes, and reduce recurrence.
  • Governance and audit readiness: lead access reviews, entitlement remediation, evidence collection, and support external/internal audits.
  • Mentorship and documentation: create runbooks, operational playbooks, and train L1/L2 engineers to improve throughput and reduce manual errors.

Benefits

  • medical, dental, and vision insurance with an employer contribution
  • flexible spending or health savings account
  • life and AD&D insurance
  • short and long term disability coverage
  • paid time off
  • employee assistance
  • participation in a 401k program with company match
  • additional voluntary or legally-required benefits

Career Resources

Build a Resume for Data Engineer

The resume builder that gets results.

  • Get clear feedback so you look as qualified as you are
  • Align your resume with the job to get further in the process, faster
  • Take the guesswork out of resume writing

Explore Related Job Searches

© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service