Engineer, Identity and Access Management

Intercontinental Exchange Holdings, Inc.

$100K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, IT, Cybersecurity, or related field, or equivalent experience.
  • Hands-on experience with SailPoint ISC platform administration and workflow development.
  • Strong IAM fundamentals, including lifecycle management and provisioning in large enterprises.
  • Proven experience in application onboarding and connector setup in SailPoint.
  • Scripting experience for identity automation using Python, REST, or JSON.
  • Experience with ServiceNow integration for access request workflows.
  • Familiarity with identity-related audit activities in regulated environments.

Responsibilities

  • Administer SailPoint ISC for provisioning and lifecycle management across the enterprise.
  • Design and maintain workflows and integrations within the ISC platform.
  • Configure connectors and map attributes for new applications.
  • Support IIQ-to-ISC migration, including application onboarding and validation.
  • Automate identity processes using SailPoint APIs and scripting.
  • Diagnose and resolve issues related to provisioning and workflows.
  • Manage ServiceNow integration for access requests and approvals.

Benefits

  • Opportunity to work in a production-critical environment with direct impact on compliance.
  • Dynamic role with hands-on responsibilities in identity management.
  • Participation in ongoing migrations and technological advancements in identity security.
  • Collaborative work culture with exposure to diverse technical stakeholders.
  • Potential for career growth in a rapidly evolving field of identity management.
Full Job Description
Overview

Job Purpose

The SailPoint ISC Engineer is responsible for the administration, engineering, and operational health of ICE's Identity and Access Management platform. This role supports the systems governing how enterprise access is granted, changed, and revoked, helping ensure identity lifecycle events execute reliably and in accordance with ICE's security and regulatory requirements. The engineer will build and maintain workflows and integrations, onboard applications into SailPoint Identity Security Cloud (ISC), and support the ongoing migration from IdentityIQ (IIQ). This is a hands-on role in a production-critical environment where precision directly impacts compliance and operational continuity.

 

Responsibilities

  • Administers SailPoint ISC end-to-end, including provisioning, deprovisioning, and lifecycle event management across the enterprise.
  • Designs, builds, and maintains workflows, transforms, rules, and integrations within the ISC platform.
  • Owns connector configuration, attribute mapping, and entitlement aggregation for new applications.
  • Supports IIQ-to-ISC migration activities, including application re-onboarding and cutover validation.
  • Automates identity processes using SailPoint APIs, REST integrations, and scripting; identifies opportunities to reduce manual identity lifecycle activities.
  • Diagnoses and resolves provisioning failures, workflow errors, and connector issues from root cause through resolution.
  • Manages the ServiceNow integration for access request routing, approvals, and provisioning fulfillment.
  • Produces access evidence, generates reports, and supports certification campaigns for internal and external audits.
  • Maintains runbooks, technical standards, and platform documentation to support team continuity and audit readiness.
  • Performs other related duties as assigned.
  • Requires rotational on-call support.

 

Knowledge and Experience

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field, or an equivalent combination of education, training, and relevant work experience.
  • Hands-on SailPoint ISC experience, including platform administration, workflow development, connector configuration, and provisioning rule management. IIQ-only experience does not satisfy this requirement.
  • Strong IAM fundamentals, including joiner/mover/leaver lifecycle management, RBAC, entitlement management, provisioning, and access governance in a large enterprise environment.
  • Experience building SailPoint workflows, transforms, and provisioning rules and translating business requirements into platform logic.
  • Experience owning the full SailPoint application onboarding lifecycle, from connector setup through certification configuration.
  • Scripting and API integration experience applied to identity automation, such as Python, BeanShell, REST, and JSON.
  • Experience integrating SailPoint with ServiceNow for access request and provisioning workflows.
  • Experience supporting identity-related audit activities, including evidence generation and access certifications in a regulated environment.
  • Ability to troubleshoot independently and communicate effectively with technical and non-technical stakeholders.

 

Desirable Skills

  • Direct experience supporting or leading an IIQ-to-ISC migration, including configuration mapping, application re-onboarding, and production cutover.
  • Exposure to Azure Active Directory, AWS IAM, or similar cloud directory services.
  • Experience querying identity data for reporting and audit evidence using SQL, Snowflake, or equivalent tools.
  • Background in financial services or another regulated environment with formal access governance requirements.
  • Familiarity with SCIM, SAML, OAuth 2.0, and OIDC.
  • SailPoint ISC or IIQ certification, CISSP, CISM, or equivalent.
  • Excellent analytical, decision-making, and problem-solving skills.
  • Ability to multitask in a fast-paced environment with a focus on timeliness, documentation, and communication.

#LI-SH3

#LI-ONSITE

Similar Jobs

More Jobs at Intercontinental Exchange Holdings, Inc.

More Information Technology Jobs

Find similar Engineer, Identity and Access Management jobs: