The Identity & Access Management (IAM) Engineer III will assist in the development and enhancement of IAM products like SailPoint, Saviynt, and Okta. This person will support role management, lifecycle management, and access certifications.
This position may be worked remotely within the United States, with the exception of California. East coast applicants must be willing to work central or mountain time zone hours.
This position is not eligible for immigration sponsorship and support. Please do not apply if at any time you will need immigration support now or in the future (i.e., H-1B, PERM). All positions, regardless of location, may require an onsite interview or in-person onboarding requirements to verify your identity.
What you'll be responsible for:
• Assists in planning, designing, developing, and implementing IAM products such as SailPoint, Saviynt, and Okta.
• Supports the analysis and implementation of authorization methods like RBAC, ABAC, PBAC, role management, lifecycle management, separation of duties (SOD), and access certifications.
• Configures, integrates, and tailors existing IAM products to address business problems or meet client requirements.
• Reviews IAM technical white papers and provide guidance to the team on future offerings.
• Manages identity lifecycle events, including access certifications, assigning permissions, deleting accounts, and making role changes.
• Performs integrations with directories (cloud and on-prem) and cloud platforms (e.g., AWS, GCP, Azure).
• Aligns business needs with technology and standards related to identity creation, deletion, vaulting, and password management.
• Creates and update metrics, automating data collection and aggregation.
• Builds automation using PowerShell scripts, RPA, SQL, and other tools like Power Automate.
• Participates in information-gathering meetings with clients to understand their needs, business goals, and desired outcomes.
• Performs other duties as assigned.
What you'll need to have:
• Minimum of 5 years' experience with Identity and Access Management.
• Minimum of 3 years' experience with SailPoint engineering and/or architecting.
• Experience with SailPoint IdentityNow or SailPoint Identity Security Cloud.
• Strong understanding of IAM platforms (SailPoint, Saviynt, Okta) to develop and scale with the organization.
• Experience with creating and updating scripts and code.
• Experience with API's (REST, JSON) and cloud infrastructure.
What would be nice for you to have:
• Bachelor's degree in Computer Science, Information Technology, Cybersecurity preferred.
• Advanced knowledge of access management frameworks (RBAC/ABAC/PBAC).
• Good understanding of Microsoft Active Directory and cloud platforms (AWS, GCP, Azure).
• Comprehensive understanding of security and access certification processes.
• Proficiency in automation tools (PowerShell, RPA, SQL, Power Automate).
• Experience with cloud and on-premises directory integrations.
• Advanced in access certification and SOD implementation.
• Advanced analytical and problem-solving skills.
• Experience with Privileged Access Management tools (eg. Delinea Secret Server).
If you got this far, we hope you're feeling excited about this opportunity. Even if you don't feel you meet every single requirement on this posting, we still encourage you to apply. We're eager to meet motivated people who align with Jack Henry's mission and can contribute to our company in a variety of ways.