Apply your Identity and Access Management expertise to support and strengthen a complex enterprise IAM environment. This role is ideal for a senior hands-on IAM professional with deep experience administering SailPoint IdentityIQ, Ping Identity, directory services, SSO, MFA, federation, identity governance, and application onboarding.
You will help maintain secure and compliant access across enterprise systems while improving provisioning, de-provisioning, access certifications, entitlement management, role-based access controls, integrations, and operational reliability.
This is not a general network-security role. The position requires direct, hands-on IAM platform administration and troubleshooting experience.
Work Location / Schedule Work location and onsite expectations should be confirmed during the recruiting process.
Candidates must be able to work effectively with technical and functional teams in a large enterprise environment.
Role Overview The Senior IAM Engineer will administer and support SailPoint IdentityIQ and Ping Identity platforms within a complex enterprise Identity and Access Management environment.
The role will support identity lifecycle management, access governance, application onboarding, federation, SSO, MFA, entitlement management, audits, incident response, troubleshooting, documentation, and platform reliability.
The engineer will also provide technical guidance to junior team members and partner with application, infrastructure, security, and business teams to implement secure IAM solutions.
Key Responsibilities - Administer, configure, maintain, and support SailPoint IdentityIQ.
- Administer and support Ping Identity platforms.
- Manage identity lifecycle processes, including:
- Provisioning
- De-provisioning
- Joiner, mover, and leaver processes
- Access requests
- Access certifications
- Entitlement management
- Implement and maintain identity-governance policies and controls.
- Support role-based access control and access-review processes.
- Onboard enterprise applications and services into the IAM ecosystem.
- Configure and troubleshoot application integrations, connectors, workflows, and access flows.
- Support Active Directory, LDAP, SSO, MFA, and federation integrations.
- Work with SAML, OAuth, and OpenID Connect protocols.
- Monitor IAM platforms for availability, performance, failures, and security issues.
- Troubleshoot and resolve complex IAM platform and integration problems.
- Develop scripts and automation using PowerShell, Python, or similar languages.
- Support IAM-related incidents, root-cause analysis, remediation, and recovery.
- Prepare access reports and documentation for audits and compliance reviews.
- Interpret and apply enterprise security policies, standards, and procedures.
- Assist with the development and enforcement of IAM standards and best practices.
- Collaborate with technical and functional teams to create solution documentation.
- Provide technical guidance and support to junior team members and stakeholders.
- Communicate risks, issues, progress, and recommendations clearly to technical and nontechnical audiences.
Required Qualifications - At least seven years of experience in Identity and Access Management.
- At least four years of hands-on experience administering SailPoint IdentityIQ and/or Ping Identity solutions.
- Strong experience with SailPoint IdentityIQ administration, configuration, integrations, or lifecycle management.
- Experience supporting Ping Identity products or comparable enterprise federation platforms.
- At least seven years of experience with:
- Active Directory
- LDAP
- Single sign-on
- Multifactor authentication
- SAML
- OAuth
- OpenID Connect
- Strong understanding of IAM concepts, including:
- Provisioning
- De-provisioning
- Access reviews
- Access certifications
- Entitlement management
- Role-based access control
- Identity lifecycle management
- Experience using PowerShell, Python, or similar scripting languages for automation or customization.
- Experience working in enterprise environments with complex IAM requirements.
- Strong troubleshooting experience across IAM platforms and integrations.
- Ability to interpret and apply security policies and standards.
- At least five years of experience implementing enterprise system integrations.
- Experience collaborating with technical and functional teams to create solution documentation.
- Strong written and verbal communication skills.
- Strong analytical, creative-thinking, and problem-solving abilities.
Preferred Qualifications - Experience supporting a Texas state-government agency.
- SailPoint IdentityIQ certification.
- Ping Identity certification.
- Familiarity with ITIL practices.
- Familiarity with NIST or comparable cybersecurity frameworks.
- Experience supporting audit and compliance initiatives.
- Experience mentoring or providing technical guidance to junior IAM team members.
Ideal Candidate Profile The ideal candidate is a senior IAM practitioner who has personally administered and troubleshot SailPoint IdentityIQ and Ping Identity in a large enterprise environment.
This person understands both identity governance and access-management technologies. They can onboard applications, support provisioning workflows, troubleshoot federation and directory issues, automate recurring tasks, produce audit documentation, and communicate effectively with security, infrastructure, application, and business teams.
The strongest candidate will be hands-on, dependable, analytical, and comfortable taking ownership of complex IAM issues through resolution.