U.S. government security clearance eligibility required
Bachelor's degree in computer science, Cybersecurity, IT, or related field
6+ years in Identity and Access Management (IAM)
4+ years of hands-on experience with SailPoint IdentityIQ or Identity Security Cloud
Active CompTIA Security+ CE or equivalent certification
Strong analytical and troubleshooting skills
Proven ability to manage complex technical projects independently
Responsibilities
Design, configure, deploy, and maintain SailPoint IdentityIQ or Identity Security Cloud
Integrate enterprise applications and services with SailPoint using APIs and connectors
Automate provisioning and de-provisioning processes for user lifecycle events
Manage access certification campaigns and enforce Separation of Duties policies
Support RBAC and ABAC model implementation to minimize over-privileged access
Perform system health checks, tuning, and maintenance for SailPoint environments
Act as a senior technical escalation point for complex provisioning and synchronization issues
Benefits
Opportunity to work on cutting-edge identity governance solutions
Engagement in federal compliance and cybersecurity initiatives
Collaboration with diverse stakeholders across the organization
Potential for professional growth in a specialized field
Access to advanced technologies and tools in identity management
Full Job Description
ITC Digital Solutions is seeking a talented Identity Governance and Administration (IGA) Engineer to design, deploy, configure, and maintain enterprise-wide identity governance solutions utilizing SailPoint IdentityIQ and/or Identity Security Cloud. This position plays a critical role in enhancing cybersecurity, automating identity lifecycle processes, enforcing RBAC policies, and supporting Zero Trust and federal compliance initiatives. The engineer will partner with stakeholders across the organization to deliver secure, efficient, and scalable identity governance capabilities.
Job Responsibilities
As Identity Governance and Administration (IGA) Engineer, you will be responsible for:
Design, configure, deploy, and maintain SailPoint IdentityIQ (IIQ) or SailPoint Identity Security Cloud platforms. Develop custom workflows, rules, forms, policies, and Beanshell/Java scripts.
Integrate enterprise applications, databases, directories (Active Directory, Entra ID, LDAP), and cloud services with SailPoint using out-of-the-box and custom web services/REST APIs/SCIM connectors.
Build and maintain automated provisioning and de-provisioning processes for Joiner, Mover, and Leaver (JML) events across hybrid infrastructures.
Configure and manage periodic access certification campaigns, entitlement catalog structures, and Separation of Duties (SoD) enforcement policies.
Support the design, implementation, and maintenance of Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) models to reduce over-privileged user access.
Perform system health checks, performance tuning, patching, version upgrades, and database maintenance across non-production and production SailPoint environments.
Ensure SailPoint configurations align with DoD/Federal cybersecurity standards (STIG compliance, NIST SP 800-53 controls) and support Authority to Operate (ATO) assessments.
Serve as the senior technical escalation point for complex provisioning errors, identity synchronization bugs, connector failures, and performance bottlenecks.
Required Qualifications
Must be able to obtain U.S. government security clearance
Bachelor's degree in computer science, Cybersecurity, Information Technology, Computer Engineering, or a related technical discipline.
Minimum of six (6) years of dedicated experience in Identity and Access Management (IAM), with at least four (4) years of hands-on engineering, configuration, and administration of SailPoint IdentityIQ or SailPoint Identity Security Cloud.
Active CompTIA Security+ CE certification (or higher DoD 8570/8140 IAT Level II compliant certification, such as CYSA+, GSEC, or CISSP).
Superior analytical, troubleshooting, and collaboration skills, with a proven history of managing complex technical deliverables independently.
Technical Expertise:
Advanced capability in developing Java, BeanShell, and XML components within the SailPoint IdentityIQ framework.
Demonstrated experience building RESTful APIs, SCIM interfaces, JDBC connectors, and custom application integrations.
Deep understanding of core identity protocols and directories: SAML 2.0, OAuth, OIDC, Active Directory, LDAP, and PKI/CAC/PIV integrations.
Solid working knowledge of relational database management systems (Oracle, SQL Server, PostgreSQL) and SQL query writing.
Direct experience implementing SailPoint solutions within Federal/DoD ICAM programs or Zero Trust Architecture (ZTA) environments.
Experience with cloud platforms (AWS, Microsoft Azure, Google Cloud Platform) and containerized application deployments.
Familiarity with DevSecOps, automated CI/CD deployment pipelines, and version control systems (Git).
Hands-on integration experience pairing SailPoint with Privileged Access Management (PAM) tools (e.g., BeyondTrust) or Identity Providers (e.g. Ping, Entra ID)
About Capgemini
Capgemini is a global leader in consulting, digital transformation, technology and engineering services. The company is headquartered in Paris, France and operates in over 50 countries. Capgemini provides a range of services including strategy and transformation, application services, technology services, and engineering services. The company serves clients in a variety of industries including automotive, consumer products, financial services, healthcare, and retail.