Identity Governance and Administration (IGA) Engineer

Wood River Federal

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Computer Engineering, or a related field.
  • 6+ years in Identity and Access Management (IAM), with 4+ years hands-on with SailPoint IdentityIQ or Identity Security Cloud.
  • Active U.S. Government Security Clearance (Secret required).
  • CompTIA Security+ CE certification or higher DoD 8570/8140 IAT Level II compliant certification (e.g., CYSA+, GSEC, or CISSP).
  • Strong analytical, troubleshooting, and collaboration skills with experience managing complex technical projects.

Responsibilities

  • Design, configure, deploy, and maintain SailPoint IdentityIQ or Identity Security Cloud.
  • Integrate various enterprise applications and cloud services with SailPoint using web services and custom APIs.
  • Automate provisioning and de-provisioning processes during Joiner, Mover, and Leaver events.
  • Manage access certification campaigns and enforce Separation of Duties (SoD) policies.
  • Support the implementation of RBAC and ABAC models to manage user access.
  • Perform system health checks, tuning, patching, and upgrades for SailPoint environments.
  • Serve as an escalation point for complex errors and performance issues.

Benefits

  • Work in a critical role fortifying enterprise cybersecurity.
  • Engagement with cutting-edge identity management technologies and practices.
  • Opportunity for cross-departmental collaboration with security architects and application owners.
  • Contributions to compliance with federal mandates and Zero Trust initiatives.
  • Potential for professional development through continued learning in a high-security environment.
Full Job Description
Position Overview

The Identity Governance and Administration (IGA) Engineer is responsible for designing, deploying, configuring, and supporting enterprise-wide Identity Governance and Administration (IGA) solutions using the SailPoint platform (IdentityIQ and/or Identity Security Cloud). This role plays a critical part in strengthening enterprise cybersecurity postures, automating the identity lifecycle (Joiner/Mover/Leaver workflows), enforcing Role-Based Access Control (RBAC), and aligning identity operations with federal mandates and Zero Trust Architecture (ZTA) initiatives. Working closely with security architects, systems administrators, and application owners, the SailPoint Engineer ensures seamless integration, compliance automation, and robust operational resilience.

Key Responsibilities:
• Design, configure, deploy, and maintain SailPoint IdentityIQ (IIQ) or SailPoint Identity Security Cloud platforms. Develop custom workflows, rules, forms, policies, and Beanshell/Java scripts.
• Integrate enterprise applications, databases, directories (Active Directory, Entra ID, LDAP), and cloud services with SailPoint using out-of-the-box and custom web services/REST APIs/SCIM connectors.
• Build and maintain automated provisioning and de-provisioning processes for Joiner, Mover, and Leaver (JML) events across hybrid infrastructures.
• Configure and manage periodic access certification campaigns, entitlement catalog structures, and Separation of Duties (SoD) enforcement policies.
• Support the design, implementation, and maintenance of Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) models to reduce over-privileged user access.
• Perform system health checks, performance tuning, patching, version upgrades, and database maintenance across non-production and production SailPoint environments.
• Ensure SailPoint configurations align with DoD/Federal cybersecurity standards (STIG compliance, NIST SP 800-53 controls) and support Authority to Operate (ATO) assessments.
• Serve as the senior technical escalation point for complex provisioning errors, identity synchronization bugs, connector failures, and performance bottlenecks.

Required Qualifications:
• Bachelor's degree in computer science, Cybersecurity, Information Technology, Computer Engineering, or a related technical discipline.
• Minimum of six (6) years of dedicated experience in Identity and Access Management (IAM), with at least four (4) years of hands-on engineering, configuration, and administration of SailPoint IdentityIQ or SailPoint Identity Security Cloud.
• Must possess an active U.S. Government Security Clearance (Secret required).
• Active CompTIA Security+ CE certification (or higher DoD 8570/8140 IAT Level II compliant certification, such as CYSA+, GSEC, or CISSP).
• Superior analytical, troubleshooting, and collaboration skills, with a proven history of managing complex technical deliverables independently.

Technical Expertise:
• Advanced capability in developing Java, BeanShell, and XML components within the SailPoint IdentityIQ framework.
• Demonstrated experience building RESTful APIs, SCIM interfaces, JDBC connectors, and custom application integrations.
• Deep understanding of core identity protocols and directories: SAML 2.0, OAuth, OIDC, Active Directory, LDAP, and PKI/CAC/PIV integrations.
• Solid working knowledge of relational database management systems (Oracle, SQL Server, PostgreSQL) and SQL query writing.
• Direct experience implementing SailPoint solutions within Federal/DoD ICAM programs or Zero Trust Architecture (ZTA) environments.
• Experience with cloud platforms (AWS, Microsoft Azure, Google Cloud Platform) and containerized application deployments.
• Familiarity with DevSecOps, automated CI/CD deployment pipelines, and version control systems (Git).
• Hands-on integration experience pairing SailPoint with Privileged Access Management (PAM) tools (e.g., BeyondTrust) or Identity Providers (e.g. Ping, Entra ID)

Similar Jobs

More Jobs at Wood River Federal

More Information Technology Jobs

Find similar Identity Governance and Administration (IGA) Engineer jobs: