Job SummaryDo you enjoy designing identity governance solutions that strengthen security, simplify access, and help the business move faster?
Join our Identity and Access Management team, which is responsible for the enterprise identity services that enable secure and reliable access across MathWorks. Our team supports a broad portfolio that includes identity lifecycle and governance, directory services, authentication and access management, privileged access, non-human and workload identities, and security awareness capabilities. We work closely with IT, Security, Compliance, and Business teams, and application owners to deliver identity services that are secure, scalable, automated, and aligned with business needs.
We are looking for a Senior SailPoint IAM engineer to help lead the implementation, and ongoing improvement of our SailPoint platform as a key part of our IAM portfolio. This role will help define how identities, accounts, entitlements, roles, access requests, certifications, and lifecycle events are governed across the enterprise. The ideal candidate will combine deep SailPoint expertise with strong IAM skills and a DevOps mindset for building reliable, repeatable, and well-managed identity services.
Responsibilities- Design and evolve SailPoint Identity Security Cloud (ISC) solutions supporting identity lifecycle management, access requests, provisioning, certification, and governance workflows.
- Define scalable application onboarding and integration patterns for ISC using APIs, SCIM, and modern identity standards across enterprise and cloud ecosystems.
- Partner with business, application, security, and compliance stakeholders to onboard applications and establish consistent, enterprise-wide governance models.
- Architect and implement access control frameworks, including birthright access, RBAC, ABAC, segregation of duties, and least privilege principles.
- Apply DevOps and engineering practices to ISC platform delivery, including CI/CD pipelines, source control, automated validation, and governed release processes.
- Improve platform reliability and scalability through automation, monitoring, logging, configuration management, and structured environment separation.
- Provide technical leadership through troubleshooting complex identity flows, supporting audit and compliance needs, and mentoring IAM team members on secure, sustainable IAM design practices.
Minimum Qualifications- A bachelor's degree and 6 years of professional work experience (or a master's degree and 3 years of professional work experience, or a PhD degree, or equivalent experience) is required.
Additional QualificationsA successful candidate for this role will have a combination of some or all the following skills/experience:
- 5+ years of experience in enterprise Identity and Access Management, including Identity Governance and Administration.
- Deep expertise in SailPoint Identity Security Cloud (ISC), including identity modeling, source onboarding, access requests, provisioning, certifications, policies, workflows, and lifecycle design.
- Proven experience leading IAM solution architecture and SailPoint ISC implementations in large, complex enterprise environments.
- Strong ability to design end-to-end identity architectures covering lifecycle management, governance, provisioning, and integration patterns.
- Experience integrating ISC with enterprise ecosystems, including HR systems, directories, ITSM platforms, and business applications using APIs and modern standards.
- Expertise designing and implementing access control models such as RBAC, ABAC, birthright access, segregation of duties, and least privilege.
- Strong experience applying DevOps and engineering practices to IAM, including CI/CD pipelines, source control, automated validation, and governed deployment models.
- Deep understanding of identity data management, correlation, entitlement modeling, and policy enforcement at enterprise scale.
- Strong technical capability in IAM automation, API-driven integration, and extensibility using scripting and modern integration patterns, with working knowledge of federation and provisioning standards including SAML, OAuth, OIDC, SCIM, LDAP, SQL, ReST Apis, and Active Directory.