Role: Sailpoint Identity IQ Architect
Location: NYC NY (Hybrid)
Duration: 12 months
Working Hours: 37.5 HRS/week
We're looking for a talented SailPoint IIQ and ISC Developer/Administrator to join our team. You'll play a key role in developing, administering, and maintaining our identity and access management (IAM) solutions, ensuring secure and efficient access across our organization. Expertise in Okta and Citizen IAM initiatives is a strong plus.
What You'll Do:
- Design, implement, and maintain SailPoint IIQ and ISC solutions
- Develop and automate workflows, connectors, and application onboarding
- Administer and support Microsoft Entra ID (Azure AD), including Privileged Identity Management (PIM)
- Integrate IAM systems with cloud platforms such as AWS, Azure, or Google Cloud Platform
- Implement and manage Okta solutions, with a focus on Citizen IAM and external user identity needs
- Conduct code reviews to eliminate redundancies and optimize system logic
- Identify and address IAM vulnerabilities early in the development process
- Collaborate with IT stakeholders and business owners to mature Role-Based Access Control (RBAC) andapplication onboarding programs
- Manage and integrate APIs, privilege access management (PAM) tools, SailPoint Access History, SailPoint Access Modeling and database platforms
- Test, deploy, and recommend patches and upgrades for IAM systems
- Migration from IIQ to ISC for the upcoming project
1. SailPoint IdentityIQ Engineering & Development
- Develop and maintain BeanShell rules, custom workflows, lifecycle event logic, task definitions, and plugin modules.
- Engineer custom connectors, aggregation jobs, reconciliation logic, and provisioning adapters.
- Build scalable application onboarding frameworks, entitlement schemas, and role models.
- Implement and optimize certification campaigns, policy enforcement, SoD controls, and governance reporting.
- Extend IIQ using Java, REST APIs, SCIM, and custom UI components.
2. IAM Architecture & Solution Design
- Define and maintain end to end IAM architecture, including identity sources, directories, governance layers, and provisioning flows.
- Architect scalable identity lifecycle frameworks supporting joiner/mover/leaver automation, authoritative source alignment, and attribute driven access.
- Design integration patterns between SailPoint IIQ and ServiceNow, including:
- Access request workflows
- Automated ticket creation and closure
- Provisioning orchestration
- Incident and change management alignment
- Catalog item governance and approval routing
- Establish RBAC/ABAC frameworks, role mining strategies, and access modeling standards.
- Create architectural diagrams, data flow maps, and governance models for enterprise IAM programs.
- Evaluate modernization opportunities (e.g., SailPoint SaaS, passwordless, adaptive risk, ServiceNow IAM modules).
- Lead design reviews, threat modeling sessions, and IAM roadmap planning with cybersecurity leadership.
3. Integration & Directory Services
- Architect and implement integrations with Active Directory, LDAP, Azure AD/Entra ID, HR systems, cloud applications, and ServiceNow.
- Develop REST/SOAP integrations, SCIM connectors, and custom provisioning logic.
- Implement authentication and federation patterns using SAML, OAuth, OIDC, and MFA platforms.
- Ensure directory hygiene, identity data quality, and lifecycle accuracy across systems.
4. ServiceNow Integration & Workflow Engineering
- Design and maintain ServiceNow IAM workflows, including access request, approval routing, and fulfillment automation.
- Integrate SailPoint IIQ with ServiceNow for:
- Ticket based provisioning and deprovisioning
- Automated incident creation for provisioning failures
- Change management workflows tied to IAM operations
- Catalog item governance and entitlement mapping
- Collaborate with ServiceNow platform owners to ensure alignment between IAM processes and enterprise workflow standards.
- Optimize ServiceNow → SailPoint → downstream system orchestration for speed, accuracy, and auditability.
- Support migration or redesign efforts when ServiceNow is used as a front end for IAM services.
5. Security Engineering & Governance
- Apply Zero Trust, least privilege, RBAC/ABAC, and governance principles to all IAM designs.
- Engineer automated controls supporting SOX, HIPAA, ISO 27001, and NIST compliance.
- Conduct root cause analysis for provisioning failures, connector issues, workflow errors, and performance bottlenecks.
- Partner with security architects to align IAM architecture with enterprise cybersecurity strategy.
6. Operational Support & Platform Stability
- Support production IIQ environments, including break/fix, patching, upgrades, and performance tuning.
- Maintain detailed technical documentation, architectural diagrams, and operational runbooks.
- Collaborate with HRIS, infrastructure, ServiceNow, and application teams to resolve identity issues and improve lifecycle reliability.
Additional Skills and Information:
- 5–9 years in IAM engineering, with 5–10+ years of SailPoint IdentityIQ development.
- Strong proficiency in Java, BeanShell, XML, JSON, SQL, and REST API development.
- Deep understanding of IIQ object model, connector frameworks, workflow engine, and plugin architecture.
- Hands on experience architecting integrations between SailPoint IIQ and ServiceNow.
- Strong knowledge of directory services, identity stores, and authentication protocols.
- Security & Governance
- Expertise in identity governance concepts, RBAC/ABAC, SoD, and policy enforcement.
- Familiarity with compliance frameworks (NIST)