IAM Operations Consultant (Ping & SailPoint)
Location: Plano, TX (5 days onsite)
Shift: Standard hours + on-call rotation Core
Responsibilities Platform Management: Oversee day-to-day operations, availability, and performance for Ping Identity and SailPoint (IIQ/IdentityNow). Ping Administration: Manage PingFederate, PingAccess, and PingID. Configure OIDC/SAML integrations, MFA policies, and adaptive access. SailPoint Governance: Handle application onboarding, identity lifecycle (JML), access certifications, and SoD policy enforcement. Incident & Problem Management: Lead root cause analysis (RCA), triage complex IAM incidents, and execute changes via CAB. Automation & Optimization: Use APIs and scripting (PowerShell/Python/Java) to automate routine tasks and implement configuration-as-code. Security & Compliance: Support SOX/PCI audits by providing evidence and ensuring least-privilege controls across all platforms. Required Qualifications Technical Depth: Strong knowledge of SAML 2.0, OIDC, OAuth 2.0, and certificate management. Infrastructure: Proficiency in AD/LDAP, Linux/Windows admin, and networking (DNS, TLS, Load Balancers). Development: Ability to write/debug BeanShell (for IIQ) and work with REST APIs. Process: Deep understanding of ITIL processes and enterprise security best practices. Preferred Skills Certifications: Ping Identity or SailPoint professional certifications. Cloud IAM: Experience with Azure AD/Entra ID, AWS IAM, or Google Cloud Platform IAM. DevOps: Exposure to CI/CD pipelines and Git-based versioning for IAM configurations. Integrations: Hands-on experience with Workday, ServiceNow, and SAP/Oracle connectors. Tech Stack SSO/MFA: PingFederate, PingAccess, PingDirectory, PingID. IGA: SailPoint IdentityIQ, IdentityNow. Tools: PowerShell, Python, Java, Splunk, ServiceNow, Git.