Role : IAM Operations Consultant (Ping & SailPoint)
Location: Plano, TX (5 days onsite)
Shift: Standard hours + on-call rotation
Core Responsibilities
Platform Management: Oversee day-to-day operations, availability, and performance for Ping Identity and SailPoint (IIQ/IdentityNow).
Ping Administration: Manage PingFederate, PingAccess, and PingID. Configure OIDC/SAML integrations, MFA policies, and adaptive access.
SailPoint Governance: Handle application onboarding, identity lifecycle (JML), access certifications, and SoD policy enforcement.
Incident & Problem Management: Lead root cause analysis (RCA), triage complex IAM incidents, and execute changes via CAB.
Automation & Optimization: Use APIs and scripting (PowerShell/Python/Java) to automate routine tasks and implement configuration-as-code.
Security & Compliance: Support SOX/PCI audits by providing evidence and ensuring least-privilege controls across all platforms.
Required Qualifications
Experience: 5 8 years in IAM operations; 3+ years specialized experience in both Ping and SailPoint.
Technical Depth: Strong knowledge of SAML 2.0, OIDC, OAuth 2.0, and certificate management.
Infrastructure: Proficiency in AD/LDAP, Linux/Windows admin, and networking (DNS, TLS, Load Balancers).
Development: Ability to write/debug BeanShell (for IIQ) and work with REST APIs.
Process: Deep understanding of ITIL processes and enterprise security best practices.
Preferred Skills
Certifications: Ping Identity or SailPoint professional certifications.
Cloud IAM: Experience with Azure AD/Entra ID, AWS IAM, or Google Cloud Platform IAM.
DevOps: Exposure to CI/CD pipelines and Git-based versioning for IAM configurations.
Integrations: Hands-on experience with Workday, ServiceNow, and SAP/Oracle connectors.
Tech Stack
SSO/MFA: PingFederate, PingAccess, PingDirectory, PingID.
IGA: SailPoint IdentityIQ, IdentityNow.
Tools: PowerShell, Python, Java, Splunk, ServiceNow, Git.