Haystack
← Back to Jobs
Technology
AC

IAM Engineer (Salipoint IdentityIQ and Security Cloud)

ACS Consultancy Services, Inc.Buffalo, NY🇺🇸United StatesPosted 1 Sept 2026

Why This Role Stands Out

Advance your career as an IAM Engineer by designing and implementing cutting-edge SailPoint solutions within a reputable firm, offering a hybrid work model for excellent flexibility. You'll thrive in this role if you possess strong technical acumen in IdentityIQ and Security Cloud, enjoy complex problem-solving, and are eager to contribute to robust identity governance frameworks. Don't miss this opportunity to significantly impact a dynamic technology environment.

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Buffalo, NY, United States
Posted
1 week ago
SOAPSQLAWSMFAOAuthSAMLActive DirectoryAzureGoogle CloudHIPAAJavaLDAPRESTZero Trust

Job Description

Job Title: IAM Engineer (Salipoint IdentityIQ and Security Cloud)

Location: BROADWAY, NY (Hybrid)

We are currently seeking candidates who meet the following qualifications:

Key Responsibilities
  • Design, implement, maintain, and administer SailPoint IdentityIQ and Identity Security Cloud solutions.
  • Develop and maintain BeanShell rules, custom workflows, lifecycle events, task definitions, and plugin modules.
  • Engineer custom connectors, aggregation jobs, reconciliation logic, and provisioning adapters.
  • Develop and automate IAM workflows, connectors, application onboarding, and provisioning processes.
  • Build scalable application onboarding frameworks, entitlement schemas, and role models.
  • Implement and optimize certification campaigns, policy enforcement, SoD controls, and governance reporting.
  • Extend SailPoint IdentityIQ using Java, REST APIs, SCIM, and custom UI components.
  • Support and execute migration from SailPoint IdentityIQ to Identity Security Cloud.
  • Define and maintain end-to-end IAM architecture across identity sources, directories, governance layers, and provisioning flows.
  • Architect identity lifecycle frameworks supporting joiner, mover, and leaver automation.
  • Establish RBAC/ABAC frameworks, role mining strategies, and access modeling standards.
  • Create architectural diagrams, data flow maps, and governance models for enterprise IAM programs.
  • Design and maintain integrations between SailPoint and ServiceNow, including access requests, approval routing, provisioning orchestration, incident management, and change management.
  • Integrate IAM platforms with Active Directory, LDAP, Microsoft Entra ID (Azure AD), HR systems, cloud applications, and ServiceNow.
  • Develop REST/SOAP integrations, SCIM connectors, and custom provisioning logic.
  • Implement authentication and federation patterns using SAML, OAuth, OIDC, and MFA platforms.
  • Administer Microsoft Entra ID, including Privileged Identity Management (PIM).
  • Integrate IAM solutions with AWS, Azure, and Google Cloud Platform cloud environments.
  • Implement and manage Okta solutions, including Citizen IAM and external user identity requirements.
  • Design and maintain ServiceNow IAM workflows for access requests, approval routing, and fulfillment automation.
  • Integrate SailPoint with ServiceNow for ticket-based provisioning and deprovisioning, automated incident creation, change management, catalog governance, and entitlement mapping.
  • Optimize ServiceNow SailPoint downstream system orchestration for speed, accuracy, and auditability.
  • Apply Zero Trust, least privilege, RBAC/ABAC, and identity governance principles to IAM designs.
  • Engineer automated security controls supporting SOX, HIPAA, ISO 27001, and NIST compliance.
  • Conduct root cause analysis for provisioning failures, connector issues, workflow errors, and performance bottlenecks.
  • Conduct code reviews to eliminate redundancies and optimize system logic.
  • Identify and address IAM vulnerabilities early in the development lifecycle.
  • Collaborate with IT stakeholders and business owners to mature RBAC and application onboarding programs.
  • Manage and integrate APIs, PAM tools, SailPoint Access History, SailPoint Access Modeling, and database platforms.
  • Test, deploy, and recommend patches and upgrades for IAM systems.
  • Support production SailPoint environments, including break/fix, patching, upgrades, and performance tuning.
  • Maintain technical documentation, architectural diagrams, and operational runbooks.
  • Collaborate with HRIS, infrastructure, ServiceNow, security, and application teams to resolve identity issues and improve lifecycle reliability.
  • Lead design reviews, threat modeling sessions, and IAM roadmap planning with cybersecurity leadership.
  • Evaluate IAM modernization opportunities, including SailPoint SaaS, passwordless authentication, adaptive risk, and ServiceNow IAM capabilities.
Required Qualifications
  • Strong experience in IAM engineering, development, administration, and architecture.
  • Extensive experience developing and administering SailPoint IdentityIQ.
  • Hands-on experience with SailPoint Identity Security Cloud.
  • Strong knowledge of the SailPoint IIQ object model, connector framework, workflow engine, and plugin architecture.
  • Strong proficiency in Java, BeanShell, XML, JSON, SQL, and REST APIs.
  • Experience developing custom SailPoint workflows, rules, connectors, lifecycle events, aggregation jobs, and provisioning logic.
  • Experience with SailPoint application onboarding, entitlement management, role models, certification campaigns, SoD, and policy enforcement.
  • Experience architecting and implementing SailPoint IIQ and ServiceNow integrations.
  • Strong knowledge of Active Directory, LDAP, Microsoft Entra ID/Azure AD, and identity stores.
  • Experience with IAM integrations involving HR systems, cloud applications, directories, and enterprise platforms.
  • Strong understanding of authentication and federation protocols, including SAML, OAuth, OIDC, SCIM, and MFA.
  • Experience with AWS, Azure, or Google Cloud Platform cloud environments.
  • Experience administering Microsoft Entra ID and Privileged Identity Management (PIM).
  • Experience with Okta, including Citizen IAM and external identity requirements.
  • Strong understanding of RBAC, ABAC, SoD, least privilege, Zero Trust, and identity governance.
  • Experience with ServiceNow IAM workflows, access requests, approval routing, provisioning, incident management, and change management.
  • Experience troubleshooting provisioning failures, connector issues, workflow errors, and IAM performance issues.
  • Knowledge of security and compliance frameworks, including NIST.
Preferred Qualifications
  • Experience migrating SailPoint IdentityIQ implementations to SailPoint Identity Security Cloud.
  • Experience with SailPoint Access History and Access Modeling.
  • Experience with Privileged Access Management (PAM) platforms.
  • Experience with ServiceNow catalog item governance and entitlement mapping.
  • Experience designing enterprise IAM architecture and governance models.
  • Experience with passwordless authentication and adaptive-risk solutions.
  • Experience supporting SOX, HIPAA, and ISO 27001 compliance requirements.
  • Experience conducting IAM threat modeling and security architecture reviews.
  • Strong experience working across hybrid cloud and on-premises environments.


    If you meet these qualifications, please submit your application via the link provided on LinkedIn.
    Kindly do not call the general line to submit your application.

Similar jobs