Haystack
← Back to Jobs
Remote
Administrative
CD

SailPoint Identity Security Cloud Consultant

Cloud Destinations LLCLos Angeles, CA🇺🇸United StatesPosted Sep 30, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
Los Angeles, CA, United States
Posted
20 hours ago

Job Description

SailPoint ISC, Active Directory, Microsoft Entra ID, and Exchange Contractor
Location: Los Angeles, CA area – Hybrid schedule with onsite work Tuesday through Thursday and remote work Monday and Friday.
Duration: Contract 12+ Months, with potential for extension.
Overview:
The organization is seeking a qualified contractor to provide hybrid operational support, system integration engineering, and automated workflow optimization. This role will support and improve the identity and messaging ecosystem across the following core platforms:
  • SailPoint Identity Security Cloud (ISC) and NERM
  • Active Directory (AD) On-Premises
  • Azure Active Directory (Azure AD / Microsoft Entra ID)
  • Microsoft Exchange Online / Exchange Server Hybrid Messaging
Scope of Work:
The contractor will focus on complex implementation work, onboarding new platform modules, improving integration workflows, and performing root-cause analysis of systemic issues across identity, directory, and messaging systems. The role is intended to support long-term stabilization and automation rather than high-volume transactional ticket closure.
Key Responsibilities:

On-Premises Active Directory (AD) Operational Tasks

  • Health & Directory Maintenance: Monitor, troubleshoot, and remediate health issues within the on-premises AD environment related to object corruption, duplication, or sync latencies affecting downstream IAM tools.
  • Organizational Unit (OU) & Object Management: Restructure, cleanup, and standardize OU architecture, managed service accounts (MSAs), and security groups to facilitate accurate automated provisioning.
  • Group Policy Object (GPO) Alignment: Review and adjust GPOs impacting user provisioning, login scripts, and local profile creation to eliminate conflicts with SailPoint-driven access models.
  • Nested Group Rationalization: Audit and remediate highly nested security groups causing token bloat or unmapped access privileges during automated SailPoint entitlement aggregations.
  • Sid-History and Schema Attribute Audits: Remediate legacy security identifier (SID) histories and validate schema extensions required for advanced attribute matching across hybrid infrastructures.
Azure AD Direct Connector Deployment to SailPoint ISC
  • Architect, configure, and deploy the native SailPoint Azure AD direct connector to replace or augment legacy synchronization pathways.
  • Configure secure OAuth 2.0 API integrations via Microsoft Graph API.
  • Establish data aggregation schedules, attribute mappings, and account correlation rules to ensure zero downtime.
SailPoint ISC

Microsoft Exchange Online / Hybrid Messaging Operational Tasks

Qualifications:
  • Experience with SailPoint (or any other Identity Governance and Administration solution) and Microsoft Entra.
  • Experience managing Joiner-Mover-Leaver (JML) processes.
  • Experience troubleshooting provisioning and aggregation failures.
  • Strong understanding of identity lifecycle management and security frameworks.
  • Familiarity with hybrid Exchange environments and Office 365 services.
  • Deep operational expertise with Microsoft Active Directory Services (Forest/Domain architecture, GPO application, trust relationships) and Azure AD/Microsoft Entra ID schemas.
  • Hands-on experience administering Microsoft Exchange Online and hybrid Exchange environments, including mailbox management, distribution groups, mail flow, transport rules, delegation, retention, archive, and PowerShell automation.
  • Proven implementation history with SailPoint Identity Security Cloud (ISC) and NERM.
  • Strong capabilities in scripting languages (PowerShell, JavaScript, or BeanShell) used for building custom enterprise integration paths.
  • Prior work with public sector, regulated, or large-scale enterprise IT operations is preferred.
  • Vendor certification in AD, AAD, SailPoint, Exchange is highly preferred.

Similar jobs