Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
New York, NY, United States
Posted
Yesterday
SOAPSQLAWSMFAOAuthSAMLActive DirectoryAzureGoogle CloudHIPAAJavaLDAPRESTZero Trust
Job Description
Cybersecurity IAM Engineer – SailPoint IdentityIQ (IIQ)
Client: MTA
Location: 2 Broadway, MTA Headquarters – Hybrid
Experience: 7–9+ Years
Duration: Contrac
Important Notes
- Hybrid position: Onsite at MTA Headquarters with a maximum of 2 remote days per week.
- Final interview round will be in person.
- Strong hands-on SailPoint IdentityIQ (IIQ) experience is required.
- IIQ to Identity Security Cloud (ISC) migration experience is important for the upcoming project.
- Experience with Okta and Citizen IAM is a strong plus.
Job Summary
We are looking for a Cybersecurity IAM Engineer / SailPoint IIQ and ISC Developer/Architect to design, develop, and modernize enterprise identity governance solutions across on-prem and hybrid cloud environments.
The role will focus on SailPoint development, IAM architecture, identity lifecycle automation, application onboarding, integrations, governance, and ServiceNow workflow orchestration.
Responsibilities
SailPoint IIQ Development
- Develop and maintain BeanShell rules, workflows, lifecycle events, tasks, and plugins.
- Build custom connectors, aggregation jobs, reconciliation logic, and provisioning adapters.
- Develop application onboarding frameworks, entitlement schemas, and role models.
- Implement certification campaigns, SoD controls, policy enforcement, and governance reporting.
- Extend IIQ using Java, REST APIs, SCIM, and custom UI components.
IAM Architecture & Design
- Design end-to-end IAM architecture and identity lifecycle solutions.
- Support Joiner/Mover/Leaver automation and attribute-based access.
- Design RBAC/ABAC frameworks, role mining, and access modeling.
- Create architecture diagrams, data flows, and IAM governance models.
- Support IAM modernization initiatives and roadmap planning.
Integration & Directory Services
- Integrate SailPoint with Active Directory, LDAP, Microsoft Entra ID/Azure AD, HR systems, cloud applications, and ServiceNow.
- Develop REST/SOAP integrations, SCIM connectors, and custom provisioning solutions.
- Work with SAML, OAuth, OIDC, and MFA authentication/federation technologies.
- Ensure identity data quality and accurate lifecycle management.
ServiceNow Integration
- Design SailPoint–ServiceNow workflows for access requests, approvals, provisioning, and deprovisioning.
- Automate ticket creation and closure.
- Support incident and change management workflows.
- Manage catalog items, entitlement mapping, and approval routing.
Security & Governance
- Apply Zero Trust, least privilege, RBAC/ABAC, and IAM governance principles.
- Support controls aligned with SOX, HIPAA, ISO 27001, and NIST.
- Troubleshoot provisioning failures, connector issues, workflow errors, and performance problems.
- Perform root cause analysis and support cybersecurity initiatives.
Production Support
- Support production SailPoint environments, including break/fix, upgrades, patching, and performance tuning.
- Maintain technical documentation, architecture diagrams, and operational runbooks.
- Work with HRIS, infrastructure, ServiceNow, and application teams to resolve IAM issues.
Must Have / Required Skills
- 7–9+ years of IAM engineering experience.
- Strong SailPoint IdentityIQ (IIQ) development experience.
- Strong experience with Java, BeanShell, XML, JSON, SQL, and REST APIs.
- Deep knowledge of the IIQ object model, connector framework, workflow engine, and plugin architecture.
- Hands-on experience integrating SailPoint IIQ with ServiceNow.
- Experience with Active Directory, LDAP, Azure AD/Entra ID, identity stores, and directory services.
- Strong understanding of RBAC, ABAC, SoD, identity governance, and policy enforcement.
- Experience with identity lifecycle management and application onboarding.
- Strong knowledge of authentication protocols including SAML, OAuth, OIDC, and MFA.
- Experience with REST/SOAP and SCIM integrations.
- Familiarity with NIST and security/compliance frameworks.
Preferred / Nice to Have
- SailPoint Identity Security Cloud (ISC) experience.
- Hands-on IIQ → ISC migration experience.
- Okta experience.
- Citizen IAM / external identity experience.
- Experience with PAM/PIM solutions.
- Experience with AWS, Azure, or Google Cloud Platform IAM integrations.
- Experience with SailPoint Access History and Access Modeling.
- Experience with ServiceNow IAM modules.
- Experience with passwordless/adaptive risk technologies.
- Strong understanding of enterprise Zero Trust architecture.
Similar jobs
- BA
Information Assurance Systems Administrator
NewBOOZ, ALLEN & HAMILTON, INC.
Leavenworth, KS🇺🇸$61.9k - $141k/yrHybridYesterdayTechnology - BA
AI Solution Architect
NewBOOZ, ALLEN & HAMILTON, INC.
Hanscom Air Force Base, MA🇺🇸$112.9k - $257k/yrOn-siteYesterdayAWSKubernetesLLMTechnology - BA
Model-Based Systems Engineer
NewBOOZ, ALLEN & HAMILTON, INC.
Chicago, IL🇺🇸$99k - $225k/yrOn-siteYesterdayMATLABTechnology - KE
Technical Writer
NewKELVION
Catoosa, OK🇺🇸HybridYesterdayComplianceContinuous ImprovementMicrosoft OfficeTechnology - BW
Network Voice Engineer
NewBWXT
Lynchburg, VA🇺🇸$65k - $103k/yrOn-siteYesterdayTechnology - GM
Technical Writer - GM Defense
NewGeneral Motors
Warren, MI🇺🇸HybridYesterdayRoboticsCADHeavy EquipmentTechnology