IGA Engineer (Sailpoint) Journeyman jobs in United States
cer-icon
Apply on Employer Site
company-logo

Kentro · 23 hours ago

IGA Engineer (Sailpoint) Journeyman

Kentro is a dynamic community committed to innovation and professional growth. They are hiring an IGA Engineer to implement and manage SailPoint for identity governance, ensuring secure access to critical data in a Zero Trust environment.

Information Technology & Services
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

SailPoint Architecture & Configuration: Lead the design, deployment, and ongoing management of SailPoint IdentityNow (or IIQ) to automate the full identity lifecycle (Joiner, Mover, Leaver) across hybrid and on-premises environments
ABAC Attribute Management: Define and manage the schema for "Trust Attributes" (e.g., Clearance, COI, Project Codes) within SailPoint, ensuring they align with the NIST 8112 metadata standard for consumption by policy decision points
Air-Gapped Identity Operations: Manage the offline instance of SailPoint on the Top-Secret network, developing the workflows to import "Attribute Manifests" and ensure that identity data remains synchronized with the low-side source of truth
Access Certification: Configure and execute automated access certification campaigns for critical data repositories and privileged roles, ensuring compliance with DoD audit requirements
Role Modeling: Work with mission owners to define Technical Roles and Business Roles within SailPoint, replacing broad, static Active Directory groups with granular, policy-driven access roles

Qualification

SailPointIdentity Lifecycle ManagementActive DirectoryAttribute-Based Access ControlGovernance PrinciplesIntegration ProtocolsCompTIA Security+ CESailPoint Certified EngineerCertified IdentityAccess ManagerCISA

Required

Extensive (5+ years) hands-on experience designing, implementing, and administering SailPoint (IdentityNow or IdentityIQ) in a large enterprise environment
Deep understanding of the Joiner-Mover-Leaver (JML) process and experience automating provisioning/deprovisioning workflows connected to HR systems and Active Directory
Strong knowledge of Active Directory, LDAP, and Azure Active Directory (Entra ID) structures and management
Proven experience with Role-Based Access Control (RBAC) modeling, Separation of Duties (SoD) policy creation, and access certification campaigns
BA/BS or MA/MS in a relevant field
3-10 years in a relevant field
CompTIA Security+ CE (or higher) to meet DoD 8570 IAT Level II requirements
Active Top-Secret clearance with SCI eligibility

Preferred

Experience implementing Attribute-Based Access Control (ABAC) strategies
Familiarity with DoD Identity, Credential, and Access Management (ICAM) reference designs
Knowledge of integration protocols such as REST, SCIM, and SOAP
Experience supporting USSOCOM or other DoD agencies
SailPoint Certified IdentityNow Engineer or SailPoint Certified IdentityIQ Engineer
Certified Identity and Access Manager (CIAM) or CISA

Benefits

Paid time off
Healthcare benefits
Supplemental benefits
401k including an employer match
Discount perks
Rewards
Education reimbursement for certifications, degrees, or professional development

Company

Kentro

twitter
company-logo
IT Concepts has transformed into Kentro - your center for innovation, excellence, and growth.

Funding

Current Stage
Late Stage
Company data provided by crunchbase