← Back to jobs

FUSTIS Logo
Cybersecurity IAM Engineer

FUSTIS

 

New York, NY, USA

Posted On: Just posted
Experience: 9+ years
Availability: Hybrid
Openings: 1
Category: IAM Engineer
Tenure: Contract - Corp-to-Corp
Related Jobs

No related jobs found

Description

• Design, implement, and maintain SailPoint IIQ and ISC solutions
• Develop and automate workflows, connectors, and application onboarding
• Administer and support Microsoft Entra ID (Azure AD), including Privileged Identity Management (PIM)
• Integrate IAM systems with cloud platforms such as AWS, Azure, or GCP
• Implement and manage Okta solutions, with a focus on Citizen IAM and external user identity needs
• Conduct code reviews to eliminate redundancies and optimize system logic
• Identify and address IAM vulnerabilities early in the development process
• Collaborate with IT stakeholders and business owners to mature Role-Based Access Control (RBAC) andapplication onboarding programs
• Manage and integrate APIs, privilege access management (PAM) tools, SailPoint Access History, SailPoint Access Modeling and database platforms
• Test, deploy, and recommend patches and upgrades for IAM systems
• Migration from IIQ to ISC for the upcoming project

 

  1. SailPoint IdentityIQ Engineering & Development
    • Develop and maintain BeanShell rules, custom workflows, lifecycle event logic, task definitions, and plugin modules.
    • Engineer custom connectors, aggregation jobs, reconciliation logic, and provisioning adapters.
    • Build scalable application onboarding frameworks, entitlement schemas, and role models.
    • Implement and optimize certification campaigns, policy enforcement, SoD controls, and governance reporting.
    • Extend IIQ using Java, REST APIs, SCIM, and custom UI components.
    2. IAM Architecture & Solution Design
    • Define and maintain end to end IAM architecture, including identity sources, directories, governance layers, and provisioning flows.
    • Architect scalable identity lifecycle frameworks supporting joiner/mover/leaver automation, authoritative source alignment, and attribute driven access.
    • Design integration patterns between SailPoint IIQ and ServiceNow, including:
    o Access request workflows
    o Automated ticket creation and closure
    o Provisioning orchestration
    o Incident and change management alignment
    o Catalog item governance and approval routing
    • Establish RBAC/ABAC frameworks, role mining strategies, and access modeling standards.
    • Create architectural diagrams, data flow maps, and governance models for enterprise IAM programs.
    • Evaluate modernization opportunities (e.g., SailPoint SaaS, passwordless, adaptive risk, ServiceNow IAM modules).
    • Lead design reviews, threat modeling sessions, and IAM roadmap planning with cybersecurity leadership.
    3. Integration & Directory Services
    • Architect and implement integrations with Active Directory, LDAP, Azure AD/Entra ID, HR systems, cloud applications, and ServiceNow.
    • Develop REST/SOAP integrations, SCIM connectors, and custom provisioning logic.
    • Implement authentication and federation patterns using SAML, OAuth, OIDC, and MFA platforms.
    • Ensure directory hygiene, identity data quality, and lifecycle accuracy across systems.
    4. ServiceNow Integration & Workflow Engineering
    • Design and maintain ServiceNow IAM workflows, including access request, approval routing, and fulfillment automation.
    • Integrate SailPoint IIQ with ServiceNow for:
    o Ticket based provisioning and deprovisioning
    o Automated incident creation for provisioning failures
    o Change management workflows tied to IAM operations
    o Catalog item governance and entitlement mapping
    • Collaborate with ServiceNow platform owners to ensure alignment between IAM processes and enterprise workflow standards.
    • Optimize ServiceNow → SailPoint → downstream system orchestration for speed, accuracy, and auditability.
    • Support migration or redesign efforts when ServiceNow is used as a front end for IAM services.
    5. Security Engineering & Governance
    • Apply Zero Trust, least privilege, RBAC/ABAC, and governance principles to all IAM designs.
    • Engineer automated controls supporting SOX, HIPAA, ISO 27001, and NIST compliance.
    • Conduct root cause analysis for provisioning failures, connector issues, workflow errors, and performance bottlenecks.
    • Partner with security architects to align IAM architecture with enterprise cybersecurity strategy.
    6. Operational Support & Platform Stability
    • Support production IIQ environments, including break/fix, patching, upgrades, and performance tuning.
    • Maintain detailed technical documentation, architectural diagrams, and operational runbooks.
    • Collaborate with HRIS, infrastructure, ServiceNow, and application teams to resolve identity issues and improve lifecycle reliability.

 

 

Technical Expertise
• 5–9 years in IAM engineering, with 5–10+ years of SailPoint IdentityIQ development.
• Strong proficiency in Java, BeanShell, XML, JSON, SQL, and REST API development.
• Deep understanding of IIQ object model, connector frameworks, workflow engine, and plugin architecture.
• Hands on experience architecting integrations between SailPoint IIQ and ServiceNow.
• Strong knowledge of directory services, identity stores, and authentication protocols.
Security & Governance
• Expertise in identity governance concepts, RBAC/ABAC, SoD, and policy enforcement.
• Familiarity with compliance frameworks (NIST)

 


 

Education

Bachelor's degree

Related Jobs

No related jobs found

← Back to jobs