Principal Engineer, Cybersecurity, IGA - Remote
Preference will be given to candidates residing in the Eastern or Central time zones.
As an IGA Principal Engineer, you will build and operate enterprise identity governance, authentication, and authorization services that protect access across the organization. You will partner with senior business, application, and infrastructure stakeholders to translate requirements into scalable identity architecture, standards, and controls.
WHAT YOU WILL DO
Technical Responsibilities:
-
Build, configure, and operate enterprise IGA platforms, including SailPoint, Saviynt, or Microsoft Entra ID Governance, with supporting directory and authentication services.
-
Engineer identity lifecycle workflows for joiners, movers, and leavers, including automated provisioning and deprovisioning.
-
Implement and maintain access requests, approval workflows, access certification and recertification campaigns, RBAC models, role mining, and segregation-of-duties rules.
-
Configure authoritative sources, identity reconciliation, and identity data quality remediation.
-
Implement SSO, MFA, federation, and risk-based authentication using SAML, OAuth, OpenID Connect, and SCIM.
-
Develop PowerShell, Microsoft Graph, REST API, and SCIM automations and integrations to onboard applications to IGA services.
-
Produce identity reporting, integration governance, and audit evidence for access-related controls.
-
Troubleshoot IGA, provisioning, and directory issues; maintain documentation; and execute IAM controls supporting SOX, HIPAA, ISO 27001, and NIST CSF compliance.
Knowledge and Capabilities:
-
Gather requirements from senior business, application, and infrastructure stakeholders and provide scope and architecture consultation.
-
Define, communicate, and embed enterprise identity governance standards, patterns, and controls with senior stakeholders.
-
Analyze complex identity issues, communicate technical concepts clearly, and maintain precise configuration and governance practices.
WHAT YOU NEED
Required Qualifications
-
Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related discipline, or equivalent practical experience.
-
Minimum 8 years of experience in IT or cybersecurity.
-
Minimum 5 years of hands-on experience engineering and operating IGA or IAM environments.
-
Experience with SailPoint, Saviynt, or Microsoft Entra ID Governance, plus Active Directory and Microsoft Entra ID.
-
Experience with identity lifecycle management, provisioning and deprovisioning, access certification, RBAC, and segregation-of-duties enforcement.
-
Working knowledge of SAML, OAuth, OpenID Connect, and SCIM.
-
Experience with PowerShell, Microsoft Graph, or REST APIs.
Preferred Qualifications
-
SailPoint IdentityIQ or IdentityNow Engineer, Saviynt, Microsoft Certified: Identity and Access Administrator Associate (SC-300), or CISSP certification.
United States of America Pay Ranges:
- USN: $135,600 - $225,900 USD Annual
- US5: $142,400 - $237,200 USD Annual
- US10: $149,200 - $248,500 USD Annual
- US15: $155,900 - $259,800 USD Annual
- US20: $162,700 - $271,100 USD Annual
- US30: $176,300 - $293,700 USD Annual
Required Skills
Required Languages
🇬🇧 English