
Platform Engineer, IAM
Posted Aug 25

Posted Aug 25
This is a fully remote position, open to applicants in Romania, +1 more country.
• Evaluate information security risks in accordance with internal policies and industry best practices.
• Enhance the protection of information and IT assets by testing security systems and implementing relevant security standards, policies, and procedures.
• Deploy cybersecurity technologies under the direction of the global information security lead.
• Provide daily operational support for business functions.
• Oversee third-party vendors as necessary to ensure compliance with established standards.
• Deliver information security training to relevant teams.
• Design, develop, and implement SailPoint IdentityIQ solutions, which include workflows, rules, custom connectors, and RBAC/ABAC/PBAC access models.
• Serve as the primary operational subject matter expert (SME) for the IIQ platform across all environments, addressing platform health, aggregation and provisioning issues, root-cause analysis, upgrades, and ITIL/ITSM change management.
• Conduct manager, entitlement-owner, micro-certification, and SoD access certification campaigns utilizing risk-based approaches and AI-driven insights.
• Improve Joiner, Mover, and Leaver workflows, focusing on birthright provisioning, de-provisioning, and orphan-account management.
• Lead role mining, role engineering, and entitlement rationalization efforts.
• Control privileged access through PAM integration, SoD enforcement, and Just-In-Time provisioning.
• Ensure IGA processes align with SOX, GDPR, HIPAA, PCI-DSS, NIST 800-53, and ISO 27001, providing audit-ready reporting and documentation.
• Develop integrations with ServiceNow/Jira, SIEM/SOAR, and AWS, Azure, and GCP IAM.
• Collaborate with application owners, HR, IT Security, and business units to foster adoption.
• Present key performance indicators (KPIs) that reflect platform maturity.
• Over 10 years of experience in Identity & Access Management, including a minimum of 7 years in hands-on IGA platform engineering.
• Expert-level knowledge of SailPoint IdentityIQ, including workflows, rules, connectors, lifecycle events, certifications, and role modeling.
• Proficient in Java and BeanShell scripting.
• Familiarity with SQL, XML, JSON, REST APIs, and web services.
• Experience with LDAP / Active Directory, Azure AD / Entra ID, and enterprise directory services.
• Knowledge of SCIM, SAML 2.0, OAuth 2.0, OpenID Connect, and CI/CD pipelines using Git, Jenkins, and Ansible.
• Understanding of NIST CSF 2.0, NIST 800-53, ISO 27001/27002, Zero Trust Architecture, and COBIT 2019.
• Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
• Preferred certifications include SailPoint certifications, CISSP, CISM, or CISA.
• Competitive-edge knowledge of SailPoint Identity Security Cloud, IIQ-to-ISC migration strategies, ITDR concepts and tools, CyberArk PAM integration, cloud permission governance, ServiceNow ITSM integration, AI/ML in identity analytics, identity data governance, and Non-Human Identity governance.
• Relocation support is not available.
• Equal opportunity employment.
• Internal opportunities for professional growth are encouraged prior to external recruitment.
Quvia
Anyone AI
Manulife
Accenture Federal Services
Get handpicked remote jobs straight to your inbox weekly.