
Principal Engineer, Cybersecurity, IGA
Posted Sep 14

Posted Sep 14
This is a fully remote position, open to applicants in Michigan.
β’ Develop, configure, and manage enterprise IGA platforms such as SailPoint, Saviynt, or Microsoft Entra ID Governance, along with supporting directory and authentication services.
β’ Design identity lifecycle workflows for new hires, role changes, and departures, including automated provisioning and deprovisioning processes.
β’ Establish and sustain access requests, approval workflows, access certification, and recertification initiatives, as well as RBAC models, role mining, and segregation-of-duties regulations.
β’ Configure authoritative data sources, manage identity reconciliation, and address identity data quality issues.
β’ Implement SSO, MFA, federation, and risk-based authentication utilizing SAML, OAuth, OpenID Connect, and SCIM protocols.
β’ Create automations and integrations using PowerShell, Microsoft Graph, REST API, and SCIM to onboard applications to IGA services.
β’ Generate identity reports, governance integrations, and audit evidence for access-related compliance controls.
β’ Resolve IGA, provisioning, and directory-related issues; maintain thorough documentation; and implement IAM controls to support SOX, HIPAA, ISO 27001, and NIST CSF compliance.
β’ Collect requirements from senior business, application, and infrastructure stakeholders while providing architectural consultation and scope definition.
β’ Define, communicate, and incorporate enterprise identity governance standards, practices, and controls with senior stakeholders.
β’ Evaluate complex identity challenges, articulate technical concepts clearly, and uphold accurate configuration and governance methodologies.
β’ A Bachelorβs degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field, or equivalent practical experience.
β’ At least 8 years of experience in IT or cybersecurity.
β’ Minimum of 5 years of practical experience in engineering and managing IGA or IAM environments.
β’ Familiarity with SailPoint, Saviynt, or Microsoft Entra ID Governance, as well as Active Directory and Microsoft Entra ID.
β’ Proficient in identity lifecycle management, provisioning and deprovisioning, access certification, RBAC, and enforcement of segregation-of-duties.
β’ Knowledge of SAML, OAuth, OpenID Connect, and SCIM.
β’ Experience with PowerShell, Microsoft Graph, or REST APIs.
β’ Preferred qualifications: SailPoint IdentityIQ or IdentityNow Engineer, Saviynt, Microsoft Certified: Identity and Access Administrator Associate (SC-300), or CISSP certification.
β’ Flexibility to work remotely.
β’ No travel required (Travel Percentage: None).
Arista Networks
Coforma
Platform.sh
Arista Networks
Get handpicked remote jobs straight to your inbox weekly.