Governance and Administration (IGA) Engineer
$110,000–$125,000 year
HybridSan Antonio, Texas, United States
Job Summary
Design, configure, deploy, and maintain SailPoint IdentityIQ or Identity Security Cloud platforms, developing custom workflows, rules, and scripts. Integrate enterprise applications, directories, and cloud services using REST APIs and SCIM connectors to automate Joiner, Mover, and Leaver provisioning. Configure access certification campaigns, entitlement catalogs, and Separation of Duties policies while enforcing Role-Based and Attribute-Based Access Control models. Perform system health checks, patching, and database maintenance across production and non-production environments. Serve as the technical escalation point for complex provisioning errors, connector failures, and performance bottlenecks. Ensure all configurations align with DoD/Federal cybersecurity standards and support Authority to Operate assessments.
Required Qualifications
- Have an active Secret or higher-level Government security clearance that requires U.S. citizenship
- Bachelor's degree in computer science, Cybersecurity, Information Technology, Computer Engineering, or a related technical discipline
- Minimum of six (6) years of dedicated experience in Identity and Access Management (IAM), with at least four (4) years of hands-on engineering, configuration, and administration of SailPoint IdentityIQ or SailPoint Identity Security Cloud
- Active CompTIA Security+ CE certification (or higher DoD 8570/8140 IAT Level II compliant certification, such as CYSA+, GSEC, or CISSP)
- Superior analytical, troubleshooting, and collaboration skills, with a proven history of managing complex technical deliverables independently
- Advanced capability in developing Java, BeanShell, and XML components within the SailPoint IdentityIQ framework
- Demonstrated experience building RESTful APIs, SCIM interfaces, JDBC connectors, and custom application integrations
- Deep understanding of core identity protocols and directories: SAML 2.0, OAuth, OIDC, Active Directory, LDAP, and PKI/CAC/PIV integrations
- Solid working knowledge of relational database management systems (Oracle, SQL Server, PostgreSQL) and SQL query writing
- Direct experience implementing SailPoint solutions within Federal/DoD ICAM programs or Zero Trust Architecture (ZTA) environments
- Experience with cloud platforms (AWS, Microsoft Azure, Google Cloud Platform) and containerized application deployments
- Familiarity with DevSecOps, automated CI/CD deployment pipelines, and version control systems (Git)
- Hands-on integration experience pairing SailPoint with Privileged Access Management (PAM) tools (e.g., BeyondTrust) or Identity Providers (e.g. Ping, Entra ID)
- Applicants for employment in the US must have valid work authorization that does not now and/or will not in the future require sponsorship of a visa for employment authorization in the US by Capgemini
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.