Role Overview
We are seeking an IGA Engineer to design, build, operate, and sustain the enterprise Identity Governance & Administration (IGA) platform that serves as the control plane for how identity and access are governed across the organization. This role is responsible for developing and enhancing IGA capabilities-connectors, workflows, roles, and integrations-while keeping the platform healthy, reliable, and audit-ready, and executing the SOX ITGC controls that make it a trusted, compliant system of record for access.
This is a hands-on engineering role spanning both build and run: configuring and developing new capabilities, integrating target systems, and enhancing governance workflows on one side, and sustaining platform health, change management, vendor-coordinated migrations, incident resolution, and control execution on the other. The engineer turns requirements into working configuration and code, keeps the platform available, and ensures every SOX-relevant activity is performed on schedule with complete, clean evidence. The ideal candidate brings solid hands-on experience with an enterprise IGA platform (SailPoint, Saviynt, or equivalent) combined with strong ITGC/SOX discipline and an operations-and-audit mindset.
The IGA platform is a business-critical, SOX-scoped security capability. Operational lapses translate directly into two kinds of failure: disruptions that block provisioning, deprovisioning, and access reviews, and control failures that produce audit findings and compliance exposure. This position is critical to ensuring the platform is stable, well-instrumented, and rarely surprises the business.
Key Responsibilities
IGA Development & Engineering
- Design, develop, and enhance IGA capabilities-connectors, integrations, joiner/mover/leaver (JML) and access-request workflows, roles, entitlements, certifications, and SoD rules-to meet evolving governance and business requirements.
- Build and maintain integrations between the IGA platform and target systems (HR, directories, cloud, and enterprise/SaaS applications) via APIs and connectors.
- Translate governance and access-model requirements into working configuration and code, following engineering standards and design patterns.
- Test, document, and promote changes through the appropriate environments with quality and maintainability in mind.
Platform Operations
- Operate, administer, and sustain the IGA platform so it runs reliably day to day, resolving sync, provisioning, and workflow failures as they arise.
- Execute platform upgrades, patches, and configuration changes through disciplined change control, with validated cutover and rollback plans.
- Maintain and enforce environment segregation between non-production and production.
Observability, Monitoring & Reliability
- Configure and continuously tune monitoring, logging, alerting, and dashboards for the platform, its connectors, and its governance workflows.
- Establish leading-indicator alerting (connector health, provisioning failures, job/queue depth, workflow errors) so degradations are caught before they disrupt users.
- Ensure failures generate alerts and that recurring errors are escalated into incidents per defined procedures.
- Define and track availability and health metrics for the platform and its critical workflows.
Incident & Problem Management
- Investigate and resolve incidents affecting the IGA platform and its governance workflows, restoring service and following the incident management process.
- Perform root-cause analysis on recurring platform issues and implement durable preventive fixes.
- Maintain runbooks and operational documentation to support consistent incident handling.
Change & Release Management
- Execute changes through the standard change management process-documented change requests, testing, and appropriate business/IT approvals before production migration.
- Enforce segregation of duties between developers and operations on production migrations ensure any developer activity in production is monitored, logged, and reviewed.
- Support periodic change reviews and emergency-change post-implementation reviews.
Vendor & Migration Coordination
- Serve as a technical point of contact for platform and managed-service vendors during upgrades, migrations, and platform changes.
- Plan and execute migration/upgrade cutovers-scheduling, pre-checks, validation testing, rollback plans, and go/no-go decisions-and hold vendors accountable to SLAs.
- Coordinate with infrastructure and cloud teams on environment or backup dependencies.
SOX & ITGC Compliance Execution
- Own timely, accurate execution and evidence collection for the IGA platform's SOX control set, working within the broader IAM SOX program's governance and cadence.
- Execute access-administration controls: provisioning and account changes, terminations/deactivations, administrative and user-account revalidations, SoD/role matrix maintenance, and privileged account activity reviews.
- Execute change-management controls in line with the segregation-of-duties requirements above, and support SOC 1/SOC 2 report review and periodic governance and risk reviews.
- Investigate exceptions, assess impact, document results, and drive deficiencies to remediation ensure no self-review on any revalidation control.
- Operate in a continuous audit-ready posture and support internal and external audit requests with complete, on-time evidence.
Automation & Continuous Improvement
- Use scripting to make configuration and control execution repeatable, reviewable, and auditable, reducing operational toil and tightening the loop between operations and evidence collection.
- Maintain knowledge continuity through documentation and runbooks so no single control or activity depends on one individual.
Required Qualifications
Experience
- 5-7 years in IAM/IGA engineering and operations, with hands-on experience configuring and developing on an enterprise IGA platform.
- Proven experience building and operating an enterprise IGA platform in production (SailPoint, Saviynt, or comparable).
Technical Skills
- Hands-on IGA development and administration: connectors/integrations, JML and access-request workflows, roles/entitlements, certifications, and SoD rules.
- Solid grounding in IAM fundamentals: authentication, SSO (SAML/OIDC), provisioning/SCIM, RBAC, JML, and SoD concepts.
- Experience building and integrating with target systems (HR, directories, cloud, and enterprise/SaaS applications) via APIs and connectors.
- Experience with observability and monitoring for application platforms-building meaningful alerts and dashboards, not just consuming them.
- Experience with incident and change management via ITSM tooling.
- Scripting ability (e.g., Python, PowerShell) for automation of platform tasks and evidence collection.
Compliance Skills and Experience
- SOX compliance and ITGC control testing experience.
- Ability to think, review, document, and challenge evidence from an auditor's perspective.
- Experience managing internal and external audit engagements.
- Strong understanding of IAM processes, access controls, and evidence validation.
- Ability to assess compliance risks and identify control gaps.
- Strong documentation and communication skills for auditor interactions and compliance reporting.
- Hands-on experience executing and evidencing core ITGC control types-access provisioning/deprovisioning, periodic user and privileged access reviews/recertification, and Segregation of Duties (SoD).
- Change-management control experience-change request tracking, testing, approvals, and dev-to-prod segregation of duties.
- Experience with deficiency and exception management-investigating exceptions, assessing impact, and tracking remediation to closure.
- Discipline to execute recurring controls on cadence and sustain audit-ready evidence.
- Experience reviewing SOC 1/SOC 2 reports, including complementary user entity controls (CUECs).
- Familiarity with GRC/compliance tooling for evidence and control management.
- Experience working with enterprise IAM platforms such as AD, SailPoint/Saviynt, etc. is preferred.
Preferred Qualifications
- Relevant IGA platform certification or equivalent platform-specific training.
- Deeper experience developing and troubleshooting IGA connectors and integrations.
- Experience leading IGA platform migrations or major version upgrades.
- Prior experience partnering with GRC, Internal Audit, and External Audit in a regulated enterprise.
- General awareness of the cloud environment the platform runs in-enough to coordinate effectively with infrastructure and vendor teams (deep cloud engineering not required).
Why This Role Is Critical
The IGA platform is where access is governed and where a significant set of SOX ITGC controls are executed. Without dedicated engineering, operational, and compliance ownership, the platform is exposed on two fronts at once: reliability and audit.
This role directly protects the organization from:
- Platform and workflow disruptions that block onboarding, delay deprovisioning, and stall access reviews.
- SOX control failures and audit findings-missed revalidations, broken change/SoD discipline, incomplete evidence.
- Failed or delayed platform migrations and upgrades due to a lack of internal accountability.
- Incident-handling and control-coverage gaps that threaten compliance and continuity.
- Over-dependence on premium-priced vendor and contractor support.
This position is for an engineer who builds, runs, and keeps a business-critical, SOX-scoped platform effective-someone who understands that in a regulated identity platform, engineering, reliability, and compliance are the same job.
#LI-7013