HamburgerMenu
hirist

Job Description

Roles & Responsibilities :

Identity Platform Engineer Roles & Responsibilities :

1. Build and Manage Identity Systems :

- Design, implement, and maintain enterprise Identity & Access Management (IAM) solutions.

- Configure and manage platforms such as SailPoint, Microsoft Entra ID, and Active Directory.

- Ensure identity systems are secure, scalable, and highly available.

2. Automate Joiner, Mover, and Leaver (JML) Processes :

- Build automated workflows for employee onboarding, role changes, and offboarding.

- Automatically provision and deprovision user accounts and application access based on HR events.

- Eliminate manual identity management tasks through automation.

3. User Provisioning and Access Management :

- Create automated provisioning workflows for enterprise applications.

- Assign and revoke user access according to business roles and policies.

- Ensure employees receive the correct access at the right time.

4. Application Integration :

- Integrate business applications with the organization's IAM platform.

- Build and maintain connectors using APIs, SCIM, LDAP, or other integration methods.

- Enable Single Sign-On (SSO) and centralized identity management across applications.

5. Implement Role-Based Access Control (RBAC) :

- Design and maintain RBAC models.

- Define birthright access for new employees based on their department or role.

- Ensure users receive only the permissions required to perform their jobs (Principle of Least Privilege).

6. Identity Governance and Compliance :

- Implement access governance policies and approval workflows.

- Support access certification and periodic access reviews.

- Maintain audit logs and ensure compliance with security and regulatory requirements.

7. Manage Authentication and Single Sign-On (SSO) :

- Configure and support authentication protocols such as SAML, OAuth 2.0, and OpenID Connect (OIDC).

- Enable secure Single Sign-On across enterprise applications.

8. Troubleshoot Identity Issues :

- Investigate and resolve provisioning failures, synchronization issues, authentication errors, and connector problems.

- Perform root cause analysis and implement permanent fixes instead of temporary workarounds.

9. Develop Automation and Customizations :

- Create custom workflows, rules, transforms, and scripts within SailPoint.

- Automate repetitive IAM processes using scripting languages such as PowerShell, Java, or Python where applicable.

- Build reusable solutions that improve operational efficiency.

10. Collaborate with Cross-Functional Teams:

- Work closely with HR teams for employee lifecycle management.

- Coordinate with IT Infrastructure, Security, Application Owners, and DevOps teams to onboard applications and manage access.

11. Documentation and Knowledge Sharing:

- Document identity workflows, integrations, configurations, and standard operating procedures.

- Maintain technical documentation and contribute to internal knowledge repositories.

12. Ensure Security Best Practices:

- Follow enterprise security standards and IAM architecture guidelines.

- Monitor identity systems for potential risks or unauthorized access.

- Continuously improve identity processes to enhance security and operational efficiency.

Ideal Candidate:

- Strong Identity Platform Engineer Profile - treats identity as a scalable platform product, with end-to-end lifecycle automation experience.

- Mandatory (Experience 1) - Must have 5+ years of total experience engineering enterprise identity platforms, with a minimum of 3 years hands-on SailPoint (connectors, rules, transforms, workflows, policies).

- Mandatory (Experience 2) - Must have experience building JML lifecycle automation (joiner/mover/leaver), turning manual, exception-heavy identity processes into automated, policy-driven platform components.

- Mandatory (Experience 3) - Must have experience owning application onboarding into an identity governance model - birthright access, RBAC, and request-driven access.

- Mandatory (Tech skill 1) - Must have hands-on experience provisioning and deprovisioning access across Active Directory, Entra ID, and enterprise applications.

- Mandatory (Tech skill 2) - Must have a solid grip on SAML, OAuth2, OIDC, and directory sync.

- Mandatory (Tech skill 3) - Must have experience integrating identity systems with HR sources and downstream apps via APIs or connectors.

- Mandatory (Education) - Must have a degree in CS / IT / Engineering or equivalent real-world experience.

- Preferred (Process) - Experience contributing to shared knowledge bases, runbooks, and improving identity platform standards over time.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...