Jobs · Engineering · New York

Security Cloud Developer – (SailPoint IdentityIQ)

Cloud and Things · New York, NY · Yesterday
Engineering$50–$62/hrFull-time

Location: New York, NY (Hybrid 2 days / week)
Duration: 12 Months (with potential for extension)
Start Date: estimated - 10/1/26
W2 Hourly Rate: $50-$62/hour

Overview

We are seeking a Security Cloud Developer who will support our NYS client. This role will design, develop, modernize, and support enterprise identity governance capabilities across hybrid cloud and on-premises environments using SailPoint IdentityIQ (IIQ) and Identity Security Cloud (ISC). The developer will lead IAM architecture, lifecycle automation, integrations, governance controls, and the planned migration from IIQ to ISC while aligning solutions with Zero Trust and compliance requirements.

Duties

  • Design, implement, administer, and maintain SailPoint IdentityIQ and Identity Security Cloud solutions.
  • Develop BeanShell rules, custom workflows, lifecycle event logic, task definitions, plugins, connectors, aggregation jobs, reconciliation logic, and provisioning adapters.
  • Build scalable application onboarding frameworks, entitlement schemas, role models, certification campaigns, policy enforcement, segregation-of-duties controls, and governance reporting.
  • Define end-to-end IAM architecture for identity sources, directories, governance layers, provisioning flows, and joiner/mover/leaver automation.
  • Architect and develop SailPoint integrations with ServiceNow for access requests, approvals, ticketing, provisioning, incidents, changes, catalog governance, and entitlement mapping.
  • Integrate IAM platforms with Active Directory, LDAP, Microsoft Entra ID, HR systems, AWS, Azure, GCP, cloud applications, databases, PAM tools, and downstream systems.
  • Develop REST, SOAP, SCIM, SAML, OAuth, and OIDC integrations and support MFA and federation patterns.
  • Administer Microsoft Entra ID, including Privileged Identity Management, and maintain identity data quality and directory hygiene.
  • Collaborate with business owners and technical teams to mature RBAC/ABAC, role mining, access modeling, and application onboarding programs.
  • Conduct code reviews, threat modeling, vulnerability analysis, root cause analysis, and performance troubleshooting for IAM solutions.
  • Test, deploy, patch, upgrade, tune, and provide production support for SailPoint and related IAM platforms.
  • Plan and support the migration from SailPoint IdentityIQ to Identity Security Cloud and maintain architecture diagrams, data flows, technical documentation, and operational runbooks.

Mandatory Qualifications

  • 5+ years of IAM engineering experience.
  • 5+ years of hands-on SailPoint IdentityIQ development experience.
  • Hands-on experience designing, implementing, administering, and supporting SailPoint IdentityIQ and Identity Security Cloud solutions.
  • Strong proficiency in Java, BeanShell, XML, JSON, SQL, and REST API development.
  • Deep knowledge of the SailPoint IIQ object model, connector framework, workflow engine, plugin architecture, lifecycle events, rules, aggregation, reconciliation, and provisioning.
  • Experience architecting and developing integrations between SailPoint IdentityIQ and ServiceNow.
  • Experience with Active Directory, LDAP, Microsoft Entra ID, identity stores, directory services, and authentication protocols.
  • Experience developing REST, SOAP, and SCIM integrations and implementing SAML, OAuth, OIDC, and MFA/federation patterns.
  • Experience integrating IAM systems with cloud platforms such as AWS, Azure, or GCP.
  • Strong knowledge of identity governance, Zero Trust, least privilege, RBAC, ABAC, segregation of duties, access certification, and policy enforcement.
  • Experience with joiner/mover/leaver automation, authoritative identity sources, application onboarding, entitlement modeling, role mining, and access modeling.
  • Experience supporting production IAM environments, including troubleshooting, patching, upgrades, performance tuning, code reviews, vulnerability remediation, and technical documentation.
  • Knowledge of NIST compliance requirements and the ability to engineer secure, scalable, auditable IAM solutions.
  • Ability to work onsite at 2 Broadway in New York City, with telecommuting limited to no more than two days per week.

Desirable Qualifications

  • Experience implementing and managing Okta solutions.
  • Experience supporting Citizen IAM and external-user identity programs.
  • Experience with SailPoint Access History and SailPoint Access Modeling.
  • Knowledge of SOX, HIPAA, and ISO 27001 compliance frameworks.
  • Experience with SailPoint SaaS modernization, passwordless authentication, adaptive risk, or ServiceNow IAM modules.

Similar jobs