Description
Voted one of Chicago's Best Places to Work by the Chicago Tribune for the ninth year in a row, Clarity Partners is hiring!
Clarity Partners is seeking an Identity and Access Management (IAM) SailPoint Engineer local to Chicago, IL. This role will be responsible for the design, development, customization, and advanced technical support of enterprise Identity Governance & Administration (IGA) solutions, with a strong focus on SailPoint Identity Security Cloud (ISC). The IAM SailPoint Engineer will build and maintain complex integrations, develop automation and workflows, and partner with cybersecurity, infrastructure, HRIS, and application teams to deliver secure and scalable identity solutions. The ideal candidate will bring deep technical expertise in SailPoint engineering, identity lifecycle management, cloud identity platforms, and modern authentication and integration technologies. This position will report in a hybrid setting.
Responsibilities
- Design, develop, configure, and maintain SailPoint Identity Security Cloud (ISC) solutions, rules, workflows, transforms, policies, and identity processing logic.
- Build and optimize complex provisioning and deprovisioning workflows, lifecycle event logic, identity orchestration, aggregation, and correlation processes.
- Engineer and maintain custom connectors, integrations, and advanced SailPoint configurations.
- Lead the onboarding and integration of applications into SailPoint, including schema discovery, connector engineering, entitlement modeling, provisioning logic, and aggregation tuning.
- Design and support identity integrations using SCIM, REST APIs, SAML, OAuth 2.0, and OIDC.
- Engineer identity data flows between SailPoint, Active Directory, Microsoft Entra ID, HRIS, EMR, cloud, and other enterprise platforms.
- Develop automation and scripts using PowerShell, BeanShell, JavaScript, Python, or similar technologies to support identity lifecycle operations, integrations, and data management.
- Develop API-based automation to improve identity data exchange and workflow efficiency.
- Maintain version-controlled code repositories and follow secure software development and engineering practices.
- Engineer identity integrations with Active Directory, Microsoft Entra ID, LDAP, and cloud identity platforms.
- Troubleshoot complex directory synchronization, attribute mapping, connector, aggregation, and provisioning issues.
- Support cloud identity governance across Azure, AWS, and/or GCP environments.
- Support identity federation, single sign-on (SSO), multifactor authentication (MFA), and authentication architecture.
- Serve as an escalation point for complex SailPoint and enterprise identity issues, performing root-cause analysis and implementing long-term technical solutions.
- Maintain technical documentation, integration patterns, procedures, and engineering standards.
- Partner with cybersecurity, infrastructure, HRIS, application, and other technology teams to translate business and security requirements into scalable identity solutions.
- Support scheduled after-hours maintenance activities as needed.
Requirements
Requirements
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or a related field.
- Minimum of 5 years of hands-on experience engineering, developing, or supporting Identity Governance & Administration (IGA) solutions.
- Strong hands-on experience with SailPoint Identity Security Cloud (ISC) and/or SailPoint IdentityIQ.
- Demonstrated experience developing SailPoint rules using BeanShell/Java and creating custom workflows.
- Strong scripting and automation experience using PowerShell, JavaScript, Python, BeanShell, or similar languages.
- Experience engineering integrations using SCIM, REST APIs, SAML, OAuth 2.0, and OIDC.
- Strong understanding of identity lifecycle management, Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), Segregation of Duties (SoD), and enterprise identity architecture.
- Experience working with Active Directory, Microsoft Entra ID, LDAP, HRIS systems, and cloud identity platforms.
- Experience troubleshooting complex identity provisioning, aggregation, synchronization, and integration issues.
- Knowledge of identity federation, SSO, MFA, authentication architecture, and Zero Trust security principles.
- Experience with cloud identity governance across Azure, AWS, and/or GCP.
- Experience with API testing and integration troubleshooting tools such as Postman.
- Strong analytical and troubleshooting skills with the ability to perform root-cause analysis and develop scalable technical solutions.
- Strong written and verbal communication skills with the ability to explain complex technical concepts to technical and non-technical stakeholders.
- Ability to collaborate effectively across cybersecurity, infrastructure, HRIS, application, and business teams.
- SailPoint Engineer or Architect certification is a plus.
- Experience integrating identity solutions with Epic, Oracle Health/Cerner, or other healthcare EMR platforms is a plus.
- Experience supporting large-scale identity modernization initiatives and complex healthcare technology environments is a plus.
Clarity is committed to fair and equitable compensation practices. For the Identity and Access Management (IAM) SailPoint Engineer, the base salary pay range is $120,000 - $130,000. The range represents a good faith estimate that Clarity reasonably expects to pay for this job at the time of posting. Compensation will depend upon an individual’s skills, experience, qualifications, location, and other relevant factors. The salary pay range is subject to change and may be modified at any time.