IAM SailPoint Engineer
18 hours ago
Providence
Job DescriptionAt ALLERE GROUP, we pride ourselves in creating the perfect match for our candidates. We work tirelessly to build relationships with top companies across the nation, so we always have exciting opportunities for the right candidates. If you are excited about emerging technologies and would love to be a part of a progressive company, we want to talk to you!Job Title: IAM SailPoint EngineerLocation: Allentown, PA; Providence, RI or Louisville, KY (Hybrid) NOT OPEN TO C2C CANDIDATES We are seeking a hands-on SailPoint Engineer to support and enhance our SailPoint IdentityIQ (IIQ) platform with a strong focus on application onboarding and access provisioning. You will design and implement end-to-end identity integrations, develop lifecycle event workflows, onboard new applications to IIQ, and ensure reliable provisioning to target systems. This role partners closely with Application Owners, Security, Operations, and Audit to drive consistent identity governance at scale. Immediate needs will be integrations between SailPoint IdentityIQ (IIQ) and SAP SuccessFactors Employee Central to enable HR driven identity lifecycle automation (Joiner/Mover/Leaver). You will own the end-to-end engineering—from data modeling and connector configuration to policy/rule logic, workflow orchestration, and access certification enablement—while partnering closely with our SAP/HR technology organization operating in a SAFe Agile model for planning and delivery. Responsibilities • Design and implement SailPoint connectors/integrations for SAP Success Factors Employee Central (e.g., via OData APIs, SF EC Compound Employee API, IPS, SCIM, flat file)., • Build and maintain attribute mappings, transformations, and correlation logic to create/maintain unique digital identities and entitlements., • Engineer HR driven provisioning to downstream directories and apps (e.g., AD/Azure AD, key business apps) using JML events., • Implement delta/near Realtime feeds, handle edge cases (contingent workers, rehires, LOA, concurrent employment), and ensure resiliency and replay strategies., • Build identity data exports from SailPoint to legacy IGA systems, • Translate HR events (Joiner, Mover, Leaver) into SailPoint lifecycle events, workflows, and policies (e.g., birthright access, department/location changes, manager transitions, deprovisioning)., • Implement roles, entitlements, policy violations, SOD checks, and certification campaigns driven by HR attributes., • Develop detection & remediation for orphaned accounts, rehire rules, and multi-contract scenarios within SuccessFactors., • Define and enforce authoritative source logic, identity uniqueness rules, and account correlation rules., • Build validation, reconciliation, and exception handling to minimize manual remediation., • Instrument monitoring (dashboards, alerts, audit trails); define operational SLIs/SLOs for provisioning latency and data accuracy. SAFe / Agile Delivery, • Participate in PI Planning, backlog refinement, story slicing, and cross team coordination with the SAP Scaled Agile teams (HRIS, SAP Basis, Security)., • Provide engineering estimates, produce architecture diagrams, and deliver incremental value via sprints., • Collaborate with product owners, scrum masters, and release train engineers; contribute to system demos and Inspect & Adapt events. Platform Engineering & Support, • Administer, monitor, and optimize the SailPoint IdentityIQ platform (app servers, task scheduler, connectors, clustering, job tuning, and logs)., • Develop and maintain IIQ objects (rules, workflows, tasks, roles, policies, certifications, forms, email templates, aggregation jobs)., • Troubleshoot and resolve production incidents (connector failures, provisioning errors, aggregation/job performance, identity refresh issues)., • Maintain environment parity across Dev/Test/Prod and support release management/SDLC with change controls. Application Onboarding & Provisioning, • Lead onboarding applications to IIQ including scoping, integration design, schema mapping, authoritative/non-authoritative source integration, and access modeling (entitlements/roles)., • Implement and tune provisioning connectors (e.g., AD/LDAP, Azure AD/Microsoft Entra ID, databases/JDBC, web services/REST/SOAP, SCIM, SaaS apps)., • Build and maintain joiner-mover-leaver (JML) processes, automated birthright access, and role-based access controls (RBAC)., • Define and execute account aggregation, entitlement aggregation, and credential management (password sync/management if applicable)., • Create certification campaigns and policy controls (SoD, toxic combinations), and enable continuous compliance. Experience Requirements:, • 4–7+ years of IAM engineering with SailPoint IdentityIQ and/or Identity Now (custom rules, workflows, connectors, role model, certifications)., • Hands-on integration experience with SAP SuccessFactors Employee Central as an authoritative identity source (preferably using Compound Employee and/or OData; familiarity with IPS/IAS advantageous)., • Strong grasp of HR data models (worker/assignment, manager, position, org structures) and practical handling of rehire, LOA, contingent, concurrent employment., • Proficiency with JML automation, correlation rules, and provisioning to AD/Azure AD and common enterprise apps., • Scripting/development: Java (IdentityIQ), Bean Shell, Groovy, PowerShell and/or Python for transformations, rules, and operational tooling., • Experience working in SAFe/Scaled Agile environments (PI Planning, story estimation, release planning, demos)., • Solid understanding of directory services (LDAP), SSO/SAML/OIDC, SCIM, REST, and webhook/event patterns., • Strong troubleshooting across identity data pipelines, logs, API errors, and connector behavior. ALLERE GROUP is a proud woman-owned business (WBENC certified) and active supporters of numerous philanthropic, volunteer, and fundraising endeavors. ALLERE GROUP offers direct hire, contract to hire, and statement of work placements. We offer access to employer healthcare benefits, and a 401k retirement plan. Allere Group provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.