Hampton North logo

Identity Governance Engineer

Hiring from
United States
Work type
Remote
Posted
Is this job info correct?
Show job description

Identity Governance Lifecycle Specialist

This role designs, implements, and operates identity governance and administration processes for employees, contractors, third parties, and non-human identities. The specialist integrates authoritative sources, enables the joiner/mover/leaver lifecycle, builds access request and certification workflows, and supports application onboarding. Provisioning, deprovisioning, entitlements, separation of duties, evidence, and reporting all run repeatably and stay audit-ready.


Logistics: Contract, remote in the northeast US, must be able to visit client site in CT 1-2 times per quarter


Here's what you'll be doing:

  • Design, document, configure, and maintain joiner, mover, leaver, leave of absence, contractor, and third-party identity lifecycle workflows
  • Integrate and reconcile authoritative identity sources and define lifecycle states, identity attributes, correlation rules, ownership, exception paths, and data quality controls
  • Administer access requests, approvals, provisioning, deprovisioning, birthright access, access certification, and revocation
  • Monitor provisioning failures, access request exceptions, certification issues, reconciliation results, orphaned accounts, stale access, and control breaches, and coordinate timely remediation
  • Develop and maintain SOPs, runbooks, workflows, control evidence, and audit-ready records
  • Partner with business and application owners to define roles, entitlements, ownership, approval paths, risk attributes, and role-to-entitlement mappings
  • Support RBAC design, access policy implementation, least privilege analysis, separation of duties rules, access review campaigns, and exception governance
  • Validate that the right reviewers assess the right access based on risk, with decisions, evidence, remediation, and completion documented
  • Support governance for privileged access, service accounts, application identities, APIs, automation identities, and other non-human identities
  • Maintain identity and entitlement catalogs, business-friendly access descriptions, application ownership records, and governance metadata
  • Coordinate IGA onboarding with application owners and technical SMEs across enterprise and modernized platforms
  • Gather and validate connector and API information, account schemas, entitlement data, test environments, service accounts, error handling, and deployment requirements
  • Support connectors and workflow integrations, and validate account aggregation, provisioning, deprovisioning, reconciliation, logging, and failure handling
  • Build and execute test scenarios for lifecycle events, access requests, user access certifications, roles, SoD policies, negative cases, rollback, and go-live readiness
  • Produce application onboarding and configuration guides and support transition to operational teams
  • Build dashboards and metrics for lifecycle timeliness, request turnaround, certification completion, access removals, exceptions, reconciliation, SoD violations, and application onboarding
  • Support IAM audits, risk assessments, regulatory examinations, incident response, and evidence requests
  • Work with the managed identity services provider to align SLAs, documentation, control performance, and escalation paths, and identify automation opportunities that reduce manual effort and access risk

And what you need to have:

  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field (advanced degree or equivalent experience preferred)
  • 4+ years in IAM, IGA, cybersecurity, identity operations, application security, or IT governance with hands-on ownership of identity lifecycle, access governance, provisioning, user access certifications, or application onboarding
  • Platform experience with Microsoft Entra ID, SailPoint, Saviynt, Okta, or comparable
  • Application connectors, APIs, directories, HR integrations, and service accounts
  • RBAC, SoD, reconciliation, authoritative source integration, and audit evidence
  • NIST CSF, NIST SP 800-53, and FFIEC aligned access control expectations
  • Ability to analyze identity and entitlement data to find risk and control gaps, and to troubleshoot provisioning and reconciliation issues
  • Managed service provider and regulated environment experience preferred
  • Preferred certifications: CISSP, CCSP, Security+, SSCP, CIAM, Microsoft identity credentials, or an IGA platform certification for SailPoint, Saviynt, or Microsoft Entra ID Governance

No CTC or sponsorship at this time.


Similar jobs

Apply on LinkedIn