IGA Engineer (SailPoint), Zero Trust Program (USSOCOM) ...
NNData - Tampa, FL
Apply NowJob Description
IGA Engineer (SailPoint), Zero Trust Program (USSOCOM) - Journeyman Athenix Special Missions is seeking an Identity Governance and Administration (IGA) Engineer to join the Zero Trust execution team at U.S. Special Operations Command (USSOCOM) in MacDill Air Force Base, Florida. Must be a U.S. Citizen with an Active DoD TS/SCI Clearance. Responsibilities: SailPoint Architecture & Configuration: Lead the design, deployment, and ongoing management of SailPoint IdentityNow (or IIQ) to automate the full identity lifecycle (Joiner, Mover, Leaver) across hybrid and on-premises environments. ABAC Attribute Management: Define and manage the schema for "Trust Attributes" (e.g., Clearance, COI, Project Codes) within SailPoint, ensuring they align with the NIST 8112 metadata standard for consumption by policy decision points. Air-Gapped Identity Operations: Manage the offline instance of SailPoint on the Top-Secret network, developing the workflows to import "Attribute Manifests" and ensure that identity data remains synchronized with the low-side source of truth. Access Certification: Configure and execute automated access certification campaigns for critical data repositories and privileged roles, ensuring compliance with DoD audit requirements. Role Modeling: Work with mission owners to define Technical Roles and Business Roles within SailPoint, replacing broad, static Active Directory groups with granular, policy-driven access roles. Requirements Qualifications Minimum Clearance Required to Start: Active Top-Secret clearance with SCI eligibility. Required Experience & Skills ("Must-Haves"): SailPoint Expertise: Extensive (5+ years) hands-on experience designing, implementing, and administering SailPoint (IdentityNow or IdentityIQ) in a large enterprise environment. Identity Lifecycle Management: Deep understanding of the Joiner-Mover-Leaver (JML) process and experience automating provisioning/deprovisioning workflows connected to HR systems and Active Directory. Directory Services: Strong knowledge of Active Directory, LDAP, and Azure Active Directory (Entra ID) structures and management. Governance Principles: Proven experience with Role-Based Access Control (RBAC) modeling, Separation of Duties (SoD) policy creation, and access certification campaigns. Journeyman: Education: BA/BS or MA/MS; Years Exp: 3-10; A Journeyman labor category has 3 to 10 years of experience and a BA/BS or MA/MS degree. A Journeyman labor category typically performs all functional duties independently. Preferred Experience & Skills ("Nice-to-Haves"): Experience implementing Attribute-Based Access Control (ABAC) strategies. Familiarity with DoD Identity, Credential, and Access Management (ICAM) reference designs. Knowledge of integration protocols such as REST, SCIM, and SOAP. Experience supporting USSOCOM or other DoD agencies. Certifications: Required: CompTIA Security+ CE (or higher) to meet DoD 8570 IAT Level II requirements. Preferred: SailPoint Certified IdentityNow Engineer or SailPoint Certified IdentityIQ Engineer. Preferred: Certified Identity and Access Manager (CIAM) or CISA. Equal Opportunity Employer, including disability and protected veteran status.
Created: 2026-03-13