About the Role
The Identity Management Engineer is responsible for implementing, maintaining, extending, and troubleshooting the university’s identity management platform and associated technologies. This role also drives user adoption and educates stakeholders on the value of identity governance.
Responsibilities
- Implement and maintain identity management systems, including provisioning, de-provisioning, and password management.
- Integrate IDM solutions with existing systems, applications, and directories, ensuring data synchronization.
- Manage the lifecycle of digital identities, including RBAC and recertification campaigns.
- Ensure seamless integration of the identity management platform with SSO and modern protocols like OAuth, SAML, and OpenID Connect.
- Implement security measures such as MFA, encryption, and least privilege access controls.
- Establish monitoring and auditing mechanisms to detect security incidents and track user activity.
- Collaborate with cross-functional teams to gather requirements and ensure alignment with business objectives.
- Assist end-users and IT support staff with access-related issues.
- Document implementation and configuration details, ensuring alignment with regulatory requirements and industry best practices.
- Perform other duties or projects as assigned.
Requirements
- Bachelor’s Degree or equivalent combination of directly related full-time experience and education totaling nine years.
- Five+ years of dedicated experience in Identity and Access Management (IAM).
- Experience working with Identity Governance and Administration (IGA).
- Experience administering and configuring SailPoint Identity Security Cloud (ISC), SailPoint IIQ, Saviynt or similar platforms.
- Experience developing programming code.
- Experience with key identity management and access concepts such as least privilege, privileged access, segregation of duties, RBAC, authentication, authorization, and user lifecycle workflows.
- Experience with IAM technologies and infrastructure, including SSO, directory federation, SAML, OAuth, MFA, user provisioning, account creation and management, entitlement review, enterprise directory architecture, and application onboarding.
- Familiarity with SailPoint Non-Employee Risk Management (NERM).
- Experience configuring and deploying self-service Access Request portals.
- Experience designing Access Certification campaigns.
- Active cyber security or other relevant certification (e.g., CISSP, CISM, IDM-specific).
- Experience onboarding applications and integrating disparate systems using REST APIs, SCIM, JSON, and web services.
- Programming/scripting experience in PL/SQL, Powershell, Linux shell, Java, Perl, Python, and/or JavaScript.
- Experience working with identity management in a complex University or Medical Center environment.
- Experience gathering requirements, documenting workflows, and translating business needs into technical IAM rules.
- Experience developing technical and administrative documentation and diagrams.
- Familiarity with regulations and frameworks such as HIPAA, FERPA, NIST, GDPR.
- Experience managing complex 'multi-persona' identities unique to universities.
- Ability to communicate effectively.
Skills
- Identity and Access Management (IAM)
- Identity Governance and Administration (IGA)
- SailPoint Identity Security Cloud (ISC)
- SailPoint IIQ
- Saviynt
- Programming
- Least Privilege
- Privileged Access
- Segregation of Duties
- Role-Based Access Control (RBAC)
- Authentication
- Authorization
- User Lifecycle Workflows
- Single Sign-On (SSO)
- Directory Federation
- SAML
- OAuth
- Multi-Factor Authentication (MFA)
- User Provisioning
- Self-Service Password Management
- Entitlement Review
- Enterprise Directory Architecture
- Application Onboarding
- REST APIs
- SCIM
- JSON
- Web Services
- PL/SQL
- Powershell
- Linux Shell Scripting
- Java
- Perl
- Python
- JavaScript
- HIPAA
- FERPA
- NIST
- GDPR
- Technical Documentation
- Workflow Documentation
Location
- Hybrid
Work Type
- Full-time
- Hybrid
Experience Level
- Five+ years of dedicated experience in Identity and Access Management (IAM)
Education Level
- Bachelor’s Degree
- Advanced Degree
Benefits
- Total rewards
About the Company
- Stony Brook University is committed to excellence in diversity and the creation of an inclusive learning, and working environment.
Equal Opportunity
- All qualified applicants will receive consideration for employment without regard to race, color, national origin, religion, sex, pregnancy, familial status, sexual orientation, gender identity or expression, age, disability, genetic information, veteran status and all other protected classes under federal or state laws.
- If you need a disability-related accommodation, please call the university Office of Equity and Access (OEA) at (631) 632-6280 or visit OEA.
