The Role
Designs and maintains the enterprise identity and access management ecosystem for Texas Department of Public Safety. Responsibilities include implementing SAML and OIDC identity provider frameworks, SSO, MFA, lifecycle automation, application integrations, RBAC, access certifications, SailPoint IGA, and privileged access management. The engineer also troubleshoots provisioning and connectivity issues, supports IAM infrastructure, documents technical processes, and collaborates with security and IT teams.
Summary Generated by Built In
This is a hybrid role; only local candidates will be considered.
The Senior IAM (Identity and Access Management) Engineer will support the Texas Department of Public Safety (TxDPS). This role manages the agency's enterprise IAM ecosystem, including the design and implementation of a centralized identity provider framework using SAML 2.0 and OIDC for single sign-on (SSO) and multi-factor authentication (MFA). The engineer will develop lifecycle workflows, onboard applications through REST APIs, and establish Role-Based Access Control (RBAC). The role also supports Identity Governance and Administration (IGA), Access Management, and Privileged Access Services, including the deployment and ongoing maintenance of a privileged access management solution. The engineer will collaborate with security and IT teams to maintain consistent IAM practices across the agency.
Responsibilities
- Design and implement a centralized identity provider framework using SAML 2.0 and OIDC to support SSO and MFA.
- Develop identity lifecycle workflows and automate user provisioning and reporting using PowerShell and Python.
- Onboard and integrate business applications with IAM systems through REST APIs.
- Establish RBAC models, enforce separation of duties, and design access certification campaigns.
- Integrate IAM solutions across platforms and support IGA, Access Management, and Privileged Access Services.
- Deploy a privileged access management solution featuring secure credential vaulting, automated password rotation, and just-in-time provisioning.
- Perform long-term system maintenance, including performance tuning and troubleshooting provisioning errors and connection failures.
- Collaborate with security and IT teams to maintain consistent IAM practices.
- Assess IAM technologies regularly and maintain technical documentation.
- Provide support for Directory and IAM services, servers, and databases.
Requirements
Minimum Qualifications
- 8 years of experience in IAM platform governance, engineering, lifecycle automation, and scripting.
- 8 years of experience in application onboarding and integrating business applications with IAM systems.
- 5 years of experience designing and implementing RBAC models, enforcing separation of duties, and designing certification campaigns.
- 5 years of experience managing a centralized identity provider and configuring SSO and MFA.
- 3 years of experience with SailPoint Identity Security Cloud.
- 3 years of experience implementing user access reviews with SailPoint Identity Security Cloud.
- 3 years of experience integrating applications with SailPoint Identity Security Cloud.
- 3 years of experience using Privileged Access Management.
- 3 years of experience automating user provisioning and reporting using PowerShell and Python.
Preferred Qualifications
- 2 years of experience working with a state government agency.
Additional Requirements
- Candidates must currently live within 50 miles of the Austin, Texas work location.
- Work outside normal business hours, including weekends, evenings, and holidays, may be required as requested.
Work Location and Schedule
Location: 5805 N. Lamar Blvd, Austin, TX 78752.
Schedule: Monday through Friday, 8:00 AM to 5:00 PM, excluding State holidays.
Work Arrangement: Hybrid (on-site and telework).
Skills Required
- 8 years of experience in IAM platform governance, engineering, lifecycle automation, and scripting
- 8 years of experience onboarding applications and integrating business applications with IAM systems
- 5 years of experience designing and implementing RBAC models, enforcing separation of duties, and designing certification campaigns
- 5 years of experience managing a centralized identity provider and configuring SSO and MFA
- 3 years of experience with SailPoint Identity Security Cloud
- 3 years of experience implementing user access reviews with SailPoint Identity Security Cloud
- 3 years of experience integrating applications with SailPoint Identity Security Cloud
- 3 years of experience using Privileged Access Management
- 3 years of experience automating user provisioning and reporting using PowerShell and Python
- 2 years of experience working with a state government agency
- Must currently live within 50 miles of Austin, Texas
- Availability to work outside normal business hours, including weekends, evenings, and holidays, as requested
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Air InfoSec is a veteran-owned and led cybersecurity consulting and staffing firm based in Austin, Texas, focused on enhancing government security through expert staff placement.


.png)





