Senior Identity Engineer

Posted Yesterday
Hiring Remotely in United States
Remote
Senior level
Information Technology • Consulting • Infrastructure as a Service (IaaS)
Identity Solutions Redefined
The Role
Lead SailPoint identity engineering workstreams from architecture reviews and assessments through design, implementation, testing, and delivery. Build and maintain IdentityIQ and Identity Security Cloud solutions, connectors, workflows, rules, provisioning, certifications, and automation. Integrate enterprise systems, review code and designs, mentor engineers, advise clients, and improve operational efficiency. The role also supports platform migrations, tool evaluations, knowledge transfer, and emerging non-human identity initiatives.
Summary Generated by Built In
The Role

Palyrian is building a team of Senior Identity Engineers who can walk into a live environment and be productive without ramp-up. You have four or more years of hands-on SailPoint delivery, you have shipped real identity work, and you are trusted to make design calls when an architect is not in the room.

The distinction we draw at this level is ownership of a workstream rather than a ticket. On a large program there are several concurrent workstreams — application onboarding, custom workflow implementation, RBAC maturity, etc. — and a senior engineer owns one end to end: reviewing the junior engineers’ designand connector work, keeping solutions maintainable, and designing the localized pieces of a process without escalating every question upward. Engineers who consistently do that last part are on the path to the architect track.

We also want engineers who want to broaden. Palyrian works across SailPoint, Oasis, Veza, and C1 (formerly ConductorOne), and non-human identity is where a lot of the new work is heading. If you have been single threaded on one platform and want out of that, this is the right kind of move.

About Palyrian

Palyrian is an identity services boutique founded in 2024 by three practitioners who spent years building and running enterprise identity programs together. The firm exists on a simple premise: most IAM programs have the right tools, but few have the right people. Palyrian brings the quality of a large firm with the speed of a small one, and its vision is to be the most trusted identity services boutique in the market: a focused firm clients return to because the work holds up, not because of a contract.

Palyrian works across SailPoint (IdentityIQ and Identity Security Cloud), Oasis, Veza, and C1. The team treats identity as a system, not a stack of tools, and favors fixing what a client already owns before recommending something new. It is a boutique that runs like a tech startup: small, fast, and light on process.                                                  

What You Will Do
  • Lead the technical portion of product health checks and platform architecture reviews: assess configuration, code quality, performance, and coverage, and produce actionable
  • Contribute grounded, hands-on input to future-state architecture and tool evaluations identifying  what these platforms actually do, not what the marketing materials
  • Translate assessment findings into scoped, sequenced engineering plans that can be executed.
  • Own a workstream end to end on a client program, including its scope, quality, and delivery.
  • Design and build custom SailPoint IIQ and/or ISC solutions: connectors, workflows, rules, transforms, provisioning policies, etc.
  • Design the localized pieces of a process. For example, the full sequence of events and approvals when an employee goes on extended leave and returns without needing an architect to specify it for you.
  • Run App Factory delivery: help define onboarding patterns, build reusable templates and automation, and implement various connectors.
  • Integrate with enterprise systems (Active Directory and Entra ID, HR platforms, ServiceNow, cloud platforms, custom applications) through web services, JDBC, or other types of connectors.
  • Review other engineers' application design and connector build-out. Own code review, testing strategy, and whether it is maintainable.
  • Mentor junior engineers through pairing, review, and direct feedback.
  • Manage and improve access certification campaigns, reporting, and program analytics.
  • Drive configuration, tuning, and automation improvements so operational effort falls over time.
  • Lead knowledge transfer so client teams can own more of their own platform.
What You Bring
  • 4+ years of hands-on SailPoint IdentityIQ and/or Identity Security Cloud experience, including at least two full implementation or major upgrade cycles.
  • 6+ years overall in identity and access management or enterprise software engineering.
  • Strong Java and BeanShell for IIQ, and/or transforms, cloud rules, and REST API development for ISC. Comfortable with SQL, XML, and at least one other scripting language.
  • Deep working knowledge of identity governance: joiner-mover-leaver, role and attribute-based access, certifications, segregation of duties, and provisioning.
  • Demonstrated ability to own a workstream and make design decisions within it, rather than working exclusively from someone else’s specification.
  • The ability to work directly with client stakeholders, explain technical decisions in plain language, and manage expectations in a live environment.
  • A focus on understanding the problem rather than producing syntax. Writing code is the part of this job that is getting easier; knowing what should be built is not.
  • Evidence that you build or learn outside of work; a side project, a home lab, something recent you taught yourself.
  • S. based and authorized to work in the United States.
Nice to Have
  • Experience across both IdentityIQ and Identity Security Cloud, including IIQ-to-ISC migration.
  • SailPoint certification (Certified IdentityIQ Engineer and/or Certified Identity Security Engineer). If you are not certified but can demonstrate equivalent delivery depth, tell us. We will look at the work first and sort out credentials
  • Exposure to non-human identity, machine identity, or secrets platforms (Oasis, C1, HashiCorp Vault, or comparable). This is where a growing share of Palyrian’s work is heading.
  • Experience with adjacent identity domains or IGA products: PAM (CyberArk, Delinea, BeyondTrust), IGA (Saviynt, Veza), or IdP and authentication platforms (Okta, Entra ID, Ping).
  • Identity protocol fluency: SAML, OAuth 2.0, OIDC, SCIM.
  • Regulated industry experience and the audit and compliance expectations that come with it.
  • CI/CD and infrastructure automation applied to identity platform deployments.
A Note on Certifications

Certifications help us find you and help clients trust the team, and Palyrian sponsors them. They are not how we decide whether you can do the job.    

Who Thrives Here

Palyrian is a boutique that runs like a tech startup. Identity must be your thing. The team lives by four principles:

  • Builder's Mindset. When you see a better way, you build it. Problems don’t come with answers attached.
  • Own the Outcome. You are accountable for whether the client’s program improves, not just whether the ticket closed.
  • Always Be Learning. Identity changes fast, and non-human identity changes faster. You keep pace and bring what you learn back to the team.
  • Prideful Excellence. Work that holds up after we leave. Clients return because of the quality, not the contract.

If you have spent the last few years going deeper into a single platform and have started to feel the walls, that is a good reason to talk to us rather than a reason not to.

Hiring Process
  1. An introductory screening.
  2. A technical interview with Palyrian. Expect roughly 30 minutes of systems-thinking and scenario questions rather than a live coding exercise. This is the first real gate.
  3. A behavioral and culture conversation with one of the founders.

Two interviews, and we try to keep them inside a single hour where we can. We would rather move quickly than run you through a gauntlet.

Benefits
  • Remote-first, U.S. based. Flexible hours, with client time zones taking priority when an engagement calls for it.
  • 20 days of paid time off, granted as a bucket rather than accrued, plus holidays.
  • Medical, dental, and vision coverage through Aetna.
  • 401(k) with company match: full match on the first 3% and half match on the next 2%.
  • Annual performance-based bonus eligbility.
  • Sponsored training and certifications, including platform-specific enablement.
  • Direct client work, real ownership, and a seat at a boutique early enough that your work shapes the firm.

Skills Required

  • 4+ years of hands-on SailPoint IdentityIQ and/or Identity Security Cloud experience
  • At least two full SailPoint implementation or major upgrade cycles
  • 6+ years overall experience in identity and access management or enterprise software engineering
  • Strong Java and BeanShell experience for IdentityIQ, and/or transforms, cloud rules, and REST API development for Identity Security Cloud
  • SQL, XML, and at least one additional scripting language experience
  • Deep knowledge of identity governance, including joiner-mover-leaver, RBAC, ABAC, certifications, segregation of duties, and provisioning
  • Experience owning workstreams and making design decisions independently
  • Ability to work directly with client stakeholders, explain technical decisions, and manage expectations
  • Evidence of building or learning outside of work, such as a side project or home lab
  • Based in the United States and authorized to work in the United States
  • Experience with both IdentityIQ and Identity Security Cloud, including IIQ-to-ISC migration
  • SailPoint certification, such as Certified IdentityIQ Engineer or Certified Identity Security Engineer
  • Exposure to non-human identity, machine identity, or secrets platforms
  • Experience with PAM, IGA, or identity provider platforms
  • Fluency with SAML, OAuth 2.0, OIDC, and SCIM
  • Regulated industry experience and familiarity with audit and compliance expectations
  • CI/CD and infrastructure automation experience applied to identity platform deployments
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Herndon, VA
8 Employees
Year Founded: 2024

What We Do

Palyrian is an IAM services company dedicated to transforming identity infrastructure into a powerhouse of efficiency and security. With a team of expert engineers and a passion for innovation, we design and implement tailored solutions that empower organizations to unlock their full potential. From seamless integrations to robust system optimizations, our focus is on delivering scalable and secure results that set you apart in an ever-evolving digital landscape.

Similar Jobs

Zeta Global Logo Zeta Global

Senior Software Engineer

AdTech • Artificial Intelligence • Marketing Tech • Software • Analytics
Easy Apply
Remote or Hybrid
United States
2429 Employees
150K-180K Annually
In-Office or Remote
Home, PA, USA
3751 Employees
119K-187K Annually

Coinbase Logo Coinbase

Senior Software Engineer

Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
Easy Apply
Remote
USA
4700 Employees
186K-219K Annually

HackerOne Logo HackerOne

Senior Security Engineer

Security • Software • Cybersecurity
In-Office or Remote
2 Locations
2598 Employees
180K-220K Annually

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account