JOB SUMMARY:
Argano is seeking an experienced SailPoint Engineer to design, build, and operate our identity governance program on SailPoint Identity Security Cloud (ISC). This is a hands-on engineering role for someone who has already worked at real enterprise scale—our managed identity population exceeds 400,000 users—and is comfortable owning the technical depth of a large, complex SailPoint environment: connectors and integrations, identity lifecycle automation, access certifications, role and policy design, and day-to-day platform reliability.
The SailPoint Engineer will partner closely with security, IT operations, application owners, HR systems teams, and compliance stakeholders to ensure the right people have the right access at the right time—and that we can prove it during an audit.
RESPONSIBILITIES:
- Design, configure, and maintain SailPoint Identity Security Cloud (ISC) across identity sources, applications, and provisioning connectors
- Own end-to-end Joiner-Mover-Leaver (JML) lifecycle automation, integrating with HR systems (e.g., Workday), Active Directory / Entra ID, LDAP, and downstream applications
- Design and maintain Role-Based Access Control (RBAC) models, Separation of Duties (SoD) policies, and birthright/entitlement structures at enterprise scale
- Build and tune access certification campaigns, ensuring accurate, auditable, and timely recertification cycles across a large and diverse application portfolio
- Develop and support custom and out-of-the-box connectors, workflows, and integrations (REST/SCIM/SOAP APIs) to onboard new applications into governance
- Troubleshoot provisioning, aggregation, and certification issues across a high-volume identity population, balancing performance, accuracy, and compliance
- Partner with security and compliance teams to support SOX, SOC 2, and other audit requirements, providing evidence and remediating findings
- Collaborate with application owners and business stakeholders to translate access governance requirements into scalable SailPoint solutions
- Contribute to the platform roadmap: recommend improvements, evaluate new SailPoint capabilities, and help mature governance maturity across the organization
- Document architecture, configurations, and standard operating procedures; participate in on-call/escalation support for critical identity platform issues
EDUCATION:
- Bachelor's degree in Computer Science, Information Security, or a related field preferred; equivalent practical experience will also be considered.
LOCATION:
This is an onsite position based in Seattle, WA or Orlando, FL. Candidates must be able to work onsite from either of these locations.
EXPERIENCE:
- 5+ years of overall experience in Identity and Access Management (IAM), with a strong preference for candidates whose background is concentrated in Identity Governance and Administration (IGA) specifically
- 2+ years of hands-on experience with SailPoint Identity Security Cloud (ISC)—the SaaS/cloud platform (formerly IdentityNow)—configuring sources, provisioning, access profiles, roles, workflows, and certification campaigns
- Demonstrated experience supporting a large identity population—100,000+ managed identities—including the operational and performance challenges that come with scale (aggregation windows, certification campaign design, connector throughput, etc.)
- Proven experience operating in a complex, matrixed enterprise environment with a large, heterogeneous application portfolio, multiple business units, and competing stakeholder priorities
- Solid understanding of identity lifecycle management and JML processes, including integration with HR systems and directory services (Active Directory, Entra ID/Azure AD, LDAP)
- Working knowledge of RBAC and/or ABAC modeling, SoD policy design, and access certification/attestation best practices
- Experience with API-based integrations (REST, SCIM, SOAP) for connector development and troubleshooting
- Strong troubleshooting skills and comfort owning production issues in a platform that many other teams depend on.
PREFERRED QUALIFICATIONS:
- SailPoint Certified IdentityNow Engineer, SailPoint Certified Implementation Engineer (ISC), or equivalent SailPoint certification
- Prior experience with SailPoint IdentityIQ (IIQ) in addition to ISC, particularly if you've supported a migration from IIQ to ISC
- Experience in a regulated industry (financial services, healthcare, insurance, etc.) supporting SOX, HIPAA, or similar compliance frameworks
- Familiarity with scripting/automation (PowerShell, Python, or Beanshell) for custom connectors or workflow logic
- Relevant security certifications such as CISSP, CISM, or CIAM
About UsArgano is the first of its kind: a digital consultancy totally immersed in high-performance operations. We steward enterprises through ever-evolving markets, empowering them with transformative strategies and technologies to exceed customer expectations, unlock commercial innovation, and drive optimal efficiency and growth.
Skills Required
- 5+ years of overall Identity and Access Management experience, preferably concentrated in Identity Governance and Administration
- 2+ years of hands-on SailPoint Identity Security Cloud experience configuring sources, provisioning, access profiles, roles, workflows, and certification campaigns
- Experience supporting 100,000+ managed identities at enterprise scale
- Experience operating in a complex, matrixed enterprise environment with a heterogeneous application portfolio and multiple business units
- Understanding of identity lifecycle management and joiner-mover-leaver processes
- Experience integrating IAM with Workday, Active Directory, Entra ID/Azure AD, LDAP, and downstream applications
- Working knowledge of RBAC or ABAC modeling, Separation of Duties policy design, and access certification best practices
- Experience with REST, SCIM, and SOAP API-based integrations for connector development and troubleshooting
- Strong troubleshooting skills and ability to own production issues
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience
- SailPoint Certified IdentityNow Engineer, SailPoint Certified Implementation Engineer, or equivalent SailPoint certification
- Prior SailPoint IdentityIQ experience, especially supporting migration from IdentityIQ to Identity Security Cloud
- Experience in a regulated industry supporting SOX, HIPAA, or similar compliance frameworks
- Familiarity with PowerShell, Python, or BeanShell for custom connectors or workflow logic
- CISSP, CISM, CIAM, or other relevant security certification
What We Do
Argano is a next-generation business and technology services provider that builds the Digital Foundations™ that make businesses run better. We leverage insights and innovations to help leaders design and implement the complex solutions necessary to not just survive but thrive and improve financial and operational performance. Argano believes a firm’s core operating technologies should be enablers of commercial innovation, not a constant source of limitation, and is committed to helping clients think differently about how they deploy and manage people, processes and technology.








