CrawlJobs Logo

Zero Trust IGA Engineer

barbaricum.com Logo

Barbaricum

Location Icon

Location:
United States , Tampa

Category Icon

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

Not provided

Job Description:

We are seeking an IGA Engineer to support USSOCOM’s Zero Trust execution efforts by implementing and operating SailPoint-based identity governance capabilities across NIPR, SIPR, and Top Secret networks. The IGA Engineer is responsible for designing, deploying, and maintaining SailPoint Identity Governance solutions that serve as the authoritative source for identity attributes and access decisions. This role goes beyond basic provisioning and focuses on implementing lifecycle automation, access governance, and attribute-driven access control in complex, multi-enclave environments.

Job Responsibility:

  • Design, deploy, and maintain SailPoint IdentityNow or IdentityIQ to automate Joiner-Mover-Leaver (JML) identity lifecycle processes
  • Define and manage identity attributes (e.g., clearance, role, COI, project codes) used to support attribute-based access control (ABAC) models
  • Configure and execute automated access certification campaigns for privileged roles and critical systems
  • Develop and maintain SailPoint role models, including technical and business roles, to replace static group-based access
  • Support identity governance operations across disconnected and air-gapped environments, including Top Secret networks
  • Ensure identity data integrity and synchronization between low-side and high-side environments
  • Collaborate with ICAM, Zero Trust, and integration teams to ensure identity attributes are consumed correctly by downstream enforcement tools
  • Support audit and compliance requirements related to access governance and identity lifecycle management

Requirements:

  • Active DoD Top Secret clearance with SCI eligibility
  • DoD 8570 / 8140 compliant (Security+ CE or higher – IAT Level II)
  • 5+ years of hands-on experience implementing and administering SailPoint (IdentityNow or IdentityIQ) in an enterprise environment
  • Strong understanding of identity lifecycle management (Joiner-Mover-Leaver automation)
  • Experience integrating SailPoint with Active Directory, LDAP, and Microsoft Entra ID
  • Experience implementing access governance concepts, including RBAC, separation of duties (SoD), and access certification
  • Ability to operate independently in complex, mission-critical environments
  • Labor Category Alignment: Journeyman: 3–10 years of experience
  • BA/BS or MA/MS
  • Senior: 10+ years of experience
  • MA/MS
  • supports high-visibility or mission-critical program efforts and may lead others

Nice to have:

  • Experience implementing Attribute-Based Access Control (ABAC) strategies
  • Familiarity with DoD ICAM reference architectures and Zero Trust concepts
  • Experience integrating SailPoint using REST, SCIM, or SOAP
  • Prior experience supporting USSOCOM or other DoD organizations
  • SailPoint Certified IdentityNow or IdentityIQ Engineer
  • CIAM or CISA certification

Additional Information:

Job Posted:
January 30, 2026

Work Type:
On-site work
Job Link Share:

Looking for more opportunities? Search for other job offers that match your skills and interests.

Briefcase Icon

Similar Jobs for Zero Trust IGA Engineer

System Information Assurance and Security Engineer

Barbaricum is seeking a highly skilled System Information Assurance and Security...
Location
Location
United States , Tampa
Salary
Salary:
Not provided
barbaricum.com Logo
Barbaricum
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Active DoD TS/SCI Clearance
  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field (Master’s preferred)
  • 5+ years of experience in enterprise identity and access management architecture
  • Demonstrated expertise with Zero Trust frameworks and DoD ICAM standards
  • Hands-on experience with SAML, OAuth2.0, OpenID Connect, PKI, and certificate management
  • Experience with DoD enterprise solutions such as Radiant Logic, Okta, Ping Identity, SailPoint, ForgeRock, Microsoft Entra ID (Azure AD), or equivalent
  • Deep knowledge of Privileged Access Management and Identity Governance & Administration solutions
  • Strong understanding of DoD cybersecurity compliance frameworks (RMF, NIST SP 800-53, 800-207, 8140/8570)
  • IAM / DoD Certification IAT Level II (e.g., Security+ CE, SSCP, GSEC)
Job Responsibility
Job Responsibility
  • Execute engineering solutions for identity credential and access management for Zero Trust implementation across enterprise systems
  • Design and maintain an enterprise-wide identity and access management strategy aligned with DoD Zero Trust principles, NIST 800-207, and DoD ICAM Reference Design
  • Lead integration of federated identity, single sign-on (SSO), and multi-factor authentication (MFA) across cloud and on-prem environments
  • Develop and maintain policies, standards, and reference architectures to enforce least-privilege and attribute-based access control (ABAC)
  • Conduct the implementation of Privileged Access Management (PAM) and Identity Governance and Administration (IGA) solutions
  • Collaborate with cybersecurity, network, and cloud teams to align ICAM solutions with Zero Trust pillars (identity, device, network, application, and data)
  • Ensure compliance with DoD 8140/8570, RMF, FedRAMP, and other applicable frameworks
  • Lead proof-of-concepts (POCs) and technology evaluations for emerging identity
Read More
Arrow Right

Senior System Information Assurance and Security Engineer

Barbaricum is seeking a highly skilled System Information Assurance and Security...
Location
Location
United States , Tampa
Salary
Salary:
Not provided
barbaricum.com Logo
Barbaricum
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Active DoD TS/SCI Clearance
  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field (Master’s preferred)
  • 10+ years of experience in enterprise identity and access management architecture
  • Demonstrated expertise with Zero Trust frameworks and DoD ICAM standards
  • Hands-on experience with SAML, OAuth2.0, OpenID Connect, PKI, and certificate management
  • Experience with DoD enterprise solutions such as Radiant Logic, Okta, Ping Identity, SailPoint, ForgeRock, Microsoft Entra ID (Azure AD), or equivalent
  • Deep knowledge of Privileged Access Management and Identity Governance & Administration solutions
  • Strong understanding of DoD cybersecurity compliance frameworks (RMF, NIST SP 800-53, 800-207, 8140/8570)
  • IAM / DoD Certification IAT Level II (e.g., Security+ CE, SSCP, GSEC)
Job Responsibility
Job Responsibility
  • Execute engineering solutions for identity credential and access management for Zero Trust implementation across enterprise systems
  • Design and maintain an enterprise-wide identity and access management strategy aligned with DoD Zero Trust principles, NIST 800-207, and DoD ICAM Reference Design
  • Lead integration of federated identity, single sign-on (SSO), and multi-factor authentication (MFA) across cloud and on-prem environments
  • Develop and maintain policies, standards, and reference architectures to enforce least-privilege and attribute-based access control (ABAC)
  • Conduct the implementation of Privileged Access Management (PAM) and Identity Governance and Administration (IGA) solutions
  • Collaborate with cybersecurity, network, and cloud teams to align ICAM solutions with Zero Trust pillars (identity, device, network, application, and data)
  • Ensure compliance with DoD 8140/8570, RMF, FedRAMP, and other applicable frameworks
  • Lead proof-of-concepts (POCs) and technology evaluations for emerging identity
Read More
Arrow Right

Senior System Security and Information Assurance Engineer

The Senior PAM Engineer will play a critical role within Line of Effort 2, respo...
Location
Location
United States , Tampa
Salary
Salary:
Not provided
barbaricum.com Logo
Barbaricum
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Active DoD Top Secret clearance with SCI eligibility
  • Master’s degree (MA/MS) in Cybersecurity, Information Technology, Computer Science, Engineering, or related field
  • 10+ years of professional experience in cybersecurity, systems engineering, or information assurance
  • Meets Cyber Engineer – Senior labor category requirements, including independent execution of all functional duties and support to mission-critical program elements
  • DoD 8570 IAT Level II certification or higher (e.g., Security+ CE, CCNA Security)
  • Deep expertise in Privileged Access Management (PAM) architectures and Zero Standing Privilege concepts
  • Hands-on experience implementing Just-In-Time (JIT) access workflows
  • Experience integrating PAM solutions with Active Directory, SIEM platforms (Splunk), and Identity Governance (IGA) tools
  • Experience producing technical documentation to support RMF and ATO processes (LLDs, SSPs, SOPs)
  • Ability to lead or oversee the efforts of less senior staff as required by program needs
Job Responsibility
Job Responsibility
  • Lead the installation, configuration, and technical implementation of an enterprise Privileged Access Management (PAM) solution (Delinea-focused) across multiple network enclaves
  • Discover, inventory, and onboard privileged user, administrator, and service accounts into a secure credential vault
  • Design and enforce policies for Just-In-Time (JIT) access, session monitoring, and session recording to achieve zero standing privileges
  • Develop scripts and API-based integrations between the PAM solution, Splunk SIEM, and Identity Governance (IGA) platforms
  • Support RMF accreditation activities by developing Low-Level Design (LLD) documents, System Security Plans (SSPs), and Standard Operating Procedures (SOPs)
  • Support Authority to Operate (ATO) efforts through security control implementation and technical validation
  • Lead enterprise rollout of PAM policies from pilot groups to full operational enforcement
  • Collaborate with Zero Trust architects, identity teams, and cyber engineers to ensure alignment with enterprise security architecture
Read More
Arrow Right

Senior Corporate Security Engineer

At Crusoe, the Corporate Security Engineer is essential for safeguarding our emp...
Location
Location
United States , San Francisco; Sunnyvale
Salary
Salary:
130000.00 - 170000.00 USD / Year
crusoe.ai Logo
Crusoe
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 6-8+ years of hands-on experience in a Corporate Security, Enterprise Security, or similar role
  • Proven experience designing, implementing, and managing security technologies at scale, including: MDM solutions (e.g., Intune, Kandji, Jamf, etc.), IAM solutions (e.g., Okta, Azure AD, IGA applications, etc. including SSO, MFA, PAM concepts), Endpoint security tools (EDR/XDR), Email threat protection solutions, DLP and/or SSPM solutions
  • Strong understanding of modern security principles, including Zero Trust architecture, "secure by design," and defense-in-depth
  • Experience with securing SaaS applications and enforcing security policies
  • Demonstrated experience in security incident response, including triage, investigation, and remediation
  • Familiarity with scripting languages (e.g., Python, PowerShell) for automation and integration
  • Excellent problem-solving, analytical, and critical-thinking skills
  • Strong communication and collaboration skills, with the ability to work effectively across different teams
  • Embody the Company values
Job Responsibility
Job Responsibility
  • MDM Administration & Endpoint Security: Implementing, administering, and optimizing Mobile Device Management (MDM) solutions and enforcing security policies across diverse endpoints (laptops, mobile devices)
  • Hardware & Software Security Standards: Establishing and maintaining hardware/software security standards and ensuring the strong security posture of corporate devices
  • Identity & Access Management (IAM): Designing, implementing, and managing core Identity & Access Management (IAM) technologies, including SSO, MFA, PAM, and identity lifecycle solutions, contributing to our Zero Trust architecture
  • Data Protection & Email Security: Implementing, configuring, and tuning Data Loss Prevention (DLP), SaaS Security Posture Management (SSPM), and email security solutions to protect against various threats
  • Secure Architecture & Technology Evaluation: Designing secure corporate environments using "secure by design" principles and evaluating the security posture of new technologies, vendors, and applications
  • Security Operations & Incident Response: Actively participating in corporate security operations, including monitoring security alerts, detecting, triaging, investigating, and responding effectively to security incidents
  • Security Consulting & Best Practices: Consulting with and advising IT, Engineering, and other teams on secure architecture, IAM best practices, and secure configurations
What we offer
What we offer
  • Restricted Stock Units in a fast growing, well-funded technology company
  • Health insurance package options that include HDHP and PPO, vision, and dental for you and your dependents
  • Employer contributions to HSA accounts
  • Paid Parental Leave
  • Paid life insurance, short-term and long-term disability
  • Teladoc
  • 401(k) with a 100% match up to 4% of salary
  • Generous paid time off and holiday schedule
  • Cell phone reimbursement
  • Tuition reimbursement
  • Fulltime
Read More
Arrow Right

Access Management DevOps Engineer

Working closely with the team in germany, you will be responsible for the admini...
Location
Location
Spain , Málaga
Salary
Salary:
Not provided
rewe-digital.com Logo
REWE digital
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Degree in Computer Science or equivalent qualification
  • Proven experience in Identity Governance & Administration (IGA) and IAM platforms
  • Practical knowledge of directory services (Active Directory, Entra ID, Keycloak)
  • Analytical mindset and ability to design complex authorization models
  • Strong communication and collaboration skills
  • Complete fluency in written and spoken English
  • You live in Spain, and you have a valid work permit/VISA (without sponsorship)
Job Responsibility
Job Responsibility
  • Design, build, and operate a secure and scalable Identity Governance & Administration (IGA) platform as the foundation for automation and self-service
  • Develop and maintain APIs to integrate IAM/IGA capabilities across business applications
  • Establish and maintain CI/CD pipelines and containerized environments (Docker, Kubernetes) to support the deployment and evolution of the IAM platform
  • Implement and optimize role-based and context-based access control models (RBAC, CBAC, ABAC, NBAC)
  • Collaborate with security teams to ensure compliance and enable Zero-Trust architectures
What we offer
What we offer
  • Hybrid work and flexible working time
  • Company conditions for private medical insurance
  • Ticket Restaurant
  • Professional development opportunities: English/German courses, and further IT education/trainings
  • Day off on your Birthday
  • 23 days paid vacation
  • Fulltime
Read More
Arrow Right
New

Manager, Identity Security

As Marqeta’s Manager of Identity and Access Management (IAM), you bring a strong...
Location
Location
United States
Salary
Salary:
167100.00 - 244400.00 USD / Year
marqeta.com Logo
Marqeta
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • A minimum of 15 years related experience with a Bachelor’s degree or equivalent combination of related education and work experience
  • Must have been a people manager
  • Establish clear, achievable objectives for the team that align with organizational goals
  • Experience in Agile/Scrum environments holding daily stand-ups, sprint planning, and retrospectives, using tools like Jira, and estimating user stories
  • Comfortable working in a remote only environment and getting hands-on when required
  • Providing guidance, support, and feedback to help team members grow in their roles
  • Strong experience with IAM tools (e.g., Okta, CyberArk, Ping, SailPoint, Britive)
  • Deep knowledge of IAM in cloud-native environments, especially AWS IAM, roles, policies, permissions boundaries, and federation
  • Proficiency in infrastructure-as-code (e.g., Terraform, CloudFormation)
  • Familiarity with authentication and authorization protocols (SAML, OAuth2, OpenID Connect, Kerberos)
Job Responsibility
Job Responsibility
  • Provide Technical and managerial leadership to a team of 5 to 6 Identity Security Engineers
  • Lead implementation of robust IAM strategies aligned with cloud-native architecture and security principles
  • Expand and operationalize the IAM program across IGA, PAM, SSO, MFA, access management, secrets management, and certificate lifecycle management
  • Automate identity provisioning, de-provisioning, and access reviews using tools and infrastructure-as-code
  • Design IAM integrations for AWS-native services ( EC2, S3, IAM, etc.), SaaS platforms, and third-party identity tools (e.g., Okta)
  • Promote and enforce least privilege and zero-trust principles through scalable access controls and policy automation
  • Mentor junior engineers and serve as a technical lead for IAM-related projects
  • Collaborate with Security, DevOps, and Infrastructure teams to embed IAM controls across the engineering lifecycle
  • Stay ahead of emerging trends and continuously refine IAM strategy based on evolving cloud threats and compliance requirements
What we offer
What we offer
  • Multiple health insurance options
  • Flexible time off – take what you need
  • Retirement savings program with company contribution and after tax contributions
  • Equity in a publicly-traded company and an Employee Stock Purchase Program
  • Family-forming benefits, fertility support, and up to 20 weeks of Parental Leave
  • Free therapy sessions, financial and professional coaching, and legal advice
  • Monthly stipend to support our remote work model
  • Annual “development dollars” to support our people growth and development
  • Through Flex First, the freedom to live and work wherever you and your family thrive
  • Fulltime
Read More
Arrow Right

ICAM Identity Engineer

We are seeking an ICAM Identity Engineer to provide hands-on technical expertise...
Location
Location
United States , Tampa
Salary
Salary:
Not provided
barbaricum.com Logo
Barbaricum
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Active TS/SCI Clearance
  • Demonstrated, hands-on expertise with at least one core ICAM platform (Microsoft Entra ID, enterprise PAM such as Delinea, or enterprise IGA such as SailPoint)
  • Strong understanding of identity security principles: least privilege, MFA, JIT/JEA, RBAC/ABAC
  • Experience with Active Directory administration and Group Policy management
  • Ability to design, implement, and troubleshoot complex enterprise security policies
  • DoD 8140 compliance at IAT Level II
Job Responsibility
Job Responsibility
  • Design and implement Microsoft Entra ID Conditional Access policies aligned with Zero Trust principles for Azure and AWS
  • Configure and maintain CAC/PKI-based Certificate Authentication and legacy ADFS environments
  • Manage Ping Federate as an enterprise federation gateway
  • onboard applications for SSO using SAML and OIDC
  • enforce phishing-resistant MFA
  • Onboard privileged user, service, and application accounts into Delinea
  • Implement policies for credential rotation, session recording, and privileged session monitoring
  • Develop and maintain Just-in-Time (JIT) and Just-Enough-Administration (JEA) workflows to reduce standing privileges
  • Configure SailPoint to automate Joiner-Mover-Leaver processes
  • Build and maintain enterprise access catalogs and automated approval workflows
Read More
Arrow Right
New

Support Worker

This specialist supported living service has been purpose-built for young adults...
Location
Location
United Kingdom , Church Stretton, Shrewsbury
Salary
Salary:
12.39 GBP / Hour
brookstreet.co.uk Logo
Brook-St Hiredonline
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Full UK manual driving licence held for at least 1 year
  • Access to your own vehicle (rural location)
  • Passionate about supporting people to live happy, fulfilled lives
  • Patient, caring, and a good listener
  • Confident communicator with individuals and families
  • Able to promote independence and daily living skills
  • Good IT skills and ability to use digital systems
  • Able to work independently and use initiative
Job Responsibility
Job Responsibility
  • Support individuals with daily living and independence skills
  • Promote inclusion and engagement in the wider community
  • Provide personal care where required
  • Build positive, trusting relationships with individuals and their families
  • Encourage participation in social and community activities
  • Work collaboratively within a supportive team environment
What we offer
What we offer
  • Competitive hourly pay
  • High-quality training provided
  • Comprehensive induction with shadow shifts
  • 28 days holiday in year one, increasing with service
  • Free and confidential counselling services
  • Health Cash Plan covering dental, optical, physio & more
  • Long service awards
  • Contributory pension scheme
  • Clear career development and progression opportunities
  • Regular supervision and team meetings
Read More
Arrow Right