IAM Engineer, Identity Governance (IGA & PAM)
- Company
- Deltek
- Location
- United States
- Work type
- Full Time · Remote
- Posted
- 2026-09-16
Job description
Position Responsibilities
Identity Governance & Access Management / PAM
Serve as the technical point of contact for all IGA implementation and development efforts.
Assist in the design and development of IGA connectors and integrations with enterprise applications — SaaS, on-premise, and cloud.
Build and configure certification campaigns in Saviynt (user access reviews, entitlement certifications, role certifications), including workflows and decision routing.
Build and customize workflows, rules, roles, and policies in IGA to support provisioning, deprovisioning, and access reviews.
Build reviewer hierarchies and delegation rules so the correct approvers are assigned automatically.
Configure auto-remediation so revocations flow into connected systems (AD, SaaS apps) without manual execution.
Extend governance into Privileged Access Management (PAM) — onboarding privileged accounts, vaults, and elevated entitlements into the same certification, workflow, and review model as standard access.
Implement and operate PAM controls including credential vaulting, session management, just-in-time (JIT) elevation, and privileged session monitoring.
Partners with security teams to reduce standing privilege and enforce least-privilege access across critical systems.
Maintain the data quality behind certifications — identity correlation, role definitions, and application onboarding into Saviynt
Non-Human & Agentic Identity Governance
Govern the full lifecycle of non-human identities (NHIs) — service accounts, machine identities, secrets, and API credentials — including discovery, ownership assignment, risk-tiering, and periodic recertification.
Extend the identity governance plane to AI agents — registering agents, scoping least-privilege access via Saviynt, integrating with secrets management (e.g., Azure Key Vault), and enforcing runtime guardrails and approval gates.
Help eliminate shadow agents and orphaned NHIs through continuous discovery, dormancy detection, and drift alerts.
Automation & AI-Driven Engineering
Champion an automation-first approach — identifying manual identity and access processes that can be eliminated, self-serviced, or fully automated.
Design and maintain automation using REST APIs, JSON, SQL, and scripting languages (PowerShell, Python, JavaScript).
Leverage AI-powered tools and agents (e.g., Microsoft Copilot, Claude) to accelerate connector development, troubleshooting, documentation, and operational insights.
Apply AI to enhance governance activities such as access reviews, anomaly detection, and reporting — including Saviynt's native AI/rapid-onboarding capabilities.
Compliance, Audit & Operations
Support audit readiness and access attestation for regulatory and compliance frameworks (e.g., SOX, SOC 1 / SOC 2, NIST, FedRAMP).
Maintain the data quality behind certifications — identity correlation, role definitions, and application onboarding.
Own resolution of complex incidents and service requests through ITSM platforms (e.g., ServiceNow), ensuring SLA adherence, and mentor junior engineers on identity concepts and tooling.
Qualifications
Required Qualifications
Strong understanding of IAM principles, including user lifecycle management, role-based access control (RBAC), least privilege, and segregation of duties (SoD), and PAM.
5+ years of hands-on IAM engineering experience, including deep, demonstrable expertise configuring and developing on Saviynt EIC (IGA).
Demonstrated experience with enterprise-scale IAM implementations, ideally in organizations with hundreds of applications.
Proficient with REST APIs, JSON, SQL, and scripting languages (e.g., PowerShell, Python, JavaScript).
Experience conducting or supporting access certification campaigns, audit activities, and compliance-driven controls.
Familiarity with application infrastructure and architecture (Windows/Linux, cloud platforms like Azure, AWS, GCP).
Excellent troubleshooting, debugging, communication, and documentation skills.
Ability to work independently and manage priorities in a fast-paced environment.
Preferred Qualifications
Experience with PAM platforms, procedures, implementations, and best practices. (Privileged Access Management).
Experience governing non-human and/or agentic (AI agent) identities and secrets management (e.g., Azure Key Vault).
Knowledge of Active Directory, Azure AD, and identity federation technologies (SAML, OAuth, OIDC).
Experience using AI tools and developing agents (e.g., Microsoft Copilot, Claude) to improve operational efficiency.
Prior experience in regulated environments (e.g., SOX, HIPAA, GDPR).
IAM certifications (e.g., CIAM, CISSP, Saviynt Certified Professional) are a plus.
5+ years of hands-on development experience with IGA, including configuration, workflows, and connector development.
U.S. Citizenship is required for this position due to the sensitive nature of the identity and access systems supported and applicable regulatory/compliance obligations.