À propos de ce poste IAM Platform Owner – SailPoint, PingFederate, SSO & IGA chez Synechron
Job Summary
Synechron is seeking a Senior Platform Owner – Security Tools with strong expertise in Identity and Access Management (IAM), Single Sign-On (SSO), Identity Governance and Administration (IGA), and enterprise security platforms.
The role will own the deployment, integration, administration, enhancement, and support of security toolsets, including SailPoint, Ping SSO, CyberArk, HashiCorp Vault, Imperva, and CipherTrust. The successful candidate will provide hands-on technical leadership, manage platform operations, support secure application onboarding, define governance standards, and guide technical teams.
This role will contribute to business objectives by strengthening identity governance, access controls, authentication, platform reliability, security operations, and risk management.
Software Requirements
Required
- SailPoint IdentityIQ (IIQ) or SailPoint Identity Security Cloud: Strong hands-on experience with the applicable platform version used in the project environment.
- Identity Governance and Administration (IGA): Strong understanding of identity lifecycle management, governance, provisioning, access control, and certification processes.
- SailPoint development: Experience developing and customizing workflows, forms, connectors, rules, plugins, and integrations.
- Identity lifecycle management: Experience with Joiner, Mover, Leaver (JML) workflows, access requests, certifications, provisioning, role management, and entitlement management.
- PingFederate and PingAccess: Experience implementing, integrating, administering, and supporting SSO solutions.
- Identity protocols: Strong knowledge of SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), and federated identity.
- Programming and scripting: Strong skills in one or more of Java/J2EE, Python, PowerShell, Bash, or .NET.
- Platform administration: Experience deploying, integrating, enhancing, troubleshooting, upgrading, and supporting enterprise security platforms.
- Enterprise security architecture: Strong understanding of cybersecurity principles, authentication, authorization, secure integration, and access controls.
- Agile delivery: Experience working in Agile delivery environments and managing technology initiatives.
Preferred
- HashiCorp Vault: Experience with secrets management.
- CyberArk: Experience with Privileged Access Management (PAM).
- CipherTrust Manager: Experience with tokenization and encryption services.
- Imperva: Experience with database access monitoring.
- AppViewX: Experience with certificate management.
- Experience with cloud security and DevSecOps environments.
- Relevant certifications in SailPoint, Ping Identity, CyberArk, security, or cloud technologies.
- Experience with platform automation, monitoring, reporting, and operational improvement.
Overall Responsibilities
- Own and manage enterprise security platforms and IAM solutions throughout their lifecycle.
- Lead the deployment, integration, administration, enhancement, upgrade, and operational support of security tools.
- Design and implement IGA solutions using SailPoint IdentityIQ or SailPoint Identity Security Cloud.
- Develop and maintain JML workflows, access requests, certifications, provisioning processes, roles, forms, rules, connectors, plugins, and integrations.
- Implement and support SSO solutions using PingFederate and PingAccess.
- Troubleshoot authentication, authorization, federation, provisioning, integration, and platform-related issues.
- Collaborate with application, infrastructure, security, and delivery teams to ensure secure onboarding of applications and services.
- Define platform standards, governance policies, operating procedures, and security best practices.
- Assess platform performance, availability, integration quality, security risks, and operational requirements.
- Provide technical leadership, mentoring, and guidance to technical teams.
- Lead, mentor, and develop team members through knowledge sharing, technical reviews, and structured support.
- Manage stakeholder expectations, delivery priorities, risks, dependencies, and project outcomes.
- Support cloud security, DevSecOps, automation, and efficient use of platform resources where applicable.
- Maintain secure, reliable, scalable, and auditable security platforms that support business and regulatory requirements.
Technical Skills (By Category)
Programming Languages
Essential
- Java/J2EE, Python, PowerShell, Bash, or .NET.
- Strong programming and scripting skills for platform customization, workflow automation, integration, troubleshooting, and operational support.
- Ability to develop secure, maintainable scripts, connectors, rules, plugins, and platform integrations.
Preferred
- Experience developing reusable automation utilities for IAM and security platforms.
- Experience writing scripts for CI/CD, platform administration, monitoring, reporting, and operational support.
Databases/Data Management
Essential
- Understanding of identity data, access records, roles, entitlements, certifications, provisioning data, and audit information.
- Ability to support secure data integration between IAM platforms, enterprise applications, directories, and databases.
- Understanding of data accuracy, data protection, access controls, retention, and auditability.
Preferred
- Experience with database access monitoring using Imperva.
- Experience supporting tokenization and encryption services using CipherTrust Manager.
- Experience improving identity-data quality, reconciliation, reporting, and audit readiness.
Cloud Technologies
Essential
- Understanding of cloud security concepts relevant to IAM, SSO, secrets management, identity federation, and access control.
- Ability to support security platforms and integrations in enterprise cloud or hybrid environments.
Preferred
- Experience working in cloud security environments.
- Experience with DevSecOps practices and security integration within cloud delivery processes.
- Experience with cloud-based IAM, secrets management, certificate management, or privileged access solutions.
- Experience optimizing cloud security platforms for reliability, performance, and efficient resource use.
Frameworks and Libraries
Essential
- SailPoint IdentityIQ or SailPoint Identity Security Cloud components, including workflows, forms, connectors, rules, plugins, and integrations.
- PingFederate and PingAccess integration components.
- Technology components supporting SAML 2.0, OAuth 2.0, OIDC, and federated identity.
- Frameworks and tools required for secure application onboarding and identity lifecycle automation.
Preferred
- HashiCorp Vault for secrets management.
- CyberArk for PAM.
- CipherTrust Manager for tokenization and encryption.
- AppViewX for certificate management.
- Imperva for database access monitoring.
Development Tools and Methodologies
Essential
- IAM and IGA platform ownership.
- JML lifecycle management.
- Access requests, approvals, certifications, provisioning, role management, and entitlement management.
- SSO implementation, federation, authentication, authorization, and secure application integration.
- Platform deployment, administration, troubleshooting, upgrades, enhancements, and operational support.
- Agile delivery practices.
- Technical documentation, platform standards, governance policies, and operating procedures.
- Team leadership, mentoring, stakeholder management, and project coordination.
Preferred
- DevSecOps practices.
- Security automation and continuous control monitoring.
- Certificate lifecycle automation.
- Secrets-management automation.
- Privileged-access governance and database-access monitoring.
- Platform metrics, observability, incident management, and service improvement practices.
Security Protocols
Essential
- SAML 2.0.
- OAuth 2.0.
- OpenID Connect (OIDC).
- Federated identity.
- Authentication and authorization.
- Identity provisioning and access controls.
- Identity governance, role management, access certifications, and entitlement management.
- Secure handling of secrets, credentials, tokens, certificates, and sensitive identity data.
- Enterprise security architecture and cybersecurity principles.
Preferred
- Privileged Access Management.
- Secrets management.
- Tokenization and encryption services.
- Database access monitoring.
- Certificate management.
- Security controls for cloud and DevSecOps environments.
Experience Requirements
- Required: 8+ years of experience in IAM, IGA, enterprise security platforms, identity engineering, security engineering, or a related technical discipline.
- Strong hands-on experience with SailPoint IdentityIQ or SailPoint Identity Security Cloud.
- Experience developing SailPoint workflows, forms, connectors, rules, plugins, and integrations.
- Experience implementing and supporting PingFederate, PingAccess, SAML 2.0, OAuth 2.0, OIDC, and federated identity.
- Experience with identity provisioning, role management, access certifications, access controls, authentication, and authorization.
- Experience owning security platforms, leading deployments, managing integrations, resolving technical issues, and supporting platform enhancements.
- Experience leading, mentoring, and developing technical teams.
- Preferred: Experience with HashiCorp Vault, CyberArk, CipherTrust Manager, Imperva, AppViewX, cloud security, and DevSecOps.
- Industry-specific experience is not mandatory; experience in complex enterprise or regulated environments is preferred.
- Candidates may also qualify through an equivalent combination of relevant professional experience, technical training, security certifications, and demonstrated ownership of comparable IAM or enterprise security platforms.
Day-to-Day Activities
- Administer, enhance, integrate, and troubleshoot IAM, IGA, SSO, and related enterprise security platforms.
- Collaborate with application, infrastructure, security, and business stakeholders through planning sessions, design reviews, application onboarding discussions, incident reviews, and delivery meetings.
- Deliver workflows, connectors, rules, plugins, access processes, SSO integrations, platform changes, technical documentation, and operational improvements.
- Make platform and integration decisions within approved security standards, manage risks and priorities, mentor team members, and escalate issues affecting security, availability, compliance, or delivery.
Qualifications
- A bachelor’s or master’s degree in Computer Science, Information Technology, Cybersecurity, or a related field is preferred; equivalent relevant experience and technical capability may be considered.
- 8+ years of experience in IAM, IGA, enterprise security platforms, identity engineering, or a related technical field.
- Relevant certifications in SailPoint, Ping Identity, CyberArk, security, or cloud technologies are preferred.
- Training in IAM, IGA, SSO, federation protocols, cloud security, DevSecOps, secrets management, and privileged access management is preferred.
- Maintain continuous professional development in identity security, enterprise security platforms, cybersecurity practices, cloud security, automation, and evolving identity standards.
Professional Competencies
- Apply structured critical thinking and problem-solving to resolve authentication, authorization, federation, provisioning, integration, and platform issues.
- Lead, mentor, and develop technical teams while maintaining hands-on involvement in platform engineering and delivery.
- Communicate security requirements, technical decisions, risks, delivery status, and solutions clearly to stakeholders with varied technical backgrounds.
- Adapt to changing security requirements, technologies, platform capabilities, regulatory expectations, and delivery priorities.
- Identify opportunities to improve IAM automation, platform reliability, access governance, security controls, operational efficiency, and resource utilization.
- Manage priorities, projects, incidents, platform changes, stakeholder expectations, and delivery commitments in an Agile environment.
SYNECHRON’S DIVERSITY & INCLUSION STATEMENT
Diversity & Inclusion are fundamental to our culture, and Synechron is proud to be an equal opportunity workplace and is an affirmative action employer. Our Diversity, Equity, and Inclusion (DEI) initiative ‘Same Difference’ is committed to fostering an inclusive culture – promoting equality, diversity and an environment that is respectful to all. We strongly believe that a diverse workforce helps build stronger, successful businesses as a global company. We encourage applicants from across diverse backgrounds, race, ethnicities, religion, age, marital status, gender, sexual orientations, or disabilities to apply. We empower our global workforce by offering flexible workplace arrangements, mentoring, internal mobility, learning and development programs, and more.
All employment decisions at Synechron are based on business needs, job requirements and individual qualifications, without regard to the applicant’s gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law.