This is a hands-on IAM SailPoint Engineer role within the Information Security team of a leading healthcare technology company. This engineer will build secure, scalable automation across the identity lifecycle, including provisioning and deprovisioning, role-based access control, access certifications, privileged access workflows, and operational controls. This seat's stack and responsibilities are anchored in SailPoint plus adjacent directory and privileged access management platforms, distinguishing it from a companion, broader multi-platform engineering role also open on the same team. The role supports the organization's flagship identity platform, which secures more than five million members and other external identities across all digital portals.
NOTE: *Must be eligible to work on W2 without sponsorship. Not eligible for C2C.
Active Directory Foundation: maintain and demonstrate broad AD/IAM fluency as a prerequisite to SailPoint specialization work
IAM Automation Engineering: design, develop, test, and maintain automation for identity lifecycle, provisioning, deprovisioning, access requests/approvals, and access reviews
Identity Governance Automation: build and enhance automated workflows for RBAC, access certifications, policy enforcement, exception handling, and governance reporting
Hands-On DevOps Ownership: set up and own CI/CD pipelines directly — a working method here, not a toolset managed by an adjacent team
Compliance & Audit Enablement: automate evidence collection, control validation, access review support, and reporting for NIST, HIPAA, and related standards
Operational Support & Reliability: troubleshoot IAM automation issues, support production workflows, resolve incidents, improve reliability via monitoring/logging
Documentation & Runbooks: maintain process flows, automation logic, runbooks, and support procedures
Experience: 7+ years in identity and access management or automation engineering.
Required foundation: broad Active Directory and IAM fluency, required before SailPoint specialization is considered — no exceptions
Platforms: SailPoint (IdentityNow/ISC assumed — confirm), Active Directory, Microsoft Entra ID, CyberArk, or similar
Automation/Scripting: PowerShell, Python, REST APIs, JSON, Ansible, or similar, with the ability to set up and own CI/CD pipelines hands-on
Professional skills: strong communication across levels, accountability, ownership, self-motivation, and the ability to prioritize independently — treated as hard requirements, not soft preferences
| Location | Denver, Colorado |
| Salary | $75–$85 Per Hour |
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder