Hybrid Role - Ability to travel 20-40%, on average, to the DC area based on frequency of client meetings and level of project engagement required.
Position Description: The SailPoint Senior Architect / Identity Governance and Administration (IGA) SME will serve as a senior technical authority responsible for the architecture, design, integration, enhancement, and operation of enterprise SailPoint IdentityIQ capabilities supporting a large federal customer.
The Senior Architect will provide technical leadership for SailPoint-based credential and identity lifecycle management services operating within an AWS GovCloud / FedRAMP High environment, including identity aggregation and correlation, provisioning, access governance, entitlement certification, application integration, authoritative-source integration, and DHS Continuous Diagnostics and Mitigation (CDM) reporting.
The individual will work closely with ICAM, PAM/CyberArk, cybersecurity, cloud, infrastructure, application, and operations teams to ensure the SailPoint environment is secure, scalable, highly available, auditable, and capable of meeting federal operational and security requirements.
Specific Duties to Perform / General Position Description:
- Serve as a senior SailPoint IdentityIQ architect and IGA SME, providing architecture direction, solution design, technical governance, and Tier 3 engineering support.
- Develop and maintain SailPoint architecture for a large, complex, multi-bureau federal environment, including appropriate separation and governance of bureau identity and entitlement data.
- Architect and oversee SailPoint IdentityIQ workflows, identity lifecycle, provisioning, entitlement governance, recertification, correlation, reporting, and connector health.
- Lead integrations with products such as HRConnect, USAccess, ITM, MuleSoft, WebTA, Concur, Active Directory, Azure, WC2-H, bureau applications, ServiceNow, and agency-specific authoritative/application sources.
- Ensure continuous population and quality of DHS CDM Master User Record elements including TRUST, CRED, BEHAVE, and PRIV and support required audit/reporting data.
- Provide architecture leadership for approval metadata, entitlements, NPE/service-account workflows, data integrity/correlation, reporting jobs, and application connectors.
- Design for 99.9% availability, resilient operations, backup/restore, DR, patching, monitoring, and secure operation in AWS GovCloud FedRAMP High.
- Coordinate SailPoint integration with CyberArk for privileged identity data and with Splunk/CloudWatch, ITSM, and agency security/monitoring services.
- Lead Tier 3 troubleshooting, RCA, connector remediation, architecture reviews, technical documentation, runbooks/SOPs, and Federal workforce knowledge transfer.
- Support cybersecurity and authorization activities including NIST 800-53/RMF, FISMA, FedRAMP High, vulnerability remediation, POA&M remediation, audit inquiries, and ATO maintenance.
- Collaborating with client stakeholders, product owners, and technical teams to gather requirements, translate business needs into technical solutions, and manage scope, timelines, dependencies, and delivery quality
- Provide technical leadership, code/configuration reviews, and mentoring to SailPoint engineers, developers, and administrators.
- Support structured knowledge transfer to Federal personnel, including architecture, integrations, workflows, escalation procedures, and operational processes.
Position Qualifications/Experience/Education:
Required Qualifications:
• Bachelor’s degree in Computer Science, Cybersecurity, Engineering, Information Systems, or related field; 10+ years of IAM/ICAM experience with 7+ years of deep SailPoint IdentityIQ engineering/architecture experience. • Expert knowledge of SailPoint IdentityIQ architecture, lifecycle workflows, provisioning, certifications/recertifications, roles/entitlements, connectors, correlation, reporting, and integrations.
- Experience architecting SailPoint in large federal or comparable enterprise managed-service environments with complex authoritative sources and application connectors.
- Experience with Active Directory/Azure, APIs/integration patterns, ServiceNow/ITSM, cloud-hosted federal systems, FISMA/RMF, and high-availability operations.
- Ability to lead complex troubleshooting, connector design, data-quality remediation, technical reviews, and mentoring/knowledge transfer.
- SailPoint IdentityIQ technical certification(s) appropriate to senior architecture/engineering responsibilities required or strongly preferred.
- Ability to travel 20-40%, on average, to the DC area based on frequency of client meetings and level of project engagement required.
Desired Qualifications:
- Recent federal delivery experience integrating SailPoint IdentityIQ in a managed-service environment.
- Experience with large SailPoint IIQ deployments.
- Experience with DHS CDM/MUR requirements, AWS GovCloud, Splunk/CloudWatch, MuleSoft, and CyberArk integration.
- CISSP, CCSP, or AWS certification.
- Experience applying AI-assisted coding workflows or Model Context Protocol technologies within SailPoint implementations
Competencies:
- Strong communicator able to work effectively with agency stakeholders, bureau teams, technical teams, and vendors.
- Highly organized and outcome-focused; able to manage competing priorities in a 24x7 managed-service environment.
- Proactive problem-solver who can operate with limited direction and drive issues through resolution.
- Comfortable in Agile/Scrum/Kanban and ITIL-aligned environments with disciplined change, incident, and problem management.
- Adaptable to changing BPA Call priorities, security requirements, and SLA-driven delivery.
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
. Ability to lead projects or workstreams