- Location
- WASH - Washington, DC, United States of America
- Type
- Full-time
- Seniority
- Senior
- Education
- Master
- Source
- Workday
Description
PRIMARY FUNCTION
StraitSys is seeking a Senior SailPoint Subject Matter Expert (SME) to support the Department of Justice (DOJ), Executive Office for United States Attorneys (EOUSA), Office of the Chief Information Officer (OCIO), Cybersecurity Services (CSS) Identity and Access Management (USAidam) Program in Washington, DC.
The Senior SailPoint SME will serve as the senior technical resource responsible for the design, architecture, development, maintenance, and optimization of the USAidgov SailPoint IdentityIQ (IIQ) environment. This individual will provide technical leadership for SailPoint development and operations, oversee code and workflow design, ensure system performance and reliability, and provide architectural and technical recommendations to Government Program and Project Managers.
The Senior SailPoint SME will also lead and provide technical guidance to Junior SailPoint SMEs supporting the USAidam DevOps team and assist with complex technical issues escalated through the USAidam Helpdesk.
ESSENTIAL FUNCTIONS
- Serve as the senior technical authority for the design, architecture, development, maintenance, and enhancement of the USAidgov SailPoint IdentityIQ environment.
- Design and architect the overall SailPoint solution to ensure the environment is secure, efficient, reliable, scalable, and performant.
- Ensure the SailPoint database is appropriately backed up and support the overall reliability and performance of the SailPoint architecture.
- Take ownership of SailPoint code changes and ensure changes are independently validated and appropriately reviewed before incorporation into the overall system codebase.
- Provide technical and design oversight for SailPoint workflows supporting internal and external account-management functions.
- Design, develop, maintain, and enhance SailPoint workflows supporting user lifecycle management, entitlement provisioning, identity refreshes, aggregation tasks, provisioning, and deprovisioning.
- Oversee SailPoint daily processes and connectors and ensure synchronization, aggregation, and data-correlation issues are identified and resolved quickly.
- Configure and enhance integrations and connectors, including the SailPoint Okta Connector, SailPoint MasterAPI connections, and other data-ingestion mechanisms such as CSV imports and API calls.
- Support automated user provisioning and deprovisioning processes across USAidam-supported applications and environments.
- Develop and maintain integrations necessary to support centralized entitlement and role-based access management.
- Support development and execution of user recertification campaigns for privileged and unprivileged users, including customized certifier routing rules and Government-defined account selection criteria.
- Support implementation and maintenance of automated identity lifecycle and access-governance processes.
- Provide recommendations to Government PMs regarding SailPoint architecture, design strategy, system enhancements, and the applicability and effectiveness of new SailPoint feature releases.
- Lead and provide technical guidance, mentoring, and oversight to the Junior SailPoint SMEs supporting the USAidam DevOps team.
- Assist the USAidam Helpdesk and DevOps team with complex Tier 2/Tier 3 issues escalated for engineering support.
- Troubleshoot SailPoint workflows, connectors, integrations, scripts, synchronization processes, account provisioning, entitlement, and other identity-governance issues.
- Support integration between SailPoint and the broader USAidam technology environment, including Okta and external identity providers.
- Participate in design, development, testing, validation, User Acceptance Testing (UAT), deployment, and post-deployment support activities.
- Conduct or support smoke and regression testing for new builds, enhancements, workflows, integrations, and system releases.
- Ensure updated solutions are properly tested, validated, and receive Government approval prior to production deployment.
- Support system patching, updates, security maintenance, vulnerability remediation, and related operational activities.
- Develop and maintain technical documentation, system design documentation, testing plans, training materials, and other required system artifacts.
- Support Identity and Access reports, audit logs, certification campaigns, and other Government-directed identity governance requirements.
- Collaborate with Government stakeholders, application owners, USAidam engineers, Helpdesk personnel, and other technical teams to resolve issues and deliver secure identity-management capabilities.
REQUIRED QUALIFICATIONS
- Minimum of six (6) years of experience developing code for and maintaining on-premises SailPoint installations.
- Demonstrated expertise with SailPoint IdentityIQ (IIQ) architecture, development, configuration, administration, and maintenance.
- Experience designing, developing, modifying, and maintaining SailPoint workflows supporting identity lifecycle and access-governance requirements.
- Experience developing and supporting automated user provisioning and deprovisioning processes.
- Experience configuring, maintaining, and troubleshooting SailPoint connectors and system integrations.
- Experience troubleshooting synchronization, aggregation, identity correlation, workflow, and data-integration issues.
- Experience supporting identity lifecycle management, entitlement provisioning, access governance, role management, and user certification/recertification processes.
- Experience performing code reviews, validating code changes, and maintaining code quality within an enterprise SailPoint environment.
- Experience supporting SailPoint system performance, reliability, database backup, and operational maintenance.
- Demonstrated ability to design and support integrations between SailPoint and enterprise identity/authentication technologies.
- Experience troubleshooting complex identity-management issues and providing advanced technical support.
- Experience providing technical leadership, oversight, and guidance to junior engineers or developers.
- Strong technical documentation, analytical, troubleshooting, and communication skills.
- Ability to communicate architecture and design recommendations effectively to technical teams, project leadership, and Government stakeholders.
PREFERRED QUALIFICATIONS
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Information Systems, Software Engineering, or a related technical discipline.
- SailPoint IdentityIQ certification or other relevant SailPoint technical certification.
- Experience supporting DOJ, EOUSA, or another Federal Government organization.
- Experience integrating SailPoint IdentityIQ with Okta.
- Experience with the SailPoint Okta Connector and/or SailPoint MasterAPI connector.
- Experience with Okta Identity Engine (OIE/IDaaS) and Okta Government environments.
- Experience with REST APIs, JSON, CSV-based integrations, and enterprise identity data exchanges.
- Experience developing or supporting AWS Lambda functions used for identity-management automation.
- Experience with PowerShell and other scripting or automation technologies.
- Experience with GitLab or comparable source-code management and CI/CD technologies.
- Experience working within a DevOps or DevSecOps development environment.
- Experience with modern authentication and federation standards, including SAML, OIDC, SCIM, PIV, and MFA.
- Knowledge of Privileged Access Management (PAM) and integration between identity governance and privileged account lifecycle management.
- Experience supporting Federal cloud or hybrid environments.
- Familiarity with Federal cybersecurity and identity-management requirements, including NIST, FedRAMP, Zero Trust Architecture, and the CISA Zero Trust Maturity Model.
- Experience supporting Security and Privacy Assessment & Authorization (SPA&A) and Federal system authorization activities.
PREFERENCE STATEMENT
Preference will be given to Calista shareholders and their descendants and to spouses of Calista shareholders, and to shareholders of other corporations created pursuant to the Alaska Native Claims Settlement Act, in accordance with Title 43 U.S. Code 1626(g).
EEO STATEMENT
Additionally, it is our policy to select, place, train and promote the most qualified individuals based upon relevant factors such as work quality, attitude and experience, so as to provide equal employment opportunity for all employees in compliance with applicable local, state and federal laws and without regard to non-work related factors such as race, color, religion/creed, sex, national origin, age, disability, marital status, veteran status, pregnancy, sexual orientation, gender identity, citizenship, genetic information, or other protected status. When applicable, our policy of non-discrimination applies to all terms and conditions of employment, including but not limited to, recruiting, hiring, training, transfer, promotion, placement, layoff, compensation, termination, reduction in force and benefits.
REASONABLE ACCOMMODATION
It is Calista and Subsidiaries' business philosophy and practice to provide reasonable accommodations, according to applicable state and federal laws, to all qualified individuals with physical or mental disabilities.
The statements contained in this job description are intended to describe the general content and requirements for performance of this job. It is not intended to be an exhaustive list of all job duties, responsibilities, and requirements.
This job description is not an employment agreement or contract. Management has the exclusive right to alter the scope of work within the framework of this job description at any time without prior notice.