- Location
- MT-MF-Red Tag, United States of America
- Workplace
- Remote, Hybrid, Onsite
- Type
- Full-time
- Department
- Engineering
- Experience
- 3+ years
- Education
- Master
- Visa
- Not sponsored
- Source
- Workday
Description
Job Description:
**Applicants must be authorized to work in the U.S.; Sponsorship is not available for this position.
** This role can be Remote, Hybrid or Onsite
We are looking for a Senior IAM Security Engineer to own, operate, and continuously improve our Saviynt-based Identity Governance and Administration (IGA) platform. This role is ideal for an engineer who enjoys solving complex identity challenges, leading production support efforts, designing scalable integrations, and improving identity governance capabilities across the enterprise.
You will serve as the primary technical owner of our Saviynt implementation, ensuring reliable identity lifecycle management, access governance, and integration with enterprise systems including Oracle, Active Directory, Entra ID, and other critical business applications. This role balances hands-on engineering, operational ownership, governance maturity, and technical leadership.
Our IAM program is continuing to mature and expand. This role will play a critical part in improving platform reliability, reducing manual effort, strengthening governance controls, and enabling future identity initiatives and broader enterprise security capabilities.
Core Responsibilities:
Operate and Own IAM Services (Primary)
- Own day-to-day operation, support, and reliability of the Saviynt platform
- Troubleshoot and resolve provisioning, deprovisioning, reconciliation, and identity lifecycle failures across Oracle, Active Directory, Entra ID, and integrated applications
- Serve as the primary escalation point for IAM operational incidents and complex access issues
- Perform root cause analysis and implement long-term corrective actions to prevent recurring issues
- Monitor platform health, job execution, provisioning success rates, and service performance
- Develop and maintain operational runbooks, support documentation, and knowledge articles
- Participate in production support processes, change control, peer reviews, and CAB activities
Engineer IAM Integrations and Platform Capabilities
- Design, build, enhance, and support Saviynt connectors, workflows, rules, policies, analytics, and certifications
- Develop and maintain integrations utilizing REST APIs, SOAP services, JDBC connections, and other enterprise integration methods
- Partner with application teams to onboard new applications and automate identity lifecycle processes
- Support Oracle Cloud, Oracle ERP, Active Directory, Entra ID, and other enterprise identity integrations
- Lead testing, validation, deployment, and upgrade activities for IAM platform enhancements
- Ensure IAM solutions are scalable, maintainable, and aligned with enterprise security requirements
Advance Identity Governance Capabilities
- Support and improve Joiner, Mover, Leaver (JML) lifecycle processes
- Implement and maintain access request workflows, approval processes, and entitlement management
- Design, execute, and improve access certification campaigns and remediation activities
- Contribute to role-based and attribute-based access models (RBAC/ABAC)
- Support Segregation of Duties (SoD) controls, governance policies, and audit requirements
- Assist with identity correlation, reconciliation, entitlement cleanup, and governance optimization efforts
Reduce Toil and Improve the Platform
- Identify manual processes and develop automation solutions to improve efficiency and reliability
- Improve platform observability, monitoring, reporting, and operational metrics
- Develop dashboards and reporting that provide insight into platform health and governance effectiveness
- Improve testing practices, deployment processes, and operational maturity
- Drive continuous improvement initiatives focused on scalability, reliability, and user experience
Provide Technical Leadership and Ownership
- Serve as the technical lead for IAM engagements involving application teams and business stakeholders
- Guide technical design discussions and recommend IAM best practices
- Conduct peer reviews and contribute to engineering standards and reusable implementation patterns
- Mentor junior engineers and share knowledge across the IAM team
- Communicate technical concepts, risks, and recommendations clearly to both technical and non-technical audiences
- Balance security, operational stability, business requirements, and delivery timelines pragmatically
Collaborate Across Security Domains
- Partner with Infrastructure, Security Operations, Cloud, and Application teams to deliver integrated identity solutions
- Support identity-related security incidents and remediation activities when required
- Contribute to IAM strategy, roadmap discussions, and future platform enhancements
- Assist with evaluation and adoption of new IAM technologies and capabilities
Required Qualifications
- 5+ years of hands-on experience in Identity and Access Management, Information Security, Platform Engineering, or related technical disciplines
- 3+ years of experience delivering Identity Governance and Administration (IGA) capabilities
- Experience administering and supporting enterprise IAM platforms such as Saviynt, SailPoint, Okta, EmpowerID, or similar technologies
- Strong troubleshooting and root cause analysis skills in complex production environments
- Experience with identity lifecycle management, access provisioning, deprovisioning, and governance processes
- Experience developing or supporting integrations utilizing REST APIs, SOAP services, JDBC connections, or similar technologies
- Working knowledge of Active Directory, Entra ID, and enterprise authentication and authorization concepts
- Experience with scripting or development technologies such as JavaScript, PowerShell, Python, Java, or similar languages
- Experience working within change control, peer review, and production support processes
- Strong written and verbal communication skills
- Ability to work independently while effectively collaborating with cross-functional teams
Preferred Qualifications
- Hands-on experience with Saviynt Enterprise Identity Cloud (EIC)
- Experience integrating IAM platforms with Oracle Cloud, Oracle ERP, Oracle EBS, SAP, or similar enterprise systems
- Experience with access certifications, role engineering, entitlement management, and Segregation of Duties controls
- Experience with SAML, OAuth, OpenID Connect (OIDC), MFA, and Single Sign-On technologies
- Experience supporting or integrating with Privileged Access Management (PAM) platforms such as Delinea, CyberArk, BeyondTrust, or similar solutions
- Experience automating operational processes and improving platform observability
- Familiarity with cloud identity and hybrid identity architectures
- Security certifications such as CISSP, CISM, Security+, SSCP, or related credentials
- Saviynt certifications or formal Saviynt implementation experience
What This Role Is
- A senior hands-on engineering role with ownership of a critical enterprise IAM platform
- A position responsible for balancing operational excellence, governance maturity, and engineering improvements
- A role that influences IAM architecture and strategy while remaining deeply involved in technical implementation
- A key contributor to the growth and maturity of Milwaukee Tool's IAM capabilities
What This Role Is Not
- Not a pure IAM architect position
- Not a policy-only or compliance-only role
- Not a ticket-processing role without engineering responsibilities
- Not a position that avoids operational ownership
- Not a role requiring direction for every task or decision
We provide these great perks and benefits:
- Robust health, dental and vision insurance plans
- Generous 401 (K) savings plan
- Education assistance
- On-site wellness, fitness center, food, and coffee service
- And many more, check out our benefits site HERE.
Milwaukee Tool is an equal opportunity employer.