Job Openings IAM Engineer – SailPoint IdentityIQ (RBAC / ABAC / PBAC / OPA) 10928982

About the job IAM Engineer – SailPoint IdentityIQ (RBAC / ABAC / PBAC / OPA) 10928982

IAM Engineer – SailPoint IdentityIQ (RBAC / ABAC / PBAC / OPA)

Eindhoven, Netherlands Start Date: ASAP Contract Duration: 6 Months Requirement ID: 10928982 Status: Open

About the Role

We are looking for a highly skilled IAM Engineer with deep expertise in Identity Governance & Administration (IGA) and hands-on development experience in SailPoint IdentityIQ. This role is ideal for a senior engineer who excels in stakeholder interaction, understands complex IAM requirements, and can deliver secure, scalable onboarding solutions across a large enterprise landscape.

You will be responsible for end-to-end application onboarding, workflow development, policy implementation, and integration validation—ensuring compliance with security frameworks, RBAC/ABAC/PBAC models, and Identity Lifecycle Management processes.

Key Responsibilities

  • Validate and implement functional and non-functional requirements for onboarding business applications into the IAM solution.
  • Align with architecture teams on OPAL managed-service deployment, integration design, and target solution implementation.
  • Configure technical application onboarding using standard IAM functionality, IAM architectural principles, and company IAM strategy.
  • Own the end-to-end onboarding process from intake to acceptance.
  • Drive standardization and automation, leveraging shared CI/CD pipelines with the SailPoint platform team.
  • Actively participate in Scrum / SAFe ceremonies and collaborate within an Agile DevOps environment.
  • Design and validate Workflows, Rules, Policies, and Forms within SailPoint IdentityIQ.
  • Implement and validate RBAC, ABAC, and PBAC access control frameworks.
  • Support Certification Processes, enforcement activities, and entitlement/authorization management.
  • Validate integrations with LDAP, REST/SOAP, SCIM, databases, SaaS apps (Okta), Workday, SAP Suite, and other downstream systems.
  • Perform operational support for Identity Lifecycle Management (Joiner, Mover, Leaver).
  • Monitor progress, prepare timely status reports, identify risks/dependencies, and escalate issues proactively.
  • Collaborate with application owners, technical teams, integration teams, and external vendors.

Must-Have Skills & Experience

  • 7+ years professional experience in Identity Access Management (IAM).
  • Strong hands-on development experience with SailPoint IdentityIQ.
  • Deep knowledge of IGA, onboarding patterns, and IAM best practices.
  • Experience with OPA (Open Policy Agent), OPAL, or similar policy engines (highly preferred).
  • Proven experience implementing RBAC, ABAC, PBAC frameworks.
  • Strong experience designing complex workflows, rules, policies, and forms.
  • Experience with application onboarding into SailPoint.
  • Solid understanding of Identity Lifecycle Management processes.
  • Experience with CI/CD automation, DevOps ways of working, and Agile/SAFe environments.
  • Strong communication and consultancy skills for stakeholder interaction.
  • Knowledge of security technologies, policy frameworks, and entitlement/authorization management.

Good-to-Have Skills

  • Scripting/programming experience: Java, Beanshell, JavaScript
  • Integration experience with:

    • LDAP
    • REST/SOAP
    • SCIM
    • Databases
    • SaaS apps (Okta)
    • Workday
    • SAP Suite
  • Experience with CI/CD pipelines, Azure, Linux servers

Location

Eindhoven, Netherlands (TNDL – Eindhoven) Hybrid/Onsite depending on project needs.

Who Should Apply?

Senior IAM Engineers who:

  • Have deep SailPoint IdentityIQ development experience
  • Understand enterprise IAM architectures and policy engines
  • Can manage complex onboarding and integration activities
  • Thrive in Agile/SAFe environments
  • Communicate clearly with stakeholders and technical teams
  • Are available ASAP