JobsCloseBy Editorial Insights
An experienced IAM Engineer with deep IGA expertise and hands on SailPoint IdentityIQ is needed to own end to end onboarding, workflow development and policy implementation for a large enterprise in Eindhoven on a 6 month ASAP contract with hybrid onsite work. The role focuses on RBAC ABAC and PBAC, OPAL/OPA policy engines, and Identity Lifecycle Management within an Agile DevOps environment. Expect 7+ years in IAM, strong SailPoint development, and proven integration skills with LDAP, REST/SOAP, SCIM, databases, SAP, Workday and Okta, plus CI/CD. To apply, tailor your CV to SailPoint wins, quantify onboarding outcomes, show policy and workflow design, and highlight stakeholder consultancy.
IAM Engineer – SailPoint IdentityIQ (RBAC / ABAC / PBAC / OPA)
Eindhoven, Netherlands
Start Date: ASAP Contract Duration: 6 Months
Requirement ID: 10928982
Status: Open
About the Role
We are looking for a highly skilled IAM Engineer with deep expertise in Identity Governance & Administration (IGA) and hands-on development experience in SailPoint IdentityIQ. This role is ideal for a senior engineer who excels in stakeholder interaction, understands complex IAM requirements, and can deliver secure, scalable onboarding solutions across a large enterprise landscape.
You will be responsible for end-to-end application onboarding, workflow development, policy implementation, and integration validation—ensuring compliance with security frameworks, RBAC/ABAC/PBAC models, and Identity Lifecycle Management processes.
Key Responsibilities
- Validate and implement functional and non-functional requirements for onboarding business applications into the IAM solution.
- Align with architecture teams on OPAL managed-service deployment, integration design, and target solution implementation.
- Configure technical application onboarding using standard IAM functionality, IAM architectural principles, and company IAM strategy.
- Own the end-to-end onboarding process from intake to acceptance.
- Drive standardization and automation, leveraging shared CI/CD pipelines with the SailPoint platform team.
- Actively participate in Scrum / SAFe ceremonies and collaborate within an Agile DevOps environment.
- Design and validate Workflows, Rules, Policies, and Forms within SailPoint IdentityIQ.
- Implement and validate RBAC, ABAC, and PBAC access control frameworks.
- Support Certification Processes, enforcement activities, and entitlement/authorization management.
- Validate integrations with LDAP, REST/SOAP, SCIM, databases, SaaS apps (Okta), Workday, SAP Suite, and other downstream systems.
- Perform operational support for Identity Lifecycle Management (Joiner, Mover, Leaver).
- Monitor progress, prepare timely status reports, identify risks/dependencies, and escalate issues proactively.
- Collaborate with application owners, technical teams, integration teams, and external vendors.
Must-Have Skills & Experience
-
7+ years professional experience in Identity Access Management (IAM).
- Strong hands-on development experience with SailPoint IdentityIQ.
- Deep knowledge of IGA, onboarding patterns, and IAM best practices.
- Experience with OPA (Open Policy Agent), OPAL, or similar policy engines (highly preferred).
- Proven experience implementing RBAC, ABAC, PBAC frameworks.
- Strong experience designing complex workflows, rules, policies, and forms.
- Experience with application onboarding into SailPoint.
- Solid understanding of Identity Lifecycle Management processes.
- Experience with CI/CD automation, DevOps ways of working, and Agile/SAFe environments.
- Strong communication and consultancy skills for stakeholder interaction.
- Knowledge of security technologies, policy frameworks, and entitlement/authorization management.
Good-to-Have Skills
- Scripting/programming experience: Java, Beanshell, JavaScript
- Integration experience with:
- LDAP
- REST/SOAP
- SCIM
- Databases
- SaaS apps (Okta)
- Workday
- SAP Suite
- Experience with CI/CD pipelines, Azure, Linux servers
Location
Eindhoven, Netherlands (TNDL – Eindhoven)
Hybrid/Onsite depending on project needs.
Who Should Apply?
Senior IAM Engineers who:
- Have deep SailPoint IdentityIQ development experience
- Understand enterprise IAM architectures and policy engines
- Can manage complex onboarding and integration activities
- Thrive in Agile/SAFe environments
- Communicate clearly with stakeholders and technical teams
- Are available ASAP