ITproposal logo

IAM Engineer – SailPoint IdentityIQ (RBAC / ABAC / PBAC / OPA) 10928982

ITproposal
1 day ago
Full-time
On-site
Eindhoven, 06

JobsCloseBy Editorial Insights

An experienced IAM Engineer with deep IGA expertise and hands on SailPoint IdentityIQ is needed to own end to end onboarding, workflow development and policy implementation for a large enterprise in Eindhoven on a 6 month ASAP contract with hybrid onsite work. The role focuses on RBAC ABAC and PBAC, OPAL/OPA policy engines, and Identity Lifecycle Management within an Agile DevOps environment. Expect 7+ years in IAM, strong SailPoint development, and proven integration skills with LDAP, REST/SOAP, SCIM, databases, SAP, Workday and Okta, plus CI/CD. To apply, tailor your CV to SailPoint wins, quantify onboarding outcomes, show policy and workflow design, and highlight stakeholder consultancy.


IAM Engineer – SailPoint IdentityIQ (RBAC / ABAC / PBAC / OPA)

Eindhoven, Netherlands Start Date: ASAP Contract Duration: 6 Months Requirement ID: 10928982 Status: Open

About the Role

We are looking for a highly skilled IAM Engineer with deep expertise in Identity Governance & Administration (IGA) and hands-on development experience in SailPoint IdentityIQ. This role is ideal for a senior engineer who excels in stakeholder interaction, understands complex IAM requirements, and can deliver secure, scalable onboarding solutions across a large enterprise landscape.

You will be responsible for end-to-end application onboarding, workflow development, policy implementation, and integration validation—ensuring compliance with security frameworks, RBAC/ABAC/PBAC models, and Identity Lifecycle Management processes.

Key Responsibilities

  • Validate and implement functional and non-functional requirements for onboarding business applications into the IAM solution.
  • Align with architecture teams on OPAL managed-service deployment, integration design, and target solution implementation.
  • Configure technical application onboarding using standard IAM functionality, IAM architectural principles, and company IAM strategy.
  • Own the end-to-end onboarding process from intake to acceptance.
  • Drive standardization and automation, leveraging shared CI/CD pipelines with the SailPoint platform team.
  • Actively participate in Scrum / SAFe ceremonies and collaborate within an Agile DevOps environment.
  • Design and validate Workflows, Rules, Policies, and Forms within SailPoint IdentityIQ.
  • Implement and validate RBAC, ABAC, and PBAC access control frameworks.
  • Support Certification Processes, enforcement activities, and entitlement/authorization management.
  • Validate integrations with LDAP, REST/SOAP, SCIM, databases, SaaS apps (Okta), Workday, SAP Suite, and other downstream systems.
  • Perform operational support for Identity Lifecycle Management (Joiner, Mover, Leaver).
  • Monitor progress, prepare timely status reports, identify risks/dependencies, and escalate issues proactively.
  • Collaborate with application owners, technical teams, integration teams, and external vendors.

Must-Have Skills & Experience

  • 7+ years professional experience in Identity Access Management (IAM).
  • Strong hands-on development experience with SailPoint IdentityIQ.
  • Deep knowledge of IGA, onboarding patterns, and IAM best practices.
  • Experience with OPA (Open Policy Agent), OPAL, or similar policy engines (highly preferred).
  • Proven experience implementing RBAC, ABAC, PBAC frameworks.
  • Strong experience designing complex workflows, rules, policies, and forms.
  • Experience with application onboarding into SailPoint.
  • Solid understanding of Identity Lifecycle Management processes.
  • Experience with CI/CD automation, DevOps ways of working, and Agile/SAFe environments.
  • Strong communication and consultancy skills for stakeholder interaction.
  • Knowledge of security technologies, policy frameworks, and entitlement/authorization management.

Good-to-Have Skills

  • Scripting/programming experience: Java, Beanshell, JavaScript
  • Integration experience with:

    • LDAP
    • REST/SOAP
    • SCIM
    • Databases
    • SaaS apps (Okta)
    • Workday
    • SAP Suite
  • Experience with CI/CD pipelines, Azure, Linux servers

Location

Eindhoven, Netherlands (TNDL – Eindhoven) Hybrid/Onsite depending on project needs.

Who Should Apply?

Senior IAM Engineers who:

  • Have deep SailPoint IdentityIQ development experience
  • Understand enterprise IAM architectures and policy engines
  • Can manage complex onboarding and integration activities
  • Thrive in Agile/SAFe environments
  • Communicate clearly with stakeholders and technical teams
  • Are available ASAP