Skip to content

Open nowPosted yesterday

Sr IAM Security Engineer

tti180 open roles

Where
Menomonee Falls, WI
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSr IAM Security Engineertti · Menomonee Falls, WI
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on tti's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. tti postings stay open a median of 4 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted yesterday

tti median: 4 days open

The posting

Job Description:

**Applicants must be authorized to work in the U.S.; Sponsorship is not available for this position.

** This role can be Remote, Hybrid or Onsite

We are looking for a Senior IAM Security Engineer to own, operate, and continuously improve our Saviynt-based Identity Governance and Administration (IGA) platform. This role is ideal for an engineer who enjoys solving complex identity challenges, leading production support efforts, designing scalable integrations, and improving identity governance capabilities across the enterprise.

You will serve as the primary technical owner of our Saviynt implementation, ensuring reliable identity lifecycle management, access governance, and integration with enterprise systems including Oracle, Active Directory, Entra ID, and other critical business applications. This role balances hands-on engineering, operational ownership, governance maturity, and technical leadership.

Our IAM program is continuing to mature and expand. This role will play a critical part in improving platform reliability, reducing manual effort, strengthening governance controls, and enabling future identity initiatives and broader enterprise security capabilities.

Core Responsibilities:

Operate and Own IAM Services (Primary)

  • Own day-to-day operation, support, and reliability of the Saviynt platform
  • Troubleshoot and resolve provisioning, deprovisioning, reconciliation, and identity lifecycle failures across Oracle, Active Directory, Entra ID, and integrated applications
  • Serve as the primary escalation point for IAM operational incidents and complex access issues
  • Perform root cause analysis and implement long-term corrective actions to prevent recurring issues
  • Monitor platform health, job execution, provisioning success rates, and service performance
  • Develop and maintain operational runbooks, support documentation, and knowledge articles
  • Participate in production support processes, change control, peer reviews, and CAB activities

Engineer IAM Integrations and Platform Capabilities

  • Design, build, enhance, and support Saviynt connectors, workflows, rules, policies, analytics, and certifications
  • Develop and maintain integrations utilizing REST APIs, SOAP services, JDBC connections, and other enterprise integration methods
  • Partner with application teams to onboard new applications and automate identity lifecycle processes
  • Support Oracle Cloud, Oracle ERP, Active Directory, Entra ID, and other enterprise identity integrations
  • Lead testing, validation, deployment, and upgrade activities for IAM platform enhancements
  • Ensure IAM solutions are scalable, maintainable, and aligned with enterprise security requirements

Advance Identity Governance Capabilities

  • Support and improve Joiner, Mover, Leaver (JML) lifecycle processes
  • Implement and maintain access request workflows, approval processes, and entitlement management
  • Design, execute, and improve access certification campaigns and remediation activities
  • Contribute to role-based and attribute-based access models (RBAC/ABAC)
  • Support Segregation of Duties (SoD) controls, governance policies, and audit requirements
  • Assist with identity correlation, reconciliation, entitlement cleanup, and governance optimization efforts

Reduce Toil and Improve the Platform

  • Identify manual processes and develop automation solutions to improve efficiency and reliability
  • Improve platform observability, monitoring, reporting, and operational metrics
  • Develop dashboards and reporting that provide insight into platform health and governance effectiveness
  • Improve testing practices, deployment processes, and operational maturity
  • Drive continuous improvement initiatives focused on scalability, reliability, and user experience

Provide Technical Leadership and Ownership

  • Serve as the technical lead for IAM engagements involving application teams and business stakeholders
  • Guide technical design discussions and recommend IAM best practices
  • Conduct peer reviews and contribute to engineering standards and reusable implementation patterns
  • Mentor junior engineers and share knowledge across the IAM team
  • Communicate technical concepts, risks, and recommendations clearly to both technical and non-technical audiences
  • Balance security, operational stability, business requirements, and delivery timelines pragmatically

Collaborate Across Security Domains

  • Partner with Infrastructure, Security Operations, Cloud, and Application teams to deliver integrated identity solutions
  • Support identity-related security incidents and remediation activities when required
  • Contribute to IAM strategy, roadmap discussions, and future platform enhancements
  • Assist with evaluation and adoption of new IAM technologies and capabilities

Required Qualifications

  • 5+ years of hands-on experience in Identity and Access Management, Information Security, Platform Engineering, or related technical disciplines
  • 3+ years of experience delivering Identity Governance and Administration (IGA) capabilities
  • Experience administering and supporting enterprise IAM platforms such as Saviynt, SailPoint, Okta, EmpowerID, or similar technologies
  • Strong troubleshooting and root cause analysis skills in complex production environments
  • Experience with identity lifecycle management, access provisioning, deprovisioning, and governance processes
  • Experience developing or supporting integrations utilizing REST APIs, SOAP services, JDBC connections, or similar technologies
  • Working knowledge of Active Directory, Entra ID, and enterprise authentication and authorization concepts
  • Experience with scripting or development technologies such as JavaScript, PowerShell, Python, Java, or similar languages
  • Experience working within change control, peer review, and production support processes
  • Strong written and verbal communication skills
  • Ability to work independently while effectively collaborating with cross-functional teams

Preferred Qualifications

  • Hands-on experience with Saviynt Enterprise Identity Cloud (EIC)
  • Experience integrating IAM platforms with Oracle Cloud, Oracle ERP, Oracle EBS, SAP, or similar enterprise systems
  • Experience with access certifications, role engineering, entitlement management, and Segregation of Duties controls
  • Experience with SAML, OAuth, OpenID Connect (OIDC), MFA, and Single Sign-On technologies
  • Experience supporting or integrating with Privileged Access Management (PAM) platforms such as Delinea, CyberArk, BeyondTrust, or similar solutions
  • Experience automating operational processes and improving platform observability
  • Familiarity with cloud identity and hybrid identity architectures
  • Security certifications such as CISSP, CISM, Security+, SSCP, or related credentials
  • Saviynt certifications or formal Saviynt implementation experience

What This Role Is

  • A senior hands-on engineering role with ownership of a critical enterprise IAM platform
  • A position responsible for balancing operational excellence, governance maturity, and engineering improvements
  • A role that influences IAM architecture and strategy while remaining deeply involved in technical implementation
  • A key contributor to the growth and maturity of Milwaukee Tool's IAM capabilities

What This Role Is Not

  • Not a pure IAM architect position
  • Not a policy-only or compliance-only role
  • Not a ticket-processing role without engineering responsibilities
  • Not a position that avoids operational ownership
  • Not a role requiring direction for every task or decision

We provide these great perks and benefits:

  • Robust health, dental and vision insurance plans
  • Generous 401 (K) savings plan
  • Education assistance
  • On-site wellness, fitness center, food, and coffee service
  • And many more, check out our benefits site HERE.

Milwaukee Tool is an equal opportunity employer.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against tti's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on tti's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    tti's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.