Logo
Kentro Estelle iLab

Senior IGA Engineer - (TS/SCI)

Kentro Estelle iLab, Tampa, Florida, us, 33646

Save Job

Thank you for considering IT Concepts dba Kentro, where innovation drives opportunity and collaboration leads to success. Our dynamic community of experts is fully committed to advancing our customers' missions, fostering professional growth, and making a positive impact on our communities.

By joining our supportive community, you will find that Kentro is dedicated to your personal and professional development. Together, we can drive meaningful change, spark innovation, and achieve extraordinary milestones.

Job Summary We are seeking a highly skilled

Identity Governance and Administration (IGA) Engineer

to join the Zero Trust execution team at U.S. Special Operations Command (USSOCOM). In a Zero Trust architecture, identity is the new perimeter, and this role is responsible for building and maintaining the "source of truth" that governs access to the Command's most critical data.

Responsibilities

SailPoint Architecture & Configuration: Lead the design, deployment, and ongoing management of SailPoint IdentityNow (or IIQ) to automate the full identity lifecycle (Joiner, Mover, Leaver) across hybrid and on‑premises environments.

ABAC Attribute Management: Define and manage the schema for "Trust Attributes" (e.g., Clearance, COI, Project Codes) within SailPoint, ensuring they align with the NIST 8112 metadata standard for consumption by policy decision points.

Air‑Gapped Identity Operations: Manage the offline instance of SailPoint on the Top‑Secret network, developing the workflows to import "Attribute Manifests" and ensure that identity data remains synchronized with the low‑side source of truth.

Access Certification: Configure and execute automated access certification campaigns for critical data repositories and privileged roles, ensuring compliance with DoD audit requirements.

Role Modeling: Work with mission owners to define Technical Roles and Business Roles within SailPoint, replacing broad, static Active Directory groups with granular, policy‑driven access roles.

Location Onsite in Tampa, FL

Qualifications

Master's degree (MA/MS)

10+ years of relevant experience

Extensive SailPoint expertise (5+ years) designing, implementing, and administering SailPoint (IdentityNow or IdentityIQ) in a large enterprise environment.

Deep understanding of the Joiner‑Mover‑Leaver (JML) process and experience automating provisioning/deprovisioning workflows linked to HR systems and Active Directory.

Strong knowledge of Active Directory, LDAP, and Azure Active Directory (Entra ID) structures and management.

Proven experience with Role‑Based Access Control (RBAC) modeling, Separation of Duties (SoD) policy creation, and access certification campaigns.

Preferred Experience & Skills ("Nice‑to‑Haves")

Experience implementing Attribute‑Based Access Control (ABAC) strategies.

Familiarity with DoD Identity, Credential, and Access Management (ICAM) reference designs.

Knowledge of integration protocols such as REST, SCIM, and SOAP.

Experience supporting USSOCOM or other DoD agencies.

Certifications

Required: CompTIA Security+ CE (or higher) to meet DoD 8570 IAT Level II requirements.

Preferred: SailPoint Certified IdentityNow Engineer or SailPoint Certified IdentityIQ Engineer.

Preferred: Certified Identity and Access Manager (CIAM) or CISA.

Clearance

Active Top‑Secret clearance with SCI eligibility.

Benefits We offer a competitive benefits package including paid time off, healthcare benefits, supplemental benefits, 401(k) with employer match, discount perks, rewards, and more. Employees are eligible for education reimbursement for certifications, degrees, or professional development.

Equal Opportunity Employment & VEVRAA Kentro is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran, or any other status protected by applicable federal, state, or local law.

Kentro is strongly committed to compliance with VEVRAA and other applicable federal, state, and local laws governing equal employment opportunity. Our policies and procedures ensure hiring practices align with these requirements.

We encourage protected veterans to self‑identify during the application process. This information is strictly confidential and will only be used for reporting and compliance purposes as required by law. Providing this information is voluntary and will not impact your employment eligibility.

How to Apply To apply, please click the "Apply for this Job" button at the bottom of this Job Description or the button at the top: "Application." Upload your resume and complete all application steps. If you need alternative application methods, please email careers@kentro.us and request assistance.

Accommodations To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions. If you need to discuss reasonable accommodations, please email careers@kentro.us.

#J-18808-Ljbffr