JobRaahGet matched free

Jobs

Senior Identity & Access Management Engineer

greatamerica · Cedar Rapids, IA · United States · On-site

Posted Sep 10, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

GreatAmerica is a highly successful entrepreneurial company providing equipment financing to businesses across the United States. Our exemplary customer service, our principle-centered business philosophy and our team-based operating approach are key to our success and growth. We have also recently become a bank! We are looking to add a key member to our Identity & Access Management Team! The Senior Identity & Access Management (IAM) Engineer is responsible for designing, implementing, and continuously enhancing GreatAmerica's identity governance, access management, and privileged access capabilities. This role serves as a senior technical specialist, ensuring identity and access controls are secure, scalable, automated, and aligned with regulatory, audit, and risk management requirements. Working across SailPoint, CyberArk, Okta, and related technologies, the Senior IAM Engineer develops and maintains enterprise identity lifecycle processes, role-based access controls, privileged access solutions, and authentication services. The role partners closely with Security, Audit, Compliance, Infrastructure, and Application teams to translate security and control requirements into effective technical solutions while advancing automation, operational efficiency, and governance maturity. The Senior IAM Engineer plays a key role in strengthening GreatAmerica's identity security program by improving access governance, supporting regulatory compliance, reducing access-related risk, and ensuring the reliability and effectiveness of identity services across the organization. As a Senior IAM Engineer, you will: Build and maintain automated identity lifecycle workflows, certification campaigns, and connectors within SailPoint IdentityNow, including connector development and integration with enterprise applications (ServiceNow, ILS). Design, build, and roll out role-based access control (RBAC) models, including role mining, role engineering, and ongoing role lifecycle governance. Integrate and administer Okta as the enterprise identity provider, including single sign-on (SSO), multi-factor authentication (MFA), and lifecycle management through SCIM provisioning. Implement and support CyberArk privileged access management (PAM), including credential vaulting, session isolation and monitoring, just-in-time (JIT) elevation policy administration, elimination of standing privileges, and privileged account onboarding. Support the migration from self-hosted CyberArk PAS to CyberArk Privilege Cloud, report and integration transition, and updates to operational procedures. Develop self-service and automated access request workflows spanning request intake, approval routing, and fulfillment. Automate joiner, mover, and leaver (JML) provisioning and deprovisioning processes across enterprise systems to ensure timely and accurate access changes. Execute recurring access certification campaigns and quarterly configuration reviews (privileged…