Sailpoint & Entra ID Consultant OUTSIDE IR35 at Costello & Reyes Group Limited, Home & site (once a month), 6 Months, £500-£550 per day

£500 - £550 per day

Contract Description

Costello & Reyes Group Limited have been engaged by its client a global defence firm to identify a SailPoint Consultant/Engineer - Design & Delivery who holds current SC level Clearance.

Role Overview

We are seeking an experienced SC Cleared SailPoint Consultant to take a leading, hands-on role in the design, configuration, implementation and delivery of SailPoint Identity Governance and Administration (IGA) capabilities within a secure enterprise environment.

This is not purely an architecture or advisory position. The successful consultant must be capable of taking requirements from initial discovery and solution design through to hands-on configuration, integration, testing, deployment and transition into operational service.

The consultant will work closely with Security, IAM, Infrastructure, Application, Service Management and business stakeholders to translate identity and access management requirements into practical SailPoint solutions.

The role requires someone who can operate independently, challenge requirements where appropriate, identify technical and operational dependencies, and ultimately design what is required and then build and deliver it.

Key Responsibilities

MUST BE SC CLEARED

SailPoint Solution Design

Lead the discovery and assessment of existing Identity and Access Management processes, technologies, applications and identity sources.

Translate business, security, regulatory and technical requirements into detailed SailPoint solution designs.

Design scalable and supportable Identity Governance and Administration capabilities covering the complete identity life cycle.

Produce high-level and detailed technical designs, including integration patterns, workflows, data flows, identity models and security controls.

Define appropriate identity attributes, authoritative sources, correlation logic and identity profiles.

Design Joiner, Mover and Leaver (JML) processes and associated automated provisioning/de-provisioning workflows.

Design access request, approval, certification and governance processes.

Define Role-Based Access Control (RBAC) and where appropriate, Attribute-Based Access Control (ABAC) approaches.

Design role models, access profiles, entitlements and associated governance structures.

Define Segregation of Duties (SoD) policies and controls.

Design privileged and high-risk access governance processes and integration with PAM capabilities where applicable.

Ensure designs align with organisational security architecture, IAM strategy and relevant regulatory requirements.

Hands-On SailPoint Implementation

The consultant must be comfortable undertaking the implementation themselves rather than operating solely in an advisory capacity.

Responsibilities will include:

Configure and implement SailPoint solutions in accordance with agreed designs.

Configure identity profiles, life cycle states and identity processing.

Build and configure application/source integrations and connectors.

Configure account aggregation and identity correlation.

Configure entitlement aggregation and governance.

Implement provisioning and de-provisioning processes.

Develop Joiner, Mover and Leaver workflows.

Configure access request and approval workflows.

Configure access certifications and periodic access reviews.

Implement role and access-profile structures.

Configure policy and Segregation of Duties controls.

Configure notifications, escalations and approval processes.

Develop appropriate customisation where standard functionality does not meet requirements.

Troubleshoot SailPoint configuration, connector and integration issues.

Support migration of configurations through Development, Test, UAT and Production environments.

Integration

Design and deliver integrations between SailPoint and enterprise systems including, as applicable:

Microsoft Active Directory

Microsoft Entra ID/Azure AD

Microsoft 365

LDAP directories

HR/HCM platforms

ServiceNow

Privileged Access Management platforms

Databases

Enterprise applications

SaaS platforms

Cloud environments

REST APIs and web services

Bespoke and Legacy applications

The consultant should be capable of determining the most appropriate integration approach, including use of standard connectors, APIs or custom integrations.

SailPoint Development & Technical Capability

Depending upon the SailPoint platform and client environment, the consultant should have strong practical capability across relevant technologies, potentially including:

SailPoint IdentityIQ and/or SailPoint Identity Security Cloud

Java

BeanShell

PowerShell

REST APIs

JSON

XML

SQL

Web services

OAuth/modern authentication mechanisms

Active Directory and LDAP

Microsoft Entra ID

Git and appropriate source-control practices

Experience developing or modifying SailPoint rules, workflows, connectors and integration components is highly desirable.

Identity Governance

The consultant will be expected to provide practical expertise across the wider IGA life cycle, including:

Identity life cycle management

Joiner, Mover and Leaver processes

Birthright access

Access requests

Access approvals

Automated provisioning

Automated de-provisioning

Access certification and recertification

Role management

Entitlement management

Segregation of Duties

Orphaned and dormant accounts

Privileged access governance

Non-human/service identities

Contractor and third-party identities

Identity reconciliation

Policy enforcement

Access analytics and reporting

Testing & Assurance

Develop appropriate test strategies and test cases for SailPoint implementations.

Perform technical, integration and functional testing.

Support System Integration Testing and User Acceptance Testing.

Validate provisioning and de-provisioning processes across integrated systems.

Validate identity correlation and aggregation processes.

Test negative and exception scenarios, including failed provisioning and reconciliation.

Validate role, entitlement and SoD configurations.

Support defect identification, investigation and remediation.

Ensure sufficient evidence is retained to demonstrate successful implementation and control operation.

Documentation

Produce and maintain appropriate project and operational documentation, including:

High-Level Designs

Low-Level Designs

Solution Architecture documentation

Integration designs

Identity and entitlement models

Configuration documentation

Data-flow diagrams

Workflow documentation

Connector specifications

Test plans and evidence

Deployment and rollback plans

Operational runbooks

Troubleshooting guides

Support documentation

Knowledge-transfer materials

Documentation must be sufficiently detailed to enable the solution to be supported and enhanced following transition into BAU.

Deployment & Transition to Service

Support or lead SailPoint deployment into production.

Develop deployment, implementation and rollback plans.

Work with Change and Service Management functions to ensure controlled production releases.

Support Early Life Support following deployment.

Diagnose and resolve production issues where required.

Transfer knowledge to internal IAM and support teams.

Ensure appropriate monitoring, alerting and operational procedures are established.

Identify outstanding risks, technical debt and future improvement opportunities before transition into BAU.

Security & Compliance

The consultant will be expected to ensure that SailPoint solutions support the organisation's broader security and compliance requirements, including:

Least privilege

Need-to-know access

Separation of duties

Privileged access controls

Timely removal of access

Periodic access certification

Auditability

Traceability of approvals and changes

Appropriate logging and monitoring

Secure integration and credential management

The consultant should understand how effective IGA contributes to wider Zero Trust and Identity Security principles.

Stakeholder Engagement

The role will require engagement with a broad range of technical and non-technical stakeholders, including:

IAM and Cyber Security teams

Security Architects

Enterprise Architects

Infrastructure teams

Application Owners

Business Process Owners

Service Management

Risk and Compliance

Internal Audit

Third-party suppliers

Project and Programme Management

The consultant must be capable of explaining complex identity and SailPoint concepts clearly to both technical and non-technical audiences.

Essential Experience

Candidates should demonstrate:

Significant hands-on SailPoint implementation experience.

Strong experience with SailPoint IdentityIQ and/or SailPoint Identity Security Cloud, depending upon the client environment.

Proven ability to design and implement SailPoint solutions rather than specialising solely in architecture, advisory or support.

Experience delivering SailPoint solutions through the complete implementation life cycle.

Strong understanding of Identity Governance and Administration principles.

Practical experience implementing Joiner, Mover and Leaver processes.

Experience configuring access requests, approvals and certification campaigns.

Experience with identity aggregation, correlation, provisioning and reconciliation.

Experience integrating SailPoint with enterprise applications and identity sources.

Experience designing and implementing roles, access profiles and entitlement structures.

Strong troubleshooting and problem-solving capability.

Experience operating within structured enterprise change and release processes.

Strong documentation skills.

Ability to work independently and take ownership of technical delivery.

Highly Desirable Experience

Experience in one or more of the following would be advantageous:

SailPoint IdentityIQ

SailPoint Identity Security Cloud

SailPoint IdentityNow

Microsoft Entra ID

Active Directory

Privileged Access Management

CyberArk

ServiceNow

Microsoft Azure

AWS

HR-driven identity life cycle management

Non-human identity governance

Complex application onboarding

Legacy application integration

API-based integration

RBAC design and role engineering

Segregation of Duties

Identity security transformation programmes

Migration from Legacy IAM/IGA platforms

Large-scale SailPoint implementations

Highly regulated or security-sensitive environments

Relevant SailPoint certifications would also be advantageous.

Security Clearance

Active UK Security Check (SC) clearance is required -

Candidates must be capable of operating within the security and information-handling requirements applicable to an SC-cleared environment.

Where required by the engagement, candidates may also need to work from secure client locations and comply with restrictions relating to remote working, equipment and access to client systems.

Personal Attributes

We are looking for someone who is:

Technically strong and genuinely hands-on.

Comfortable moving between architecture, engineering and delivery activities.

Able to take ownership of a requirement from initial discovery through to production implementation.

Pragmatic and delivery focused.

Capable of working with incomplete or evolving requirements.

Able to challenge proposed approaches constructively.

Security conscious and comfortable operating within controlled environments.

Able to communicate effectively with senior stakeholders and technical specialists.

Methodical in documentation, testing and implementation.

Comfortable diagnosing complex integration and identity-management issues.

What Good Looks Like

The successful consultant will not simply produce a SailPoint design and hand it to another team.

They will be able to:

Understand the requirement - design the solution - configure/build it - integrate it - test it - deploy it - troubleshoot it - document it - transition it into operational service.

The key requirement is therefore a strong SailPoint practitioner combining solution design/architecture capability with demonstrable hands-on engineering and delivery experience.

Candidate Screening Priorities

Particular emphasis should be placed on establishing that candidates can demonstrate:

1. Current active SC clearance.

2. Recent hands-on SailPoint delivery experience.

3. End-to-end SailPoint solution design capability.

4. Practical configuration, development and integration experience.

5. Delivery of JML, provisioning, certification and access-governance capabilities.

6. Complex application onboarding and connector/integration experience.

7. Ability to troubleshoot and resolve implementation issues personally.

8. Experience taking SailPoint solutions through testing and into production.

9. Strong documentation and knowledge-transfer capability.

10. Evidence that they are genuinely a Design + Build consultant rather than solely a SailPoint Architect or SailPoint BA.

This is an immediate requirement so should you feel you have the relevant experience, please do submit your profile and contact for further details.

Costello & Reyes Group Limited act as a recruitment partner to its clients.