Costello & Reyes Group Limited have been engaged by its client a global defence firm to identify a SailPoint Consultant/Engineer - Design & Delivery who holds current SC level Clearance.
Role Overview
We are seeking an experienced SC Cleared SailPoint Consultant to take a leading, hands-on role in the design, configuration, implementation and delivery of SailPoint Identity Governance and Administration (IGA) capabilities within a secure enterprise environment.
This is not purely an architecture or advisory position. The successful consultant must be capable of taking requirements from initial discovery and solution design through to hands-on configuration, integration, testing, deployment and transition into operational service.
The consultant will work closely with Security, IAM, Infrastructure, Application, Service Management and business stakeholders to translate identity and access management requirements into practical SailPoint solutions.
The role requires someone who can operate independently, challenge requirements where appropriate, identify technical and operational dependencies, and ultimately design what is required and then build and deliver it.
Key Responsibilities
MUST BE SC CLEARED
SailPoint Solution Design
Lead the discovery and assessment of existing Identity and Access Management processes, technologies, applications and identity sources.
Translate business, security, regulatory and technical requirements into detailed SailPoint solution designs.
Design scalable and supportable Identity Governance and Administration capabilities covering the complete identity life cycle.
Produce high-level and detailed technical designs, including integration patterns, workflows, data flows, identity models and security controls.
Define appropriate identity attributes, authoritative sources, correlation logic and identity profiles.
Design Joiner, Mover and Leaver (JML) processes and associated automated provisioning/de-provisioning workflows.
Design access request, approval, certification and governance processes.
Define Role-Based Access Control (RBAC) and where appropriate, Attribute-Based Access Control (ABAC) approaches.
Design role models, access profiles, entitlements and associated governance structures.
Define Segregation of Duties (SoD) policies and controls.
Design privileged and high-risk access governance processes and integration with PAM capabilities where applicable.
Ensure designs align with organisational security architecture, IAM strategy and relevant regulatory requirements.
Hands-On SailPoint Implementation
The consultant must be comfortable undertaking the implementation themselves rather than operating solely in an advisory capacity.
Responsibilities will include:
Configure and implement SailPoint solutions in accordance with agreed designs.
Configure identity profiles, life cycle states and identity processing.
Build and configure application/source integrations and connectors.
Configure account aggregation and identity correlation.
Configure entitlement aggregation and governance.
Implement provisioning and de-provisioning processes.
Develop Joiner, Mover and Leaver workflows.
Configure access request and approval workflows.
Configure access certifications and periodic access reviews.
Implement role and access-profile structures.
Configure policy and Segregation of Duties controls.
Configure notifications, escalations and approval processes.
Develop appropriate customisation where standard functionality does not meet requirements.
Troubleshoot SailPoint configuration, connector and integration issues.
Support migration of configurations through Development, Test, UAT and Production environments.
Integration
Design and deliver integrations between SailPoint and enterprise systems including, as applicable:
Microsoft Active Directory
Microsoft Entra ID/Azure AD
Microsoft 365
LDAP directories
HR/HCM platforms
ServiceNow
Privileged Access Management platforms
Databases
Enterprise applications
SaaS platforms
Cloud environments
REST APIs and web services
Bespoke and Legacy applications
The consultant should be capable of determining the most appropriate integration approach, including use of standard connectors, APIs or custom integrations.
SailPoint Development & Technical Capability
Depending upon the SailPoint platform and client environment, the consultant should have strong practical capability across relevant technologies, potentially including:
SailPoint IdentityIQ and/or SailPoint Identity Security Cloud
Java
BeanShell
PowerShell
REST APIs
JSON
XML
SQL
Web services
OAuth/modern authentication mechanisms
Active Directory and LDAP
Microsoft Entra ID
Git and appropriate source-control practices
Experience developing or modifying SailPoint rules, workflows, connectors and integration components is highly desirable.
Identity Governance
The consultant will be expected to provide practical expertise across the wider IGA life cycle, including:
Identity life cycle management
Joiner, Mover and Leaver processes
Birthright access
Access requests
Access approvals
Automated provisioning
Automated de-provisioning
Access certification and recertification
Role management
Entitlement management
Segregation of Duties
Orphaned and dormant accounts
Privileged access governance
Non-human/service identities
Contractor and third-party identities
Identity reconciliation
Policy enforcement
Access analytics and reporting
Testing & Assurance
Develop appropriate test strategies and test cases for SailPoint implementations.
Perform technical, integration and functional testing.
Support System Integration Testing and User Acceptance Testing.
Validate provisioning and de-provisioning processes across integrated systems.
Validate identity correlation and aggregation processes.
Test negative and exception scenarios, including failed provisioning and reconciliation.
Validate role, entitlement and SoD configurations.
Support defect identification, investigation and remediation.
Ensure sufficient evidence is retained to demonstrate successful implementation and control operation.
Documentation
Produce and maintain appropriate project and operational documentation, including:
High-Level Designs
Low-Level Designs
Solution Architecture documentation
Integration designs
Identity and entitlement models
Configuration documentation
Data-flow diagrams
Workflow documentation
Connector specifications
Test plans and evidence
Deployment and rollback plans
Operational runbooks
Troubleshooting guides
Support documentation
Knowledge-transfer materials
Documentation must be sufficiently detailed to enable the solution to be supported and enhanced following transition into BAU.
Deployment & Transition to Service
Support or lead SailPoint deployment into production.
Develop deployment, implementation and rollback plans.
Work with Change and Service Management functions to ensure controlled production releases.
Support Early Life Support following deployment.
Diagnose and resolve production issues where required.
Transfer knowledge to internal IAM and support teams.
Ensure appropriate monitoring, alerting and operational procedures are established.
Identify outstanding risks, technical debt and future improvement opportunities before transition into BAU.
Security & Compliance
The consultant will be expected to ensure that SailPoint solutions support the organisation's broader security and compliance requirements, including:
Least privilege
Need-to-know access
Separation of duties
Privileged access controls
Timely removal of access
Periodic access certification
Auditability
Traceability of approvals and changes
Appropriate logging and monitoring
Secure integration and credential management
The consultant should understand how effective IGA contributes to wider Zero Trust and Identity Security principles.
Stakeholder Engagement
The role will require engagement with a broad range of technical and non-technical stakeholders, including:
IAM and Cyber Security teams
Security Architects
Enterprise Architects
Infrastructure teams
Application Owners
Business Process Owners
Service Management
Risk and Compliance
Internal Audit
Third-party suppliers
Project and Programme Management
The consultant must be capable of explaining complex identity and SailPoint concepts clearly to both technical and non-technical audiences.
Essential Experience
Candidates should demonstrate:
Significant hands-on SailPoint implementation experience.
Strong experience with SailPoint IdentityIQ and/or SailPoint Identity Security Cloud, depending upon the client environment.
Proven ability to design and implement SailPoint solutions rather than specialising solely in architecture, advisory or support.
Experience delivering SailPoint solutions through the complete implementation life cycle.
Strong understanding of Identity Governance and Administration principles.
Practical experience implementing Joiner, Mover and Leaver processes.
Experience configuring access requests, approvals and certification campaigns.
Experience with identity aggregation, correlation, provisioning and reconciliation.
Experience integrating SailPoint with enterprise applications and identity sources.
Experience designing and implementing roles, access profiles and entitlement structures.
Strong troubleshooting and problem-solving capability.
Experience operating within structured enterprise change and release processes.
Strong documentation skills.
Ability to work independently and take ownership of technical delivery.
Highly Desirable Experience
Experience in one or more of the following would be advantageous:
SailPoint IdentityIQ
SailPoint Identity Security Cloud
SailPoint IdentityNow
Microsoft Entra ID
Active Directory
Privileged Access Management
CyberArk
ServiceNow
Microsoft Azure
AWS
HR-driven identity life cycle management
Non-human identity governance
Complex application onboarding
Legacy application integration
API-based integration
RBAC design and role engineering
Segregation of Duties
Identity security transformation programmes
Migration from Legacy IAM/IGA platforms
Large-scale SailPoint implementations
Highly regulated or security-sensitive environments
Relevant SailPoint certifications would also be advantageous.
Security Clearance
Active UK Security Check (SC) clearance is required -
Candidates must be capable of operating within the security and information-handling requirements applicable to an SC-cleared environment.
Where required by the engagement, candidates may also need to work from secure client locations and comply with restrictions relating to remote working, equipment and access to client systems.
Personal Attributes
We are looking for someone who is:
Technically strong and genuinely hands-on.
Comfortable moving between architecture, engineering and delivery activities.
Able to take ownership of a requirement from initial discovery through to production implementation.
Pragmatic and delivery focused.
Capable of working with incomplete or evolving requirements.
Able to challenge proposed approaches constructively.
Security conscious and comfortable operating within controlled environments.
Able to communicate effectively with senior stakeholders and technical specialists.
Methodical in documentation, testing and implementation.
Comfortable diagnosing complex integration and identity-management issues.
What Good Looks Like
The successful consultant will not simply produce a SailPoint design and hand it to another team.
They will be able to:
Understand the requirement - design the solution - configure/build it - integrate it - test it - deploy it - troubleshoot it - document it - transition it into operational service.
The key requirement is therefore a strong SailPoint practitioner combining solution design/architecture capability with demonstrable hands-on engineering and delivery experience.
Candidate Screening Priorities
Particular emphasis should be placed on establishing that candidates can demonstrate:
1. Current active SC clearance.
2. Recent hands-on SailPoint delivery experience.
3. End-to-end SailPoint solution design capability.
4. Practical configuration, development and integration experience.
5. Delivery of JML, provisioning, certification and access-governance capabilities.
6. Complex application onboarding and connector/integration experience.
7. Ability to troubleshoot and resolve implementation issues personally.
8. Experience taking SailPoint solutions through testing and into production.
9. Strong documentation and knowledge-transfer capability.
10. Evidence that they are genuinely a Design + Build consultant rather than solely a SailPoint Architect or SailPoint BA.
This is an immediate requirement so should you feel you have the relevant experience, please do submit your profile and contact for further details.
Costello & Reyes Group Limited act as a recruitment partner to its clients.
Outside Spy discovers all the Outside IR35 IT contract opportunities for members.