Senior Identity Engineer at Palyrian

We are redirecting you to the source. If you are not redirected in 3 seconds, please click here.

Senior Identity Engineer at Palyrian. . Location: United States. The Role. . Palyrian is building a team of Senior Identity Engineers who can walk into a live environment and be productive without ramp-up. You have four or more years of hands-on SailPoint delivery, you have shipped real identity work, and you are trusted to make design calls when an architect is not in the room.. . The distinction we draw at this level is ownership of a workstream rather than a ticket. On a large program there are several concurrent workstreams — application onboarding, custom workflow implementation, RBAC maturity, etc. — and a senior engineer owns one end to end: reviewing the junior engineers’ designand connector work, keeping solutions maintainable, and designing the localized pieces of a process without escalating every question upward. Engineers who consistently do that last part are on the path to the architect track.. . We also want engineers who want to broaden. Palyrian works across SailPoint, Oasis, Veza, and C1 (formerly ConductorOne), and non-human identity is where a lot of the new work is heading. If you have been single threaded on one platform and want out of that, this is the right kind of move.. . About Palyrian. . Palyrian is an identity services boutique founded in 2024 by three practitioners who spent years building and running enterprise identity programs together. The firm exists on a simple premise: most IAM programs have the right tools, but few have the right people. Palyrian brings the quality of a large firm with the speed of a small one, and its vision is to be the most trusted identity services boutique in the market: a focused firm clients return to because the work holds up, not because of a contract.. . Palyrian works across SailPoint (IdentityIQ and Identity Security Cloud), Oasis, Veza, and C1. The team treats identity as a system, not a stack of tools, and favors fixing what a client already owns before recommending something new. It is a boutique that runs like a tech startup: small, fast, and light on process.                                                  . . What You Will Do. . . Lead the technical portion of product health checks and platform architecture reviews: assess configuration, code quality, performance, and coverage, and produce actionable. . Contribute grounded, hands-on input to future-state architecture and tool evaluations identifying  what these platforms actually do, not what the marketing materials. . Translate assessment findings into scoped, sequenced engineering plans that can be executed.. . Own a workstream end to end on a client program, including its scope, quality, and delivery.. . Design and build custom SailPoint IIQ and/or ISC solutions: connectors, workflows, rules, transforms, provisioning policies, etc.. . Design the localized pieces of a process. For example, the full sequence of events and approvals when an employee goes on extended leave and returns without needing an architect to specify it for you.. . Run App Factory delivery: help define onboarding patterns, build reusable templates and automation, and implement various connectors.. . Integrate with enterprise systems (Active Directory and Entra ID, HR platforms, ServiceNow, cloud platforms, custom applications) through web services, JDBC, or other types of connectors.. . Review other engineers' application design and connector build-out. Own code review, testing strategy, and whether it is maintainable.. . Mentor junior engineers through pairing, review, and direct feedback.. . Manage and improve access certification campaigns, reporting, and program analytics.. . Drive configuration, tuning, and automation improvements so operational effort falls over time.. . Lead knowledge transfer so client teams can own more of their own platform.. . . What You Bring. . . 4+ years of hands-on SailPoint IdentityIQ and/or Identity Security Cloud experience, including at least two full implementation or major upgrade cycles.. . 6+ years overall in identity and access management or enterprise software engineering.. . Strong Java and BeanShell for IIQ, and/or transforms, cloud rules, and REST API development for ISC. Comfortable with SQL, XML, and at least one other scripting language.. . Deep working knowledge of identity governance: joiner-mover-leaver, role and attribute-based access, certifications, segregation of duties, and provisioning.. . Demonstrated ability to own a workstream and make design decisions within it, rather than working exclusively from someone else’s specification.. . The ability to work directly with client stakeholders, explain technical decisions in plain language, and manage expectations in a live environment.. . A focus on understanding the problem rather than producing syntax. Writing code is the part of this job that is getting easier; knowing what should be built is not.. . Evidence that you build or learn outside of work; a side project, a home lab, something recent you taught yourself.. . S. based and authorized to work in the United States.. . . Nice to Have. . . Experience across both IdentityIQ and Identity Security Cloud, including IIQ-to-ISC migration.. . SailPoint certification (Certified IdentityIQ Engineer and/or Certified Identity Security Engineer). If you are not certified but can demonstrate equivalent delivery depth, tell us. We will look at the work first and sort out credentials. . Exposure to non-human identity, machine identity, or secrets platforms (Oasis, C1, HashiCorp Vault, or comparable). This is where a growing share of Palyrian’s work is heading.. . Experience with adjacent identity domains or IGA products: PAM (CyberArk, Delinea, BeyondTrust), IGA (Saviynt, Veza), or IdP and authentication platforms (Okta, Entra ID, Ping).. . Identity protocol fluency: SAML, OAuth 2.0, OIDC, SCIM.. . Regulated industry experience and the audit and compliance expectations that come with it.. . CI/CD and infrastructure automation applied to identity platform deployments.. . . A Note on Certifications. . Certifications help us find you and help clients trust the team, and Palyrian sponsors them. They are not how we decide whether you can do the job.    . . Who Thrives Here. . Palyrian is a boutique that runs like a tech startup. Identity must be your thing. The team lives by four principles:. . . Builder's Mindset. . When you see a better way, you build it. Problems don’t come with answers attached.. . Own the Outcome. . You are accountable for whether the client’s program improves, not just whether the ticket closed.. . Always Be Learning. . Identity changes fast, and non-human identity changes faster. You keep pace and bring what you learn back to the team.. . Prideful Excellence. . Work that holds up after we leave. Clients return because of the quality, not the contract.. . . If you have spent the last few years going deeper into a single platform and have started to feel the walls, that is a good reason to talk to us rather than a reason not to.. . Hiring Process. . . An introductory screening.. . A technical interview with Palyrian. Expect roughly 30 minutes of systems-thinking and scenario questions rather than a live coding exercise. This is the first real gate.. . A behavioral and culture conversation with one of the founders.. . . Two interviews, and we try to keep them inside a single hour where we can. We would rather move quickly than run you through a gauntlet.. . Benefits. . . Remote-first, U.S. based. Flexible hours, with client time zones taking priority when an engagement calls for it.. . 20 days of paid time off, granted as a bucket rather than accrued, plus holidays.. . Medical, dental, and vision coverage through Aetna.. . 401(k) with company match: full match on the first 3% and half match on the next 2%.. . Annual performance-based bonus eligbility.. . Sponsored training and certifications, including platform-specific enablement.. . Direct client work, real ownership, and a seat at a boutique early enough that your work shapes the firm..