Charles Schwab
Sr Identity & Access Governance (IGA) Engineer (Sailpoint)
Phoenix, AZ, US · Senior
Sponsorship not specifiedDetected 31 days ago
PythonJavaRESTOAuthMachine LearningData EngineeringCybersecuritySOC OperationsComplianceAgileJiraLeadershipCommunicationCollaborationProblem SolvingOrganizational Skills
About the role
- We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location(s).
- In Schwab Cybersecurity Services (SCS), Office of CISO, we provide platforms, services, and security operations capabilities which enable the firm to produce successful client and shareholder outcomes securely and safely.
Responsibilities
- Serve as a Senior Identity Governance & Administration (IGA) Engineer, owning the design, implementation, automation, and operational maturity of enterprise IGA solutions across on‑prem and cloud environments.
- Lead the delivery of IGA solutions (e.g., SailPoint and other enterprise cloud based IGA platforms), supporting identity lifecycle (Joiner/Mover/Leaver), access requests, certifications, and policy enforcement.
- Drive IGA automation and AI readiness, leveraging workflow automation, event‑driven integrations, and analytics to reduce manual operations, improve access accuracy, and scale identity governance.
- Act as a technical authority and design partner to Security Architecture, IAM Governance, Infrastructure, and Application teams to define end‑to‑end identity and access solutions.
- Design and implement complex integrations with applications, data platforms, AI services, and infrastructure using REST APIs, connectors, SCIM, flat files, and event messaging.
- Develop and maintain custom IGA extensions including rules, workflows, transforms, and integrations using Java, BeanShell, Python, and scripting technologies.
- Lead access model design and optimization, including RBAC/ABAC strategies, entitlement consolidation, token bloat reduction, and least‑privilege enforcement.
- Partner with audit, risk, and compliance teams to ensure alignment with security controls and regulatory requirements (e.g., SOX, SOC), proactively identifying and remediating gaps.
- Collaborate with Scrum Masters, Product Owners, and Project Managers to deliver solutions through Agile / SAFe execution models from design through production.
- Provide cross‑IAM support and guidance, collaborating with teams responsible for LDAP, Active Directory, SSO/federation, and Privileged Access Management (PAM) tools.
Requirements
- Your Opportunity At Schwab, you are empowered to make an impact on your career.
Nice to have
- Security or IAM certifications such as CISSP, CISM, SailPoint certification, or equivalent.
- Experience integrating IGA with Privileged Access Management (PAM) solutions.
- Exposure to governing access to AI/ML platforms, data pipelines, or automation services.
- RBAC/ABAC, SoD, least privilege, entitlement lifecycle management, and access certification frameworks.
- Experience driving automation and AI‑enabled capabilities within IAM or security platforms (analytics, recommendation engines, workflow optimization).
- Working knowledge of cloud identity architectures and standards (SCIM, OAuth2, OIDC, SAML).
- Experience operating in Agile / SAFe environments, with proficiency in tools such as Jira and Confluence.
- Strong ability to translate business, security, compliance, and AI platform requirements into scalable IGA technical solutions.
Apply directly at Charles Schwab →Create a free account for alerts like thisView Charles Schwab immigration profile
This listing is sourced directly from Charles Schwab's careers page and normalized into a canonical job model.