Charles Schwab

Charles Schwab

Sr Identity & Access Governance (IGA) Engineer (Sailpoint)

Phoenix, AZ, US · Senior

Sponsorship not specifiedDetected 31 days ago
PythonJavaRESTOAuthMachine LearningData EngineeringCybersecuritySOC OperationsComplianceAgileJiraLeadershipCommunicationCollaborationProblem SolvingOrganizational Skills

About the role

  • We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location(s).
  • In Schwab Cybersecurity Services (SCS), Office of CISO, we provide platforms, services, and security operations capabilities which enable the firm to produce successful client and shareholder outcomes securely and safely.

Responsibilities

  • Serve as a Senior Identity Governance & Administration (IGA) Engineer, owning the design, implementation, automation, and operational maturity of enterprise IGA solutions across on‑prem and cloud environments.
  • Lead the delivery of IGA solutions (e.g., SailPoint and other enterprise cloud based IGA platforms), supporting identity lifecycle (Joiner/Mover/Leaver), access requests, certifications, and policy enforcement.
  • Drive IGA automation and AI readiness, leveraging workflow automation, event‑driven integrations, and analytics to reduce manual operations, improve access accuracy, and scale identity governance.
  • Act as a technical authority and design partner to Security Architecture, IAM Governance, Infrastructure, and Application teams to define end‑to‑end identity and access solutions.
  • Design and implement complex integrations with applications, data platforms, AI services, and infrastructure using REST APIs, connectors, SCIM, flat files, and event messaging.
  • Develop and maintain custom IGA extensions including rules, workflows, transforms, and integrations using Java, BeanShell, Python, and scripting technologies.
  • Lead access model design and optimization, including RBAC/ABAC strategies, entitlement consolidation, token bloat reduction, and least‑privilege enforcement.
  • Partner with audit, risk, and compliance teams to ensure alignment with security controls and regulatory requirements (e.g., SOX, SOC), proactively identifying and remediating gaps.
  • Collaborate with Scrum Masters, Product Owners, and Project Managers to deliver solutions through Agile / SAFe execution models from design through production.
  • Provide cross‑IAM support and guidance, collaborating with teams responsible for LDAP, Active Directory, SSO/federation, and Privileged Access Management (PAM) tools.

Requirements

  • Your Opportunity At Schwab, you are empowered to make an impact on your career.

Nice to have

  • Security or IAM certifications such as CISSP, CISM, SailPoint certification, or equivalent.
  • Experience integrating IGA with Privileged Access Management (PAM) solutions.
  • Exposure to governing access to AI/ML platforms, data pipelines, or automation services.
  • RBAC/ABAC, SoD, least privilege, entitlement lifecycle management, and access certification frameworks.
  • Experience driving automation and AI‑enabled capabilities within IAM or security platforms (analytics, recommendation engines, workflow optimization).
  • Working knowledge of cloud identity architectures and standards (SCIM, OAuth2, OIDC, SAML).
  • Experience operating in Agile / SAFe environments, with proficiency in tools such as Jira and Confluence.
  • Strong ability to translate business, security, compliance, and AI platform requirements into scalable IGA technical solutions.

This listing is sourced directly from Charles Schwab's careers page and normalized into a canonical job model.