×
Register Here to Apply for Jobs or Post Jobs. X

IGA Engineer; Sailpoint Journeyman

Job in Tampa, Hillsborough County, Florida, 33646, USA
Listing for: Kentro
Full Time position
Listed on 2026-02-16
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer
Salary/Wage Range or Industry Benchmark: 60000 USD Yearly USD 60000.00 YEAR
Job Description & How to Apply Below
Position: IGA Engineer (Sailpoint) Journeyman

Thank you for considering IT Concepts dba Kentro, where innovation drives opportunity and collaboration leads to success. Our dynamic community of experts is fully committed to advancing our customers' missions, fostering professional growth, and making a positive impact on our communities.

By joining our supportive community, you will find that Kentro is dedicated to your personal and professional development. Together, we can drive meaningful change, spark innovation, and achieve extraordinary milestones.

Kentro is hiring a highly skilled Identity Governance and Administration (IGA) Engineer to join the Zero Trust execution team at U.S. Special Operations Command (USSOCOM). In a Zero Trust architecture, identity is the new perimeter, and this role is responsible for building and maintaining the "source of truth" that governs access to the Command's most critical data.

As the IGA Engineer, you will lead the implementation and configuration of Sail Point across the NIPR, SIPR, and Top-Secret networks. You will move beyond basic account provisioning to implement a sophisticated Attribute-Based Access Control (ABAC) model. You will be responsible for defining and managing the lifecycle of "Trust Attributes" (such as clearance level, training status, and job role) that are consumed by downstream enforcement tools like Microsoft Purview and Kiteworks.

Your work ensures that when a user's status changes, their access to sensitive data is updated instantly—even in air-gapped environments.

Responsibilities
  • SailPoint Architecture & Configuration:
    Lead the design, deployment, and ongoing management of SailPoint Identity Now (or IIQ) to automate the full identity lifecycle (Joiner, Mover, Leaver) across hybrid and on-premises environments.
  • ABAC Attribute Management:
    Define and manage the schema for "Trust Attributes" (e.g., Clearance, COI, Project Codes) within SailPoint, ensuring they align with the NIST 8112 metadata standard for consumption by policy decision points.
  • Air-Gapped Identity Operations:
    Manage the offline instance of SailPoint on the Top-Secret network, developing the workflows to import "Attribute Manifests" and ensure that identity data remains synchronized with the low-side source of truth.
  • Access Certification:
    Configure and execute automated access certification campaigns for critical data repositories and privileged roles, ensuring compliance with DoD audit requirements.
  • Role Modeling:
    Work with mission owners to define Technical Roles and Business Roles within SailPoint, replacing broad, static Active Directory groups with granular, policy-driven access roles.
Requirements
  • SailPoint Expertise: Extensive (5+ years) hands-on experience designing, implementing, and administering SailPoint (Identity Now or Identity

    IQ) in a large enterprise environment.
  • Identity Lifecycle Management: Deep understanding of the Joiner-Mover-Leaver (JML) process and experience automating provisioning/deprovisioning workflows connected to HR systems and Active Directory.
  • Directory Services: Strong knowledge of Active Directory, LDAP, and Azure Active Directory (Entra ) structures and management.
  • Governance Principles: Proven experience with Role-Based Access Control (RBAC) modeling, Separation of Duties (SoD) policy creation, and access certification campaigns.
  • Education: BA/BS or MA/MS in a relevant field
  • Years Exp: 3-10 years in a relevant field
Preferred Experience & Skills ("Nice-to-Haves")
  • Experience implementing Attribute-Based Access Control (ABAC) strategies.
  • Familiarity with DoD Identity, Credential, and Access Management (ICAM) reference designs.
  • Knowledge of integration protocols such as REST, SCIM, and SOAP.
  • Experience supporting USSOCOM or other DoD agencies.
Certifications
  • Required:

    CompTIA Security+ CE (or higher) to meet DoD 8570 IAT Level II requirements.
  • Preferred:
    SailPoint Certified Identity Now Engineer or SailPoint Certified Identity

    IQ Engineer.
  • Preferred:
    Certified Identity and Access Manager (CIAM) or CISA.
Clearance Requirement
  • Active Top-Secret clearance with SCI eligibility.
Benefits

The Company:
We believe in generating success collaboratively, enabling long-term mission success, and building trust for the next challenge. With you as our partner, let's solve challenges, think innovatively, and maximize impact. We are a close community of experts that pride ourselves on creating an environment defined by teamwork, dedication, and excellence. We hold three ISO certifications (27001:2013, 20000-1:2011, 9001:2015), two CMMI ML 3 ratings (DEV and SVC) and CMMC Level 2 Certification.

Industry

Recognition & Culture

Growth | Inc 5000's Fastest Growing Private Companies, DC Metro List Fastest Growing;
Washington Business Journal:
Fastest Growing Companies, Top Performing Small Technology Companies in Greater D.C. Culture | Northern Virginia Technology Council Tech 100 Honoree;
Virginia Best Place to Work;
Washington Business Journal:
Best Places to Work, Corporate Diversity Index Winner - Mid-Size Companies, Companies Owned by…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary