In this role, you will:
- Role Engineering: Lead the full lifecycle of RBAC implementation, including the design, definition, and validation of Business Roles, IT Roles, and Organizational Roles within SailPoint IIQ.
- Role Mining & Analysis: Utilize IIQ's advanced features, including Role Mining and Entitlement Analysis, to identify, define, and consolidate access patterns across the enterprise landscape.
- Role Composition: Define the composition of Roles by mapping them to appropriate Access Profiles and Entitlements, ensuring accuracy and consistency across target applications.
- Stakeholder Collaboration: Work closely with Business Process Owners and Application Owners to gather requirements, validate role definitions, and ensure the access model accurately reflects current business functions.
- Custom Rule Development: Develop, test, and deploy custom Java and BeanShell rules, XML configuration, and custom workflows to meet complex RBAC requirements, including dynamic role assignment logic.
- Application Onboarding: Configure and deploy standard and custom Connectors (e.g., Active Directory, LDAP, JDBC, SAP) to onboard applications, accurately aggregating and correlating Identities and Entitlements for use in the role model.
- Provisioning: Implement automated Provisioning and De-provisioning logic based on Role assignment changes, ensuring that users gain and lose access efficiently as they join, move, or leave the organization.
- Certification (Attestation): Configure and execute various Certification Campaigns (e.g., Manager, Role Owner, Application Owner) based on the deployed Role Model to simplify and enforce periodic access reviews.
- Separation of Duties (SoD): Design, configure, and manage SoD Policies within IIQ, ensuring that conflicting role combinations are identified and flagged for review, and developing appropriate preventative controls.
- Reporting: Develop custom reports and dashboards to monitor Role Adoption, track Provisioning Success Rates, and demonstrate RBAC compliance for internal and external audits.
Work model:
We believe hybrid work is the way forward as we strive to provide flexibility wherever possible. Based on this role’s business requirements, this is a hybrid position requiring 2-3 days a week in a client or Cognizant office in Toronto, ON. Regardless of your working arrangement, we are here to support a healthy work-life balance though our various wellbeing programs.
What you need to have to be considered:
- 6+ Years of hands-on development and implementation experience with SailPoint IdentityIQ
- Deep expertise in Role-Based Access Control (RBAC) principles and the ability to apply them to an enterprise environment
- Proficiency in Java and BeanShell scripting for writing custom rules, policies, and workflows within the SailPoint framework
- Strong understanding of Identity Governance and Administration (IGA) concepts, including lifecycle management (Joiner, Mover, Leaver)
We're excited to meet people who share our mission and can make an impact in a variety of ways. Don't hesitate to apply, even if you only meet the minimum requirements listed. Think about your transferable experiences and unique skills that make you stand out as someone who can bring new and exciting things to this role.
#LI-EF1
#CB
#Ind123