Logo for GreatAmerica Financial Services

Senior Identity & Access Management Engineer

Role overview

Qualifications

  • 5+ years of hands-on experience in Identity and Access Management engineering or administration roles.
  • 3+ years of direct, hands-on experience with SailPoint (IdentityIQ and/or IdentityNow).
  • Demonstrated experience designing and deploying RBAC models.
  • Strong PowerShell scripting and REST API experience for automation.

Responsibilities

  • Build and maintain automated identity lifecycle workflows and connectors within SailPoint.
  • Design, build, and roll out role-based access control (RBAC) models.
  • Integrate and administer Okta as the enterprise identity provider.
  • Implement and support CyberArk privileged access management.

Key facts

Hard skills

Other skills

  • Problem Solving
  • Collaboration

About the company

GreatAmerica Financial Services logo

GreatAmerica Financial Services

Financial Services

GreatAmerica is the largest, family-owned national commercial equipment finance company in the United States. A $3.3+ billion company with life-to-date finance originations of $18 billion, GreatAmerica was established in Cedar Rapids, Iowa in 1992. Dedicated to helping manufacturers, distributors, resellers, and franchisees be more successful and keep their customers for a lifetime, GreatAmerica offers innovative, complementary services in addition to financing. GreatAmerica is committed to the communities it serves and donates more than $1.1 million annually through a GreatAmerica Donor Advised Fund and an Employee Advised Fund, giving team members a say in where funds are allocated.

Company details

IndustryFinancial Services
Company size501 - 1000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

GreatAmerica Financial Services is a highly successful entrepreneurial company providing equipment financing to businesses across the United States. Our exemplary customer service, our principle-centered business philosophy and our team-based operating approach are key to our success and growth.

We are looking to add a key member to our Identity & Access Management Team!

The Senior Identity & Access Management (IAM) Engineer is responsible for designing, implementing, and continuously enhancing GreatAmerica's identity governance, access management, and privileged access capabilities. This role serves as a senior technical specialist, ensuring identity and access controls are secure, scalable, automated, and aligned with regulatory, audit, and risk management requirements.

Working across SailPoint, CyberArk, Okta, and related technologies, the Senior IAM Engineer develops and maintains enterprise identity lifecycle processes, role-based access controls, privileged access solutions, and authentication services. The role partners closely with Security, Audit, Compliance, Infrastructure, and Application teams to translate security and control requirements into effective technical solutions while advancing automation, operational efficiency, and governance maturity.

The Senior IAM Engineer plays a key role in strengthening GreatAmerica's identity security program by improving access governance, supporting regulatory compliance, reducing access-related risk, and ensuring the reliability and effectiveness of identity services across the organization.

As a Senior IAM Engineer, you will:

  • Build and maintain automated identity lifecycle workflows, certification campaigns, and connectors within SailPoint IdentityNow, including connector development and integration with enterprise applications (ServiceNow, ILS).

  • Design, build, and roll out role-based access control (RBAC) models, including role mining, role engineering, and ongoing role lifecycle governance.

  • Integrate and administer Okta as the enterprise identity provider, including single sign-on (SSO), multi-factor authentication (MFA), and lifecycle management through SCIM provisioning.

  • Implement and support CyberArk privileged access management (PAM), including credential vaulting, session isolation and monitoring, just-in-time (JIT) elevation policy administration, elimination of standing privileges, and privileged account onboarding.

  • Support the migration from self-hosted CyberArk PAS to CyberArk Privilege Cloud, report and integration transition, and updates to operational procedures.

  • Develop self-service and automated access request workflows spanning request intake, approval routing, and fulfillment.

  • Automate joiner, mover, and leaver (JML) provisioning and deprovisioning processes across enterprise systems to ensure timely and accurate access changes.

  • Execute recurring access certification campaigns and quarterly configuration reviews (privileged access, password and authentication settings), producing audit-ready evidence for ICFR logical access controls.

  • Support SOX-related access controls, segregation of duties (SoD) enforcement, and the generation of audit evidence for Internal Control over Financial Reporting (ICFR).

  • Develop PowerShell and REST API automation for entitlement extracts, reconciliation, reporting, and audit evidence generation.

  • Apply FFIEC IT examination handbook guidance to identity governance, access control design, and third-party access risk.

  • Partner with security, audit, compliance, and application teams to translate control requirements into engineered, testable technical solutions.

  • Troubleshoot, tune, and document IAM integrations and workflows to ensure reliability, performance, and auditability.

To be successful, you will need:

Required

  • 5+ years of hands-on experience in Identity and Access Management engineering or administration roles.

  • 3+ years of direct, hands-on experience with SailPoint (IdentityIQ and/or IdentityNow), including lifecycle workflows, certification campaigns, and connector development or integration.

  • Demonstrated experience designing and deploying RBAC models, including role mining, role engineering, and role lifecycle governance.

  • Working experience with CyberArk PAM, including vaulting, session isolation and monitoring, and privileged account onboarding.

  • Strong PowerShell scripting and REST API experience for automation, entitlement extracts, reconciliation, and audit evidence generation.

  • Proven ability to build access request automation covering requests, approvals, and fulfillment.

  • Experience automating JML provisioning and deprovisioning across multiple enterprise systems.

Preferred

  • Practical experience integrating and administering Okta as an identity provider, including SSO, MFA, and SCIM-based lifecycle provisioning (depth in two of SailPoint / CyberArk / Okta required; ability to develop depth in the third).

  • Experience in a financial services environment, with a solid understanding of the regulatory and control landscape applicable to banking or financial institutions.

  • Experience supporting ICFR and SOX access controls, including segregation of duties and audit evidence preparation.

  • Familiarity with FFIEC IT examination guidance as it relates to identity governance and logical access.

Education

  • Bachelor's degree with a major in cybersecurity, computer science or related field preferred, but not required. Information security experience may be substituted for requisite education.

Certifications

  • Preferred, not required: SailPoint Certified IdentityNow/IdentityIQ Engineer; CyberArk Defender or Sentry; Okta Certified Professional or Administrator; CISSP or equivalent.

Sharing rewards is an integral part of our culture. We believe in the value of hard work and reward our employees beyond the paycheck. Our total rewards package is based on eligibility and includes:

Financial Benefits

  • Competitive Compensation
  • Monthly Bonuses for Eligible Employees
  • 401(k) and Company Match
  • Annual Profit Sharing
  • Paid Time Off

Health, Wellbeing, and Family Planning Benefits

  • Paid Vacation - starting at 80 hours annually for employees in their first year of service.
  • Paid Sick Days - Ten (10) per year with a conversion option for unused time.
  • Ten (10) Paid Holidays per year
  • Gym Reimbursement
  • Health Insurance
  • Dental Insurance
  • Vision Insurance
  • Short-Term and Long Term Disability
  • Company Paid Life Insurance
  • Flexible Spending Accounts (FSA)
  • Health Savings Accounts (HSA)
  • Employee Assistance Program
  • Parental Leave

Education and Career Planning Benefits

  • Tuition Assistance
  • Networking Opportunities
  • Leadership Development Opportunities

Perks

  • Paid Parking
  • Service Awards
  • Hybrid work arrangements
  • Business casual environment
  • A strong organizational culture focused on our greatest asset: you!

If your experience aligns closely, please apply. We value diverse backgrounds and adding new perspectives. We encourage you to apply if you can make a strong impact in this role at www.greatamerica.com/careers.

Please note, applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment visa.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at GreatAmerica Financial Services

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.