Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead IAM Provisioning Engineer- SailPoint/ CyberArk/ PKI / Entra ID

$89.3k - $124k

The Nippon Telegraph and Telephone Corporation (NTT)

Req ID: 373979


NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.

We are currently seeking a Lead IAM Provisioning Engineer- SailPoint/ CyberArk/ PKI / Entra ID to join our team in Plano, Texas (US-TX), United States (US).

Prior to Applying, please review and comply accordingly:

** Must be a US citizen or Green card holder to proceed with applying.

**Please carefully review the job requirements and pay transparency details below prior to applying

This SailPoint-Focused L3 Senior User Provisioning Engineer is a technical leader for identity lifecycle, entitlement engineering, and privileged access across enterprise IGA/PAM and cloud identity platforms. This role owns complex SailPoint and CyberArk integrations, designs Entra ID identity flows, manages PKI and certificate automation, and drives reliability, auditability, and automation across provisioning processes. The L3 engineer resolves escalated incidents, leads root-cause remediation, and mentors L2/L1 staff.

Key Responsibilities
- Technical ownership of user lifecycle and entitlement engineering across Active Directory, Entra ID, SaaS apps, and custom systems.- SailPoint IGA leadership: design, implement, and tune connectors, provisioning policies, role engineering, reconciliation, and certification campaigns.
- CyberArk PAM stewardship: onboard targets, manage vault policies, implement credential rotation, and support privileged session controls.
- PKI and certificate lifecycle: architect and operate certificate issuance, renewal, revocation, and automation for service identities and TLS endpoints.
- Cloud identity engineering: design Entra ID conditional access, cross-tenant syncs, and entitlement models; coordinate with AWS/GCP IAM as needed.
- Automation and infrastructure as code: develop and maintain SCIM/SAML/OIDC connectors, PowerShell/Python scripts, and Terraform/IaC for repeatable provisioning patterns.
- Incident response and RCA: lead Tier-3 troubleshooting for provisioning failures, perform root-cause analysis, implement permanent fixes, and reduce recurrence.
- Governance and audit readiness: lead access reviews, entitlement remediation, evidence collection, and support external/internal audits.
- Mentorship and documentation: create runbooks, operational playbooks, and train L1/L2 engineers to improve throughput and reduce manual errors.

Required Qualifications:
- 5+ years of hands-on IAM experience with progressive responsibility in provisioning and identity engineering.
- Proven, practical experience with SailPoint (IGA) and CyberArk (PAM) implementations.
- Deep operational knowledge of Entra ID / Azure AD and identity synchronization patterns.
- Strong understanding of PKI concepts and hands-on certificate management.
- Proficient with identity protocols: SCIM, SAML, OAuth/OIDC, MFA.
- Advanced scripting and automation skills: PowerShell, Python, Bash; experience with Terraform or CloudFormation.
- Experience with ITSM/ticketing tools (ServiceNow, Jira) and SLA management.
- Demonstrated ability to perform complex troubleshooting and deliver durable engineering fixes.

Preferred Qualifications
- Experience integrating HR systems (Workday, SuccessFactors) with IGA.
- Familiarity with Kubernetes RBAC, secrets management (Vault, Key Vault), and DevSecOps CI/CD integration.
- Certifications: SailPoint, CyberArk, Microsoft Identity/Entra, CISSP, or equivalent.
Soft Skills and Logistics
- Analytical and detail oriented with strong problem-solving and RCA discipline.
- Effective communicator able to influence engineering, security, and business stakeholders.
- Proven mentor and team player who improves operational maturity.
- Employment type: Full-time or contract. Location: Remote / Hybrid / On-site. Reports to: IAM Operations or Security Architecture Lead.

Where required by law, NTT DATA provides a reasonable range of compensation for specific roles. The starting pay range for this remote role is $89,300 - $124,000. This range reflects the minimum and maximum target compensation for the position across all US locations. Actual compensation will depend on a number of factors, including the candidate's actual work location, relevant experience, technical skills, and other qualifications.

This position may also be eligible for incentive compensation based on individual and/or company performance.


This position is eligible for company benefits including medical, dental, and vision insurance with an employer contribution, flexible spending or health savings account, life and AD&D insurance, short and long term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally-required benefits.

About NTT DATA

NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D.

Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client's needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use @nttdata.com and @talent.nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form,

NTT DATA endeavors to make accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here. If you'd like more information on your EEO rights under the law, please click here. For Pay Transparency information, please click here.
Vacancy posted 22 hours ago
Similar jobs that could be interesting for youBased on the Lead IAM Provisioning Engineer- SailPoint/ CyberArk/ PKI / Entra ID in Plano, TX vacancy
  •  ...Zimmermann Company is looking for a CIAM/IAM Engineer in McKinney, TX. You will lead customer identity and access...  ...initiatives. This role requires expertise in SailPoint Identity Security Cloud, Active Directory, and Microsoft Entra ID. Candidates should have a minimum of... 
    Suggested

    Yoh, A Day & Zimmermann Company

    Mckinney, TX
    1 day ago
  •  ...Services LLC is seeking a Senior Cybersecurity Staff Engineer -- CIAM Consultant to lead initiatives in Customer Identity and Access...  ...customer-facing applications. A robust understanding of SailPoint and Microsoft Entra ID is essential. #J-18808-Ljbffr Tixy Services LLC
    Suggested
    2 days per week
    3 days per week

    Tixy Services LLC

    Mckinney, TX
    5 days ago
  • $89.3k - $124k

     ...Req ID:  373979   NTT DATA...  ...seeking a Sailpoint IDN Engineer - Hybrid in...  ...Senior User Provisioning Engineer is...  ...SailPoint and CyberArk integrations, designs Entra ID identity...  ...flows, manages PKI and...  ...incidents, leads root‑cause remediation...  ...AWS/GCP IAM as needed.... 
    Suggested
    Permanent employment
    Full time
    Contract work
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT America

    Plano, TX
    6 hours ago
  • $130k - $178k

     ...Identity & Access Management Engineer to create solutions around Cyber...  ...Risk needs, focusing on the SailPoint IdentityNow implementation in...  ...and troubleshooting CyberArk issues. The ideal candidate will...  ...will have a minimum of 7 years IAM experience, coupled with a Bachelor... 
    Suggested

    loanDepot

    Plano, TX
    3 days ago
  •  ...Services LLC in McKinney, Texas is seeking a CIAM/IAM Engineer with extensive hands-on experience in Customer Identity and Access Management, SailPoint Identity Security Cloud, and Microsoft Entra ID. The role involves leading identity initiatives, supporting end-user... 
    Suggested

    Yoh Services LLC

    Mckinney, TX
    2 days ago
  •  ...Identity And Access Management Engineer, Lead Collaborative. Respectful...  ..., and management of IAM solutions, focusing on security...  ...in IAM lifecycle management, provisioning, and access governance concepts...  ...IAM certifications (e.g., SailPoint Certified Identity IQ Engineer... 

    Toyota Motor Sales, U.S.A., Inc.

    Plano, TX
    4 days ago
  •  ...Toyota is growing and leading the future of mobility...  ...Management Operations Engineer, Lead Location: Plano,...  ...hands-on expertise in SailPoint (IIQ/ISC) and Okta/Auth...  ...tools such as Delinea or CyberArk, and Okta Workforce SSO...  ...Engineering teams Ensure IAM solutions are designed... 
    Relocation package

    Toyota North America

    Plano, TX
    5 days ago
  •  ...IAM Governance Engineer At Cogent Infotech, we believe in creating...  ...Governance (IGA) and lead our transition to a...  ...Key Infrastructure (PKI), managing internal Certificate...  ...-prem) and Microsoft Entra ID (Azure AD), ensuring...  ...IGA platforms (e.g., SailPoint, Saviynt, or similar... 
    For contractors
    Immediate start

    Cogent Info

    Plano, TX
    1 day ago
  •  ...About Us Perfict Global is a leading IT consulting services...  ...areas: Identity Governance SailPoint Identity Lifecycle (JML)...  ...least 10+ years of experience in IAM; 7+ years of experience in...  ...and 5+ years of experience in CyberArk • Experience in integrating... 

    Perfict Global, Inc.

    Plano, TX
    5 days ago
  • $130k - $178k

     ...Identity & Access Management Engineer, you will be engineering solutions...  ...helping them address our SailPoint IdentityNow implementation....  ...Workday and Azure AD. The Sr. IAM Engineer must have expertise...  ...Design and implementation of CyberArk solutions, including Enterprise... 

    loanDepot

    Plano, TX
    4 days ago
  •  ...financial industry. As a Lead Architect for IAM at JPMorgan Chase within...  ..., and process engineering. Excellent collaboration...  ...technologies, including SailPoint, Microsoft Entra ID, ForgeRock, PingIdentity...  ...Gateways, Active Directory, CyberArk, Delinea, and Hashi Corp... 

    JPMorgan Chase & Co.

    Plano, TX
    2 days ago
  •  ...Responsibilities Automate IAM processes and application integrations using SailPoint IdentityNow workflows, SCIM API,...  ...efficiency and reduce manual provisioning overhead. Develop and deploy...  ...Authentication, PAM tools, AWS IAM, Azure Entra. ~4+ years of experience with... 
    Immediate start
    Day shift

    Texas Capital Bank

    Richardson, TX
    3 days ago
  • A leading technology firm is seeking a SailPoint Developer responsible for the installation and deployment of SailPoint Identity/IQ solutions. The ideal candidate...  ...degree and 4+ years of IT experience, particularly in IAM and SailPoint. You will work closely with... 
    Full time

    Infosys

    Richardson, TX
    3 days ago
  • Artech L.L.C. in Plano, Texas is looking for a skilled professional in Identity and Access Management (IAM). The candidate should have hands-on experience with SailPoint IdentityIQ (IIQ) and/or SailPoint IdentityNow (IDN) and be proficient in debugging and resolving... 

    Artech L.L.C.

    Plano, TX
    3 days ago
  •  ...Job Description Senior IAM Engineer Direct Hire Location: Plano 75093 Schedule...  ...requirements, with a primary focus on our SailPoint IdentityNow deployment. This role...  ...integrating SailPoint IdentityNow with CyberArk, Azure AD, ServiceNow, and developing APIs... 

    The Intersect Group

    Plano, TX
    4 days ago
  • $147.25k - $225k

     ...achievers. As a Senior Lead Cybersecurity...  ...and Access Management (IAM) solutions across multi...  ...expertise in cloud identity provisioning, role management,...  ...EntraID, Ping, ForgeRock, CyberArk, Hashicorp Vault, and...  ...junior architects and engineers. Equal Opportunity Employer... 

    慨正橡扯

    Plano, TX
    2 days ago
  • $93.5k - $156.45k

    PepsiCo is looking for a PKI Engineer based in Plano, TX. This hands-on role encompasses end-to-end ownership of enterprise PKI platforms, managing operational support, and driving PKI design and engineering initiatives. Candidates should possess a Bachelor's degree in... 

    PepsiCo

    Plano, TX
    4 days ago
  •  ...Opportunities: System Engineer- Identity (11250) Requisition ID 11250 -Posted -...  ...Summary The IAM & PAM Engineer...  ...entitlements, provisioning and de-...  ...environments. Lead in the documentation...  ...Preferably skills with SailPoint, Okta, and a...  ...as Delinea, CyberArk and BeyondTrust... 
    Work at office
    Local area

    Universal Cable Holdings Inc

    Plano, TX
    2 days ago
  • Engineering Leader - Identity and Access Management Location(s) Koch Technology...  ...Leader, Identity & Access Management (IAM) to lead and develop a team of Identity...  ...enterprise identity platforms such as Entra ID (Azure AD), Ping, SailPoint, Okta, or similar. Working... 
    Work at office
    Flexible hours

    Koch

    Plano, TX
    2 days ago
  •  ...Job Title- GCP IAM Engineer Location- Plano, TX 75093 Reporting Type- Onsite Work Timing- Regular Hours Monday...  ...applications in a regulated environment. The role focuses on provisioning IAM roles, managing service accounts, automating access... 
    Local area
    Monday to Friday

    campus4tech

    Plano, TX
    2 days ago
  •  ...Toyota is growing and leading the future of...  ...Management (PAM) Engineer Plano, TX Who...  ...Access Management (IAM) services. You’ll...  ...Centrify, Delinea, CyberArk etc, ~ Familiarity...  ..., Account provisioning, and access governance...  ...Experience with SailPoint . Experience with... 
    Work at office
    Remote work

    Toyota

    Plano, TX
    4 days ago
  • $111.53k - $146.74k

     ...Active Directory & Identity Engineer will serve as the...  ...Identity Governance (IGA) and lead our transition to a...  ...design for enterprise IAM solutions, ensuring all...  ...Key Infrastructure (PKI), managing internal Certificate...  ...on-prem) and Microsoft Entra ID (Azure AD), ensuring... 
    For contractors
    Immediate start

    North Texas Tollway Authority

    Plano, TX
    1 day ago
  • $70 - $75 per hour

    # Sr. IAM EngineerApply**Job#: 3035103****Job Description:**Sr. IAM Engineer**Location:** Plano, Texas (Onsite) **Employment Type:** ContractRole OverviewWe are seeking...  ...including how access is requested, approved, provisioned, governed, and revoked.* Think through the... 
    Hourly pay
    Contract work

    Apex Systems

    Plano, TX
    1 day ago
  •  ...Management (PAM) Engineer role helps create...  ...team to ensure all IAM solutions meet risk...  ...related breaches, leading rapid response efforts...  ..., Delinea, or CyberArk. Familiarity with...  ...scripting, account provisioning, and access governance...  .... Experience with SailPoint. Experience with... 
    Flexible hours

    TCC Toyota Motor Credit Corporation Company

    Plano, TX
    4 days ago
  •  ...Req ID: 135506  Region: Americas  Country: USA  State/Province: Texas  City:...  ...General Overview Functional Area: Engineering         Career Stream: Design - Software...  ...Indirect Indicator: Indirect Summary The Lead Network and Security Compliance Test... 
    Work experience placement

    Celestica

    Richardson, TX
    4 days ago
  • Koch is looking for an Engineering Leader for Identity and Access Management (IAM) based in Plano, TX. The ideal candidate will lead a team of Identity Engineers responsible for secure identity capabilities across the enterprise. In this role, you will focus on building... 

    Koch

    Plano, TX
    2 days ago
  • Optimum in Plano, Texas is seeking a Manager of Identity Engineering responsible for evolving and scaling IAM and PAM platforms. This senior leadership role focuses on driving future-state identity capabilities and partnering with security, architecture, and platform teams... 

    Optimum

    Plano, TX
    2 days ago
  •  ...detection and incident response in the fast-paced FinTech sector. The ideal candidate will have over 5 years in SIEM/SOAR and expertise in IAM within regulated environments, ensuring effective production support and compliance with bank regulations. This role requires on-site... 
    Shift work
    Weekend work
    3 days per week

    Bank of America

    Plano, TX
    2 days ago
  • Infosys is seeking for a SailPoint Developer. This candidate is responsible...  ...The SailPoint Implementation Engineer will require a strong...  ...Identity Access Management (IAM), and Access Governance/SailPoint...  ..., access certifications, and provisioning. Preferred Qualifications:... 
    Full time
    Temporary work
    Relocation

    Infosys

    Richardson, TX
    3 days ago
  • A leading financial services firm is seeking a Lead Technical Program Manager to drive IAM initiatives. This role requires expertise in managing complex technology projects, strong stakeholder management skills, and a proven track record in delivering high-impact results... 

    JPMorgan Chase & Co.

    Plano, TX
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead IAM Provisioning Engineer- SailPoint/ CyberArk/ PKI / Entra ID. Be the first to apply!