Back to Jobs
Stony Brook University

Identity Management Engineer

Stony Brook University
US-NY-Stony BrookFull TimeSenior140k–180k USDPosted Today
Identity Management Engineer


 

Required Degree/Qualifications: (as evidenced by an attached resume):
Bachelor’s Degree. In lieu of the Bachelor's degree, a combination of directly related full-time experience supporting Identity and Access Management services and education totaling nine [9] ​years may be considered. Five [5]+ years of dedicated experience in Identity and Access Management (IAM). Experience working with Identity Governance and Administration (IGA). Experience administering and configuring SailPoint Identity Security Cloud (ISC), SailPoint IIQ, Saviynt or similar platforms; including managing identity profiles, access profiles, roles, and transforms. Experience developing programming code. Experience with key identity management and access concepts and principles such as least privilege, privileged access, segregation of duties, role-based access control (RBAC), authentication, authorization, and user lifecycle workflows (Joiner/Mover/Leaver). Experience with IAM technologies and infrastructure, such as single sign-on (SSO), directory federation, SAML, OAuth, multi-factor authentication, user provisioning and self-service, account creation, and management; entitlement review certification and management; enterprise directory architecture and design, and onboarding applications.

Preferred Qualifications:
Advanced Degree. Familiarity with SailPoint Non-Employee Risk Management (NERM) for managing the lifecycle of contractors, guests, researchers, and vendors. Experience configuring and deploying self-service Access Request portals and designing Access Certification (user access review) campaigns. An active cyber security or other relevant certification, such as CISSP, CISM, or IDM-specific. Experience onboarding applications and integrating disparate systems using REST APIs, SCIM, JSON, and web services. Experience programming/scripting experience in PL/SQL, Powershell, Linux shell, Java, and/or Perl, Python, JavaScript. Experience working with identity management within a complex University or Medical Center environment. Experience gathering requirements, document workflows (Standard Operating Procedures, runbooks), and translating business needs into technical IAM rules. Experience developing technical and administrative documentation and diagrams. Familiarity with regulations and frameworks such as HIPAA, FERPA, NIST, GDPR, etc. Experience managing complex "multi-persona" identities unique to universities (e.g., users transitioning between student, staff, adjunct faculty, and alumni) and familiarity compliance regulations and frameworks such as FERPA HIPAA, NIST, GDPR, etc.

Brief Description of Duties/Primary Purpose:
The Identity Management Engineer is tasked with implementing, maintaining, extending, and troubleshooting the university’s identity management platform and associated technologies. This position is also expected to drive user adoption and educate stakeholders on the value of identity governance. The Identity Management Engineer must have the ability to communicate with others effectively.

Duties:

Implement and Maintain Identity Management Systems: Implement and develop technologies and processes to enable stable and secure enterprise-wide identity management (IDM) functions. This includes provisioning new user accounts, establishing unique credentials, de-provisioning accounts, self-service password management, and integrating directories and databases for authentication and authorization services. Implement third-party IDM systems and assist in migrating legacy systems to new technologies. Collaborate with vendors and consultants to install, configure, integrate, and test new systems, and upgrade existing ones. Design and maintain custom applications used for IDM functions. Monitor system performance, apply patches, update system configuration, and identify address security vulnerabilities.

Integrating Identity Solutions and Data Analysis/Mapping: Integrate IDM solutions with existing systems, applications, and directories, ensuring seamless interoperability and data synchronization across the organization's IT ecosystem. Oversee data integrity by ensuring authoritative sources and target systems are integrated, with identity data normalized and reliable.

Identity Lifecycle and Access Management: Implement technology and processes for managing the lifecycle of digital identities, including user provisioning, de-provisioning, role-based access control (RBAC), and recertification campaigns to ensure efficient governance and compliance. Work closely with service owners to ensure the identity management platform integrates seamlessly with Single Sign-On (SSO) and modern protocols such as OAuth, SAML, and OpenID Connect, streamlining user authentication and access across multiple applications and platforms.

Ensuring Data Security: Implement and enforce robust security measures, such as multi-factor authentication (MFA), encryption, and least privilege access controls, to protect sensitive identity-related data and mitigate the risk of unauthorized access or data breaches. Establish monitoring and auditing mechanisms to detect security incidents, track user activity, and assess the effectiveness of IDM controls, supporting continuous improvement and compliance validation. Ensure that systems and procedures adhere to security best practices and comply with all relevant university policies regarding information security, change management, and communications.

Collaborating with Stakeholders and Support: Collaborate with cross-functional teams, including IT, security, compliance, and business units, to gather requirements, assess technical feasibility, and ensure alignment with business objectives. Assist end-users and IT support staff with access-related issues, providing high-quality customer service at all times.

Documentation and Diagrams: Fully document implementation and configuration details, ensuring alignment with regulatory requirements and industry best practices while addressing organizational security and compliance needs.

Other duties or projects as assigned as appropriate to rank and department mission.

Special Notes:
This is a full-time appointment. FLSA Exempt position, not eligible for the overtime provisions of the FLSA. Minimum salary threshold must be met to maintain FLSA exemption.

SUNY implemented a hybrid telecommuting pilot program. This position has been approved to participate in the pilot, which allows for up to 5 remote days per pay period.

For this position, we are unable to sponsor candidates for work visas.

Resume/CV and cover letter should be included with the online application.

Stony Brook University is committed to excellence in diversity and the creation of an inclusive learning, and working environment. All qualified applicants will receive consideration for employment without regard to race, color, national origin, religion, sex, pregnancy, familial status, sexual orientation, gender identity or expression, age, disability, genetic information, veteran status and all other protected classes under federal or state laws.

If you need a disability-related accommodation, please call the university Office of Equity and Access (OEA) at (631) 632-6280 or visit OEA.

In accordance with the Title II Crime Awareness and Security Act a copy of our crime statistics can be viewed here.

Visit our WHY WORK HERE page to learn about the total rewards we offer.

 

 


 

 

 Job Number: 2602463Official Job Title: Supervising Programmer/AnalystJob Field: Information TechnologyPrimary Location: US-NY-Stony BrookDepartment/Hiring Area: Division of Information Technology - Information SecuritySchedule: Full-time Shift :Day Shift Shift Hours: 8:30AM - 5PM  Posting Start Date: Jul 28, 2026Posting End Date: Aug 11, 2026, 3:59:00 AMSalary:140,000 - 180,000Appointment Type: TermSalary Grade:SL5SBU Area:Stony Brook University
Ready to apply? You'll be taken to Stony Brook University's application page.