Senior Identity Engineer @Palyrian
All Others
Salary unspecified
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 1wk ago

[Hiring] Senior Identity Engineer @Palyrian

1wk ago - Palyrian is hiring a remote Senior Identity Engineer. 💸 Salary: unspecified 📍Location: USA

Role Description

Palyrian is building a team of Senior Identity Engineers who can walk into a live environment and be productive without ramp-up. You have four or more years of hands-on SailPoint delivery, you have shipped real identity work, and you are trusted to make design calls when an architect is not in the room.

The distinction we draw at this level is ownership of a workstream rather than a ticket. On a large program there are several concurrent workstreams — application onboarding, custom workflow implementation, RBAC maturity, etc. — and a senior engineer owns one end to end:

  • Reviewing the junior engineers’ design and connector work.
  • Keeping solutions maintainable.
  • Designing the localized pieces of a process without escalating every question upward.

We also want engineers who want to broaden. Palyrian works across SailPoint, Oasis, Veza, and C1 (formerly ConductorOne), and non-human identity is where a lot of the new work is heading. If you have been single threaded on one platform and want out of that, this is the right kind of move.

What You Will Do

  • Lead the technical portion of product health checks and platform architecture reviews: assess configuration, code quality, performance, and coverage, and produce actionable insights.
  • Contribute grounded, hands-on input to future-state architecture and tool evaluations identifying what these platforms actually do, not what the marketing materials say.
  • Translate assessment findings into scoped, sequenced engineering plans that can be executed.
  • Own a workstream end to end on a client program, including its scope, quality, and delivery.
  • Design and build custom SailPoint IIQ and/or ISC solutions: connectors, workflows, rules, transforms, provisioning policies, etc.
  • Design the localized pieces of a process, such as the full sequence of events and approvals when an employee goes on extended leave and returns.
  • Run App Factory delivery: help define onboarding patterns, build reusable templates and automation, and implement various connectors.
  • Integrate with enterprise systems (Active Directory and Entra ID, HR platforms, ServiceNow, cloud platforms, custom applications) through web services, JDBC, or other types of connectors.
  • Review other engineers' application design and connector build-out. Own code review, testing strategy, and whether it is maintainable.
  • Mentor junior engineers through pairing, review, and direct feedback.
  • Manage and improve access certification campaigns, reporting, and program analytics.
  • Drive configuration, tuning, and automation improvements so operational effort falls over time.
  • Lead knowledge transfer so client teams can own more of their own platform.

Qualifications

  • 4+ years of hands-on SailPoint IdentityIQ and/or Identity Security Cloud experience, including at least two full implementation or major upgrade cycles.
  • 6+ years overall in identity and access management or enterprise software engineering.
  • Strong Java and BeanShell for IIQ, and/or transforms, cloud rules, and REST API development for ISC. Comfortable with SQL, XML, and at least one other scripting language.
  • Deep working knowledge of identity governance: joiner-mover-leaver, role and attribute-based access, certifications, segregation of duties, and provisioning.
  • Demonstrated ability to own a workstream and make design decisions within it, rather than working exclusively from someone else’s specification.
  • The ability to work directly with client stakeholders, explain technical decisions in plain language, and manage expectations in a live environment.
  • A focus on understanding the problem rather than producing syntax.
  • Evidence that you build or learn outside of work; a side project, a home lab, something recent you taught yourself.
  • U.S. based and authorized to work in the United States.

Nice to Have

  • Experience across both IdentityIQ and Identity Security Cloud, including IIQ-to-ISC migration.
  • SailPoint certification (Certified IdentityIQ Engineer and/or Certified Identity Security Engineer). If you are not certified but can demonstrate equivalent delivery depth, tell us.
  • Exposure to non-human identity, machine identity, or secrets platforms (Oasis, C1, HashiCorp Vault, or comparable).
  • Experience with adjacent identity domains or IGA products: PAM (CyberArk, Delinea, BeyondTrust), IGA (Saviynt, Veza), or IdP and authentication platforms (Okta, Entra ID, Ping).
  • Identity protocol fluency: SAML, OAuth 2.0, OIDC, SCIM.
  • Regulated industry experience and the audit and compliance expectations that come with it.
  • CI/CD and infrastructure automation applied to identity platform deployments.

Benefits

  • Remote-first, U.S. based. Flexible hours, with client time zones taking priority when an engagement calls for it.
  • 20 days of paid time off, granted as a bucket rather than accrued, plus holidays.
  • Medical, dental, and vision coverage through Aetna.
  • 401(k) with company match: full match on the first 3% and half match on the next 2%.
  • Annual performance-based bonus eligibility.
  • Sponsored training and certifications, including platform-specific enablement.
  • Direct client work, real ownership, and a seat at a boutique early enough that your work shapes the firm.

Who Thrives Here

Palyrian is a boutique that runs like a tech startup. Identity must be your thing. The team lives by four principles:

  • Builder's Mindset: When you see a better way, you build it. Problems don’t come with answers attached.
  • Own the Outcome: You are accountable for whether the client’s program improves, not just whether the ticket closed.
  • Always Be Learning: Identity changes fast, and non-human identity changes faster. You keep pace and bring what you learn back to the team.
  • Prideful Excellence: Work that holds up after we leave. Clients return because of the quality, not the contract.

Hiring Process

  • An introductory screening.
  • A technical interview with Palyrian. Expect roughly 30 minutes of systems-thinking and scenario questions rather than a live coding exercise.
  • A behavioral and culture conversation with one of the founders.
  • Two interviews, and we try to keep them inside a single hour where we can.
Before You Apply
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Identity Engineer @Palyrian
All Others
Salary unspecified
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 1wk ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 126,869+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later