ForgeApply · Job listing
Sr Systems Engineer - IAM
Earlywarning
See all 87 open roles at Earlywarning →
Tailor your resume for this Earlywarning job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Earlywarning's site. Free trial, no card required.
About this role
At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.
Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.
Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.
Overall Purpose The Senior Systems Engineer - IAM sits within the Identity Platform Engineering team, part of the broader Identity and Access Management department, and serves as the technical anchor for Early Warning's Identity Governance and Administration (IGA) platform. This role leads the discovery, design, delivery, and operational health of Saviynt Enterprise Identity Cloud (EIC) and the governance controls that determine how identities are provisioned, certified, and constrained across a regulated financial technology environment. This is a hands on, deeply specialized position rather than a generalist infrastructure role. The engineer is accountable for architecting access models, hardening segregation of duties controls, maintaining accurate technical documentation of supported systems, participating in audit and compliance activities, and serving as a subject matter expert in identity and access management. The role also carries a mandate to prototype new solutions to identity challenges, optimize existing systems, and evaluate emerging technologies as they become available. Essential Functions
Platform Ownership and Engineering • Owns the architecture, configuration, and operations of the Saviynt EIC platform, including access request, certification, and lifecycle management modules.
• Provides operational excellence for the identity governance platform including version maintenance, vulnerability management, patching, and overall platform health.
• Proactively monitors and maintains identity platform security assurances such as threat detection, user behavior analytics, and privileged user monitoring.
• Builds and manages connectors and integrations across directories, cloud platforms, databases, and enterprise applications, including Active Directory, Entra ID, Okta, ServiceNow, Workday, SAP, cloud infrastructure, and custom REST based endpoints.
• Authors PowerShell, Python, and other scripts to automate repetitive tasks and extend platform capability.
Governance, Controls, and Risk • Designs and maintains identity governance controls including access certification and attestation campaigns, segregation of duties (SoD) rulesets, role based and attribute based access models (RBAC and ABAC), and least privilege enforcement.
• Automates the full identity lifecycle covering joiner, mover, and leaver events, including provisioning, deprovisioning, and access reconciliation, minimizing manual intervention and standing access.
• Ensures just in time and just enough access is enforced without hindering productivity or user experience.
• Develops and tunes workflows, rules, analytics, and reporting to detect access risk and drive remediation.
• Partners with internal audit, risk, and compliance to support control testing and evidence collection for regulatory frameworks relevant to financial services, including SOX, PCI DSS, GLBA, and related audit obligations.
Design, Delivery, and Quality • Gathers requirements from business, security, and audit stakeholders, decomposes them into discrete technical components, and translates them into usable solutions incorporated into platform design.
• Establishes repeatable and reusable frameworks, patterns, and reference designs so that solutions scale consistently rather than being rebuilt for each use case.
• Plans and executes both manual and automated testing across configurations, integrations, and workflows, validating that solutions meet functional, security, and compliance requirements before release.
• Leads root cause analysis and resolution of complex identity issues spanning provisioning failures, entitlement drift, and integration breaks.
• Defines technical standards, patterns, and documentation that make the platform sustainable and repeatable as it scales.
Collaboration and Leadership • Continuously evaluates the IAM organizational structure, system configuration, and application integrations, and provides recommendations for operational and security enhancements.
• Collaborates with Enterprise Architects, Security Architects, and Application Architects to drive adoption of IAM best practices and to support documentation standards.
• Develops relationships with business and technology stakeholders to ensure on time delivery.
• Actively participates in team stand up, technical engineering discussions, change control process, audit activities, business continuity efforts, and on call rotation.
• Mentors, coaches, and trains junior systems engineers, and models a strong sense of responsibility, ownership, and pride in delivering quality results.
• Contributes to the broader identity roadmap, advising leadership on platform strategy, emerging risks, and modernization opportunities.
• Supports the company's commitment to risk management and to protecting the integrity and confidentiality of systems and data.
• The above job description is not intended to be an all inclusive list of duties and standards of the position. Incumbents will follow instructions and perform other related duties as assigned by their supervisor.
Identity Governance Focus • Progressive experience and advanced proficiency with Saviynt Enterprise Identity Cloud, including connector development, workflow configuration, rule and
Salary insight
The midpoint of this range ($136k) is about 5% above the median disclosed salary for Chicago roles listed on ForgeApply ($129k across 2,241 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Earlywarning role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior Systems Engineer - IAM — Crusoe · San Francisco, CA - US
- Senior Systems Engineer, IAM Operations — Crusoe · San Francisco, CA - US
- Sr Systems Security Engineer — SNC · Lone Tree, CO
- Sr Systems Security Engineer — SNC · Beavercreek, OH | Dayton, OH
- Senior Security Engineer I, IAM — Oscar · New York, New York, United States
- Senior IAM Engineer — M&T Bank · Buffalo, NY
- Senior IAM Engineer — Xai · Austin, Texas; Palo Alto, California; Washington, D.C.
- Senior IAM Engineer — Komodohealth · United States
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)