Company Profile:
At CGI, we’re a team of builders. We call our employees members because all who join CGI are building their own company - one that has grown to 72,000 professionals located in 40 countries. Founded in 1976, CGI is a leading IT and business process services firm committed to helping clients succeed. We have the global resources, expertise, stability and dedicated professionals needed to achieve. At CGI, we’re a team of builders. We call our employees members because all who join CGI are building their own company - one that has grown to 72,000 professionals located in 40 countries. Founded in 1976, CGI is a leading IT and business process services firm committed to helping clients succeed. We have the global resources, expertise, stability and dedicated professionals needed to achieve results for our clients - and for our members. Come grow with us. Learn more at www.cgi.com.
This is a great opportunity to join a winning team. CGI offers a competitive compensation package with opportunities for growth and professional development. Benefits for full-time, permanent members start on the first day of employment and include a paid time-off program and profit participation and stock purchase plans. We wish to thank all applicants for their interest and effort in applying for this position, however, only candidates selected for interviews will be contacted. No unsolicited agency referrals please.
Job Title: IAM Engineer with SailPoint
Position: Senior Systems Engineer
Experience: 6+ yrs
Category: IAM Engineer
Main location: Bangalore
Position ID: J0526-0908
Employment Type: Full Time
#LI-AA13
Qualification: Bachelor’s degree in computer science or related field or higher with minimum 3 years of relevant experience.
Job Description:
We are seeking a skilled and detail-oriented Identity and Access Management (IAM) Engineer with 6–8 years of experience in Microsoft Entra ID (Azure AD), On-Premises Active Directory, and SailPoint IdentityIQ/IdentityNow administration. The ideal candidate will be responsible for managing hybrid identity infrastructure, identity lifecycle management, access governance, privileged access management, and SSO integrations across enterprise and SaaS applications.
Key Responsibilities:
- Manage and support overall Identity and Access Management (IAM) operations including authentication, authorization, user access governance, and identity security controls.
- Administer Hybrid Identity infrastructure using Microsoft Entra ID (Azure AD), On-Premises Active Directory, and Azure AD Connect synchronization services.
- Manage SailPoint IdentityIQ/IdentityNow for identity lifecycle management, automated provisioning/deprovisioning, and access certification processes.
- Configure and support Single Sign-On (SSO) integrations for enterprise and SaaS applications using SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC).
- Implement and maintain Conditional Access policies based on user risk, device compliance, location, and application sensitivity.
- Enforce and manage Multi-Factor Authentication (MFA) and Self-Service Password Reset (SSPR) solutions for secure user access.
- Handle Joiner-Mover-Leaver (JML) processes, Role-Based Access Control (RBAC), entitlement management, and access review activities.
- Monitor Azure AD sign-in logs, audit logs, identity protection alerts, and suspicious authentication activities to enhance security posture.
- Troubleshoot authentication, authorization, federation, and identity synchronization issues across hybrid IAM environments.
- Design and maintain Active Directory Organizational Units (OUs), Group Policy Objects (GPOs), delegation models, and directory security best practices.
- Automate IAM operational tasks, reporting, and governance activities using PowerShell scripting, Microsoft Graph API, and SailPoint workflows.
- Collaborate with security, infrastructure, compliance, and application teams to ensure audit readiness, regulatory compliance, and IAM governance standards.
Must have Skills:
. Hybrid Identity Integration (Azure AD Connect)
. SailPoint Identity Governance & Administration
. SSO & Federation Integrations
. Conditional Access & MFA
. CyberArk PAM Administration
. PowerShell & Automation
. RBAC & Access Governance
. Active Directory Administration
. Identity Lifecycle Management