Principal IAM Engineer with SailPoint

BulgariaBulgaria·SofiaHybridlead
OtherIam Engineer
2 views0 saves0 applied

Quick Summary

Key Responsibilities

Design, implement, and own enterprise Identity Governance and Administration (IGA) architecture and operations centered on SailPoint IdentityIQ and/or Identity Security Cloud,

Technical Tools
OtherIam Engineer

The world of global advisory, audit and tax compliance services for large multi-nationals is rapidly changing and heavily dependent on technology. 

The KPMG Delivery Network (KDN) is a KPMG special purpose member firm offering a way for clients to leverage KPMG top talent and technology platforms through regional teams of specialists, enabling economies of scale and a new way of working that expands beyond local capability.

Together with KDN, KPMG member firms can drive the sales and delivery of global solutions at a competitive price and in a repeatable and consistent manner. As a member of KDN, you'll be a part of the KPMG family working alongside some of our profession's most skilled practitioners on rewarding programs and initiatives that are changing the way business operates, delivering value to our clients, and driving positive change in the communities we serve. 

You'll be enabling KDN accelerate new ways of working, using cutting-edge technology and working together with our member firms located in nearly 150 countries to help us achieve our ambition to be the most trusted and trustworthy professional services firm. 

And through your work, you'll build a global network and unlock opportunities that you may not have thought possible with access to great support, vast resources, and an inclusive, supportive environment to help you reach your full potential. 

Our KDN Bulgaria Cloud Services unit is focused on designing, building, securing and managing cloud native and hybrid platforms for the KPMG group of member firms, as well as providing cloud advisory and engineering services to external clients. 

The IAM engineer with strong hands-on expertise in SailPoint is responsible for designing, implementing, and operating enterprise Identity Governance & Administration (IGA) solutions across complex hybrid environments. The role emphasizes automation-first delivery using PowerShell, Python, and REST APIs, deep knowledge of identity lifecycle management, access governance, and role-based access control, and the ability to extend identity governance capabilities across cloud and on-premises systems while improving security posture, regulatory compliance, and operational efficiency.

Responsibilities

~1 min read
  • Design, implement, and own enterprise Identity Governance and Administration (IGA) architecture and operations centered on SailPoint IdentityIQ and/or Identity Security Cloud, delivering scalable identity lifecycle management and access governance capabilities across cloud, hybrid, and on-premises environments.
  • Lead hands-on deployment and configuration of SailPoint capabilities, including Joiner-Mover-Leaver processes, access requests, approvals, certifications, role management, policy controls, and segregation of duties (SoD).
  • Engineer automated identity lifecycle and provisioning workflows using PowerShell, Python, REST APIs, and connectors, developing reusable integrations that reduce manual effort and improve governance consistency.
  • Integrate SailPoint with enterprise applications, directories, cloud platforms, HR systems, and identity providers, ensuring seamless management of identities and access across business-critical environments.
  • Design and implement Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) models that support least privilege, compliance requirements, and operational scalability.
  • Drive access certification and governance programs by implementing periodic access reviews, policy enforcement, SoD controls, and audit-ready reporting capabilities.
  • Partner with cloud and platform engineering teams to extend identity governance capabilities into Microsoft Entra ID (Azure AD), Azure, AWS, GCP, SaaS applications, and DevOps platforms, ensuring consistent identity controls across all environments.
  • Troubleshoot complex integration and operational issues involving connectors, directories, cloud services, applications, authentication systems, and identity data sources.
  • Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related technical field.
  • 6-10+ years of experience in Identity and Access Management, Identity Governance, Security Engineering, or Security Architecture roles.

  • Proven experience designing and implementing SailPoint IdentityIQ and/or Identity Security Cloud solutions in enterprise or highly regulated environments.

  • Strong understanding of identity lifecycle management, provisioning, access governance, role modeling, SoD controls, and compliance frameworks.

  • Hands-on experience integrating IAM solutions with directories, ERP systems, cloud platforms, databases, enterprise applications, and HR systems.

  • Experience supporting IAM programs across cloud environments including Azure, AWS, and GCP.

  • Demonstrated ability to advise senior stakeholders on IAM risks, governance strategies, architectural decisions, and remediation approaches.

  • SailPoint certifications strongly preferred:
    • SailPoint IdentityIQ Engineer
    • SailPoint IdentityIQ Architect
    • SailPoint Identity Security Cloud Professional
    • SailPoint Identity Security Cloud Engineer

What We Offer

~1 min read
The chance to work in a top talent team
Attractive remuneration
Build knowledge in cutting-edge technologies
Opportunity for continuous training, learning and certification
Experience in an international and multicultural organization
Work on challenging projects with clients in various industries around the globe
Modern office environment
Additional health insurance
Life insurance
50+ benefits and services to choose from
Hybrid working policy

Location & Eligibility

Where is the job
Sofia, Bulgaria
Hybrid — some on-site time required
Who can apply
BG

Listing Details

Posted
April 29, 2026
First seen
May 6, 2026
Last seen
August 4, 2026

Posting Health

Days active
92
Repost count
0
Trust Level
16%
Scored at
August 7, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

kdn-bulgariaPrincipal IAM Engineer with SailPoint