Senior Identity and Access Management Analyst
Cary, NC, US Cary, NC, US Cary, NC, US
Together, we own our company, our future, and our shared success.
As an employee-owned company, our people are Black & Veatch. We put them at the center of everything we do and empower them to grow, explore new possibilities and use their diverse talents and perspectives to solve humanity's biggest challenges in an ever-evolving world. With over 100 years of innovation in sustainable infrastructure and our expertise in engineering, procurement, consulting and construction, together we are building a world of difference.
Company : Black & Veatch Corporation
Req Id : 117085
Opportunity Type : Staff
Relocation eligible : No
Full time/Part time : Full-Time
Project Only Hire : No
Visa Sponsorship Available: No
Why Black & Veatch?
At Black & Veatch, you’ll be part of work that matters—designing, creating, and building the infrastructure communities rely on every day, from concept through execution.
We care about how the work gets done as much as what we build. Safety is built into every decision, and people look out for each other—speaking up, collaborating, and doing the right thing because it affects real lives.
You’ll work alongside teams solving complex challenges and turning ideas into solutions that perform in the real world—gaining hands-on experience across projects, technologies, and disciplines.
Ownership shows up in how we work. We take responsibility for outcomes, follow through on commitments, and take pride in what we deliver. As a 100% employee-owned company, employees share in the long-term success we build together.
With flexible ways of working and meaningful development opportunities, you’ll build a career you can be proud to stand behind.
The Opportunity
We are seeking a highly skilled Senior Identity Governance & Administration (IGA) Analyst to lead the administration, design, and expansion of our enterprise Identity Governance program utilizing a platform integrated with a new Oracle HCM as the authoritative source of identity data.
This role will be responsible for establishing and maturing the organization's identity governance capabilities, including onboarding enterprise applications, developing a comprehensive persona and role framework, defining birthright access models, implementing automated joiner-mover-leaver (JML) processes, and ensuring compliance with multiple regulatory and contractual requirements. The successful candidate will serve as a strategic technical leader, partnering with Cybersecurity, HR, IT, Audit, Compliance, and business stakeholders to deliver scalable identity governance solutions that reduce risk while improving operational efficiency.
Key Responsibilities
Identity Governance Program Leadership
- Serve as the primary administrator and subject matter expert for the SailPoint IGA platform.
- Design, implement, and maintain enterprise identity governance processes and controls.
- Develop and execute the roadmap for the organization's identity governance maturity program.
- Establish governance standards, policies, and operational procedures for identity lifecycle management.
- Provide technical leadership and guidance for IAM and cybersecurity initiatives.
SailPoint Platform Administration
- Configure, administer, and optimize SailPoint.
- Manage identity lifecycle workflows, certifications, provisioning, access requests, and policy enforcement.
- Develop and maintain connectors, integrations, transforms, rules, workflows, and governance processes.
- Monitor platform health, performance, and operational effectiveness.
- Support platform upgrades, enhancements, and new feature adoption.
Oracle HCM Integration & Identity Lifecycle Management
- Maintain integration between Oracle HCM and SailPoint to ensure accurate identity creation, modification, and termination activities.
- Design and implement automated Joiner, Mover, and Leaver (JML) processes.
- Ensure workforce changes are accurately reflected across connected systems.
- Develop identity data governance standards to improve data quality and consistency.
Application Onboarding & Integration
- Lead onboarding of enterprise applications into the SailPoint platform.
- Work with application owners to define provisioning models, entitlement structures, and governance processes.
- Design integration patterns utilizing APIs, SCIM, JDBC, LDAP, Active Directory, Azure AD, and other identity technologies.
- Validate application access models and ensure appropriate governance controls are established.
- Create and maintain onboarding documentation, support procedures, and operational runbooks.
Persona Framework & Role Engineering
- Design and implement an enterprise persona-based access framework.
- Develop business roles, IT roles, and access profiles aligned to organizational functions.
- Establish role mining and role engineering practices.
- Partner with HR and business leaders to map job functions to required system access.
- Continuously refine personas and role models to support least privilege and operational efficiency.
Compliance, Risk & Audit Support
- Support regulatory, audit, and governance activities related to identity management.
- Participate in internal and external audits and remediation efforts.
- Produce compliance reporting and evidence supporting access governance controls.
Stakeholder Engagement
- Collaborate with HR, IT Operations, Cybersecurity, Enterprise Applications, Compliance, and business stakeholders.
- Facilitate workshops to define identity governance requirements.
- Provide executive-ready reporting, metrics, and governance updates.
Management Responsibilities
Preferred Qualifications
- 5+ years of Identity and Access Management (IAM) experience.
- 3+ years of hands-on SailPoint administration and implementation experience.
- Experience integrating IGA platforms with Oracle HCM or similar HR systems.
- Experience onboarding enterprise applications into an identity governance platform.
- Experience designing role-based access control (RBAC) and persona frameworks.
- Experience supporting regulated environments and audit requirements.
Minimum Qualifications
- Bachelor's degree in Information Security or Computer Science or related field.
- Minimum 10 years of overall experience in Cyber Security, IT, Risk Assessments, Privacy
- Of the 10 years overall experience required, must have 5 years of experience in Governance, Risk and Compliance; and Privacy.
- At least 1 certification such as CISSP, CISM, CISA, CRISC, CIPP or similar privacy certifications.
- Demonstrated experience applying security and risk frameworks, regulations and privacy such as NIST CSF/800-53/800-171, NERC CIP, CIS, CMMC, SOC2, GDPR, etc.
- Experience in developing security policies and standards, risk assessments, third party risk programs, risk management, risk registries, regulatory compliance, security awareness training and testing, security metrics, privacy, and other relevant GRC areas.
- All applicants must be able to complete pre-employment onboarding requirements (if selected) which may include any/all of the following: criminal/civil background check, drug screen, and motor vehicle records search, in compliance with any applicable laws and regulations.
Certifications
Must hold at least 1 certification such as CISSP, CISM, CISA, CRISC, CIPP or similar privacy certifications.
Work Environment/Physical Demands
Hybrid or flexible work options may be offered after the first 90 days of employment based upon manager discretion, job performance and work assignments.
Salary Plan
Job Grade
Black & Veatch endeavors to make www.bv.com/careers accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process because of a disability, please contact the Employee Relations Department at +1-913-359-1622 or via our accommodations request form. This contact information is for disability accommodation requests only; you may not use this contact information to inquire about the status of applications. General inquiries about the status of applications will not be returned.
Black & Veatch is committed to being an employer of choice by creating a valuable work experience that keeps our people engaged, productive, safe and healthy.
Our comprehensive benefits portfolio is a key component of this commitment and offers an array of health care benefits including but not limited to medical, dental and vision insurances along with disability and a robust wellness program.
To support a healthy work-life balance, we offer flexible work schedules, paid vacation and holiday time, sick time, and dependent sick time.
A variety of additional benefits are available to our professionals, including a company-matched 401k plan, adoption reimbursement, tuition reimbursement, vendor discounts, an employment referral program, AD&D insurance, pre-taxed accounts, voluntary legal plan and the B&V Credit Union. Professionals may also be eligible for a performance-based bonus program.
We are proud to be a 100 percent ESOP-owned company. As employee-owners, our professionals are empowered to drive not only their personal growth, but the company's long-term achievements - and they share in the financial rewards of the success through stock ownership.
By valuing diverse voices and perspectives, we cultivate an authentically inclusive environment for professionals and are able to provide innovative and effective solutions for clients.
BVH, Inc., its subsidiaries and its affiliated companies, complies with all Equal Employment Opportunity (EEO) laws and regulations. Black & Veatch does not discriminate on the basis of age, race, religion, color, sex, national origin, marital status, genetic information, sexual orientation, gender Identity and expression, disability, veteran status, pregnancy status or other status protected by law.
Notice to External Search Firms: Black & Veatch does not accept unsolicited resumes and will not be obligated to pay a placement fee for unsolicited resumes. Black & Veatch Talent Acquisition engages with search firms directly for hiring needs.
Job Segment:
Engineer, Engineering