SailPoint Engineering Lead
London, England, United Kingdom
SailPoint Engineering Lead
- 202605613
- London, England, United Kingdom
- Full time
Description
Willis Towers Watson (WTW) Information & Cyber Security (ICS) requires an experienced SailPoint Engineering Lead to work within the Identity and Access Management function, combining hands-on IGA engineering with product ownership of the identity platform roadmap.
As an experienced SailPoint engineer, you will be responsible for designing and building SailPoint Identity Security Cloud (ISC) solutions, developing and maintaining Joiner, Mover & Leaver automation, and owning the backlog and roadmap for our Identity Governance platform, ensuring we continue to meet regulatory and client expectations. This role is a hybrid role in London, where the normal working base location will be balance between home and office as needed.
The Role:
Willis Towers Watson IT is currently seeking a senior, experienced candidate for the position of SailPoint Engineering Lead. In this position, the successful candidate must demonstrate significant hands-on experience engineering SailPoint IGA solutions, together with the seniority to set technical direction, own and prioritise a product backlog, and mentor engineers within the team. The main focus of this position is to lead the build, operation and continuous improvement of our SailPoint platform while acting as product owner for the identity platform roadmap, influencing senior stakeholders and ensuring successful delivery of service, stakeholder alignment and continuous development of the IAM Team.
Major Accountabilities:
- Lead the design, build and maintenance of SailPoint Identity Security Cloud (ISC) solutions, including source connectors, provisioning workflows and access certification campaigns across WTW.
- Own and prioritise the SailPoint/IGA platform backlog, setting technical direction and acting as product owner for the identity platform roadmap based on business risk, compliance deadlines and stakeholder demand.
- Oversee the build and maintenance of Joiner, Mover & Leaver (JML) automation integrating HR systems (Oracle HCM) with SailPoint.
- Define and govern Segregation of Duties (SoD) policies, role models and access certification campaigns across WTW.
- Act as the senior technical authority within IAM, covering all aspects of Identity Governance and Administration.
- Drive solution development through problem solving, ensuring adherence to Security Controls, Policies and Standards with a focus on automation and control.
- Influence senior stakeholders across IT, Compliance and the business to align the identity platform roadmap with WTW's risk and regulatory priorities.
- Lead the development of skills and capabilities within the IAM team, mentoring engineers and driving process improvements and documentation.
Responsibilities:
Oversee configuration and troubleshooting of SCIM, REST and direct connectors to SaaS and on-prem applications, working hands-on where required.
Author and review custom rules, workflows and Beanshell/Java scripts and Python automation, setting standards for the wider team.
Govern the operational execution of access certification cycles, entitlement catalogue management and role mining initiatives.
Oversee platform health, ensuring provisioning/deprovisioning failures are resolved, and audit trail integrity is maintained.
Lead sprint planning, backlog grooming and roadmap reviews.
Own roadmap and status communications for leadership and stakeholders.
Oversee the user identity lifecycle, including onboarding, offboarding and account updates.
Ensure compliance with internal policies and external regulations, escalating risks as needed.
Own the response to audit findings and drive remediation measures to closure.
Oversee resolution of escalated issues and support tickets, providing senior technical input where needed.
Qualifications
What you'll bring:
Strong background and working years in IAM/IGA engineering, including 3+ years hands-on with SailPoint Identity Security Cloud (ISC) and/or IdentityIQ (IIQ), with demonstrated experience leading IGA engineering teams.
Strong understanding of IGA concepts: JML lifecycle, access certification, SoD, role-based access control.
Experience integrating SailPoint with HR systems, Active Directory/Entra ID and SaaS applications via SCIM/REST.
Scripting proficiency in Beanshell/Java (for SailPoint rules) and Python (for automation and API integration).
Working knowledge of identity standards: SAML, OAuth2/OIDC, SCIM.
Experience with access governance frameworks and compliance mapping (ISO 27001, SOC 2, GDPR or similar).
Demonstrated experience writing user stories, managing a backlog, or working closely with product/agile teams.
Strong stakeholder communication skills, able to translate technical detail for both engineers and business stakeholders.
Good project management skills.
Positive team-first attitude with strong verbal and written communication skills.
Must possess sound analytical and problem-solving capabilities.
Nice to have
- SailPoint certification (ISC Engineer/Architect).
- Experience with Saviynt, Omada or One Identity as a comparison point.
- Familiarity with Agile/Scrum ceremonies and tools (Jira, Azure DevOps).
- Exposure to Zero Trust principles and NIST SP 800-53 AC/IA control families.
What we offer:
Enjoy a benefits package designed to help you thrive, both professionally and personally. You'll receive 25 days of annual leave plus an extra WTW day to relax and recharge. Our comprehensive health and wellbeing offering includes private healthcare, life insurance, group income protection, and regular health assessments, all giving you peace of mind. Secure your future with our defined contribution pension scheme, featuring matched contributions up to 10% from the company.
We support your growth and balance with hybrid working options, access to an employee assistance programme, and a fully paid volunteer day to make a difference in your community. On top of these, you can opt into a variety of additional perks including an electric vehicle car scheme, share scheme, cycle-to-work programme, dental and optical cover, critical illness protection, and much more. Start making the most of your career and wellbeing with a range of benefits tailored for you.
Equal Opportunity Employer
We’re committed to equal employment opportunity and provide application, interview and workplace adjustments and accommodations to all applicants. If you foresee any barriers, from the application process through to joining WTW, please email candidatehelpdesk@wtwco.com
Other People Viewed
Unsolicited Contact
Any unsolicited resumes/candidate profiles submitted through our web site or to personal e-mail accounts of employees of Willis Towers Watson are considered property of Willis Towers Watson and are not subject to payment of agency fees. In order to be an authorized Recruitment Agency/Search Firm for Willis Towers Watson, any such agency must have an existing formal written agreement signed by an authorized Willis Towers Watson recruiter and an active working relationship with the organization. Resumes must be submitted according to our candidate submission process, which includes being actively engaged on the particular search. Likewise, for our authorized Recruitment Agencies/Search Firms, if the candidate submission process is not followed, no agency fees will be paid by Willis Towers Watson. Willis Towers Watson is an equal opportunity employer. If you would like to have your contact information saved for future consideration, please email: Agency.inquiries@willistowerswatson.com.
Our Offices
Our colleagues serve more than 140 countries and markets around the world. This gives a global dimension to everything we do and creates lots of exciting opportunities for you to collaborate and grow. Explore the map below to see where you career could take you.