Responsibilities
Team Intro
The Access Assurance vertical within USDS Data Defense and Access Assurance (DDAA) Team is responsible for designing and maintaining an access management program with a mission to enforce the principle of least privilege. We strive to establish secure and compliant processes around provisioning, deprovisioning and governance of access to USDS data and infrastructure proactively identifying and reducing risks.
Job Overview:
As an Identity Management Engineer reporting directly to the Principal Lead of US Data, Identity and Access Management (DIAM), you will contribute to engineering, deploying, and maintaining identity security within TikTok USDS's global infrastructure. Your role ensures secure identity lifecycle management, enforcing the principles of least privilege and compliance with international regulatory requirements.
Want more jobs like this?
Get jobs in London, United Kingdom delivered to your inbox every week.
In order to enhance collaboration and cross-functional partnerships, among other things, at this time, our organization follows a hybrid work schedule that requires employees to work in the office 3 days a week, or as directed by their manager/department. We regularly review our hybrid work model, and the specific requirements may change at any time.
Responsibilities:
- Develop and execute technical strategies for Identity Management programs.
- Engineer and support onboarding of applications onto IAM platforms (Azure AD, Google Workspace).
- Implement identity and access governance to mitigate risks associated with inappropriate access.
- Design and enforce regular identity review processes and privilege assessments.
- Develop and maintain IAM policies, procedures, and proactive monitoring mechanisms.
- Integrate IAM solutions with cybersecurity technologies (SIEM, vulnerability management).
- Lead engineering and operational management of SailPoint IdentityNow.
- Implement and optimize identity governance and administration (IGA) capabilities.
- Design and execute automated identity provisioning/de-provisioning workflows.
- Develop and maintain advanced identity reporting and compliance metrics.
- Perform integrations between SailPoint IdentityNow and enterprise applications.
Qualifications
Minimum Qualifications:
- Minimum 5 years of IAM/IT industry experience.
- Working knowledge of Active Directory/Azure AD/Entra ID.
- Strong technical background in Windows/Linux systems access management.
- Proven ability to adapt quickly to emerging IAM technologies and practices.
- Knowledge of identity lifecycle management, certification campaigns, and segregation-of-duties (SoD).
Preferred Qualifications:
- Systems engineering or IT admin experience preferred.
- Experience with scripting languages (PowerShell, Python) for automation.
- Extensive hands-on experience with SailPoint IdentityNow or similar IGA platforms (SailPoint IIQ, Saviynt).
- Proficiency in developing custom workflows, connectors, and integrations.
- Experience with role-based access control frameworks.