Sailpoint Developer

CompanyKyndryl España, S.A.U.
LocationChennai, Tamil Nadu, India, Bangalore, Karnataka, India
CategorySoftware Engineering
Seniority-
Workplace-
Posted2026-08-31
Viaworkday

Description

Who We Are

At Kyndryl, we run and reimagine the mission-critical technology systems that drive advantage for the world’s leading businesses.  We are at the heart of progress; with proven expertise and a continuous flow of AI-powered insight, enabling smarter decisions, faster innovation, and a lasting competitive edge. For our people—Kyndryls—that means doing purposeful work that powers human progress. Join us and experience a flexible, supportive environment where your well-being is prioritized and your potential can thrive.

The Role

As a SailPoint IIQ Developer, you will contribute to the implementation, enhancement, and support of enterprise IAM and IGA capabilities using SailPoint IdentityIQ. You will design and maintain workflows, rules, forms, tasks, connectors, provisioning logic, and integration components required to support Joiner, Mover, Leaver, access request, approval routing, birthright provisioning, deprovisioning, manual fulfillment, and periodic access review processes.

The role requires strong understanding of the SailPoint IIQ object model, workflow engine, Lifecycle Manager capabilities, application onboarding patterns, entitlement management, identity correlation, account aggregation, provisioning plans, and certification processes. You will support integrations with authoritative sources such as HR systems, directory services such as Active Directory or LDAP, databases, REST or SOAP APIs, flat files, and enterprise applications using out-of-the-box or custom integration approaches.

You will also troubleshoot and optimize IIQ workflows, aggregation tasks, provisioning failures, identity refresh tasks, certification campaigns, policy violations, and custom rules. The candidate should be able to analyze logs, review task results, validate XML objects, test configuration changes, create deployment evidence, and ensure all customizations align with IAM governance, security, compliance, and operational requirements.

Key Responsibilities

  • Design, develop, configure, and support SailPoint IdentityIQ solutions for enterprise IAM and IGA use cases.
  • Develop and customize IdentityIQ workflows for access requests, approvals, provisioning, deprovisioning, lifecycle events, escalation, rejection handling, manual fulfillment, and exception processing.
  • Configure and maintain application integrations using SailPoint out-of-the-box connectors, JDBC, LDAP, Active Directory, REST, SOAP, flat file, and custom integration patterns.
  • Support application onboarding activities including source analysis, account schema definition, entitlement model design, aggregation, correlation, manager mapping, provisioning policy configuration, and certification enablement.
  • Develop and maintain SailPoint IIQ rules such as BuildMap, Correlation, Customization, Before Provisioning, After Provisioning, Workflow, Certification, Policy, Validation, and Task rules.
  • Configure Lifecycle Manager capabilities including QuickLinks, access request forms, approval schemes, work items, provisioning workflows, birthright access, mover logic, and leaver deprovisioning.
  • Develop and maintain IdentityIQ objects including applications, identities, identity attributes, managed attributes, roles, policies, populations, workgroups, email templates, forms, workflows, tasks, and configuration objects.
  • Work with provisioning plans, account requests, attribute requests, entitlement requests, approval sets, work items, and manual fulfillment processes.
  • Troubleshoot IdentityIQ issues using application logs, task results, workflow cases, provisioning transactions, debug pages, aggregation results, identity refresh outcomes, and connector responses.
  • Validate and migrate IdentityIQ XML objects across development, test, UAT, pre-production, and production environments using approved change and release management processes.
  • Collaborate with architects and application owners to define connector requirements, entitlement models, approval routing, provisioning behavior, certification scope, and operational handover needs.
  • Support access certification campaigns, policy violation handling, role management, SoD controls, access review evidence, audit reporting, and compliance documentation.
  • Prepare technical documentation including design notes, configuration guides, test evidence, deployment instructions, troubleshooting steps, and support handover documents.

Your Future at Kyndryl
Every position at Kyndryl offers a way forward to grow your career. We have opportunities that you won’t find anywhere else, including hands-on experience, learning opportunities, and the chance to certify in all four major platforms. Whether you want to broaden your knowledge base or narrow your scope and specialize in a specific sector, you can find your opportunity here.

Who You Are

You’re good at what you do and possess the required experience to prove it. However, equally as important – you have a growth mindset; keen to drive your own personal and professional development. You are customer-focused – someone who prioritizes customer success in their work. And finally, you’re open and borderless – naturally inclusive in how you work with others.

Required Technical and Professional Expertise

  • 7+ Years of experience Hands-on experience with SailPoint Identity IQ development, configuration, integration, deployment, and support.
  • Strong understanding of IAM and IGA concepts including identity lifecycle management, access governance, access request, access certification, provisioning, deprovisioning, role-based access control, and segregation of duties.
  • Experience developing or customizing IdentityIQ workflows using Business Process Editor, workflow XML, process variables, approval steps, rules, scripts, subprocesses, forms, and workflow library methods.
  • Experience with application onboarding, account aggregation, entitlement aggregation, identity correlation, manager correlation, identity refresh, and provisioning configuration.
  • Experience developing IdentityIQ rules using Java and BeanShell.
  • Experience with rule types such as BuildMap, Correlation, Customization, Before Provisioning, After Provisioning, Workflow, Certification, Policy, Validation, and Task rules.
  • Experience integrating IdentityIQ with systems such as Active Directory, LDAP, JDBC databases, REST APIs, SOAP services, web services, flat files, HR systems, and enterprise applications.
  • Good understanding of provisioning plans, account requests, attribute requests, entitlement models, managed attributes, roles, policies, populations, workgroups, and access profiles.
  • Ability to troubleshoot IIQ issues using logs, task results, workflow cases, debug pages, application configuration, aggregation outputs, and provisioning transaction details.
  • Familiarity with IdentityIQ XML object management, object export/import, environment promotion, release management, and rollback planning.
  • Understanding of access reviews, certification campaigns, policy violations, SoD controls, audit requirements, and compliance reporting.
  • Working knowledge of SQL, XML, JSON, REST APIs, Java, BeanShell, application servers, and basic Linux or Windows operational commands.
  • Ability to collaborate with IAM architects, application owners, business users, security teams, testing teams, and operations teams.
  • Ability to follow secure development, documentation, change management, testing, release, and production support practices.

Preferred Skills and Experience

  • Experience with SailPoint IdentityIQ upgrade, patching, environment support, or performance tuning.
  • Experience with custom connector development, advanced connector customization, or web service connector implementation.
  • Experience with Lifecycle Manager configuration, access request customization, dynamic approval routing, and complex fulfillment patterns.
  • Experience integrating with Active Directory, Microsoft Entra ID, LDAP, ServiceNow,