You’re only human.
It’s a strange thing to say, because us humans are capable of incredible things. And at Medibank, we know our greatest potential lies in the people who work with us.
We strive to make real, fundamental change, driven by a simple purpose: to create the best health and wellbeing for all of Australia.
About the role:
We’re hiring an experienced IAM Engineer with deep, hands-on experience designing, implementing and operating enterprise-scale SailPoint Identity solutions. In this role you’ll deliver automated identity lifecycle (JML) workflows, scalable role and entitlement models, access governance, and complex IIQ customizations. Complementary experience with CyberArk PAM and Microsoft Entra ID (Azure AD) is essential to support identity security and Zero Trust alignment. You’ll work across security, cloud and infrastructure teams to deploy secure, compliant and automated IAM capabilities.
Key responsibilities
- Design, build and maintain end-to-end Joiner/Mover/Leaver (JML) workflows in SailPoint IdentityIQ.
- Develop IIQ rules, workflows, connectors, lifecycle events
- Create scalable role models and entitlement structures that enforce least privilege.
- Plan and run access certification campaigns: scoping, scheduling, remediation, reporting.
- Onboard applications to SailPoint: entitlement mapping, provisioning logic and reconciliation.
- Integrate SailPoint with directories and SaaS apps via REST APIs, JDBC, AD, LDAP and custom connectors.
- Troubleshoot and resolve complex provisioning, de-provisioning and reconciliation issues across hybrid environments.
- Automate operational tasks, improve governance via policy/process/solution enhancements.
- Support platform upgrades, performance tuning, health fixes and CI/CD deployment pipelines.
- Align Entra role governance with SailPoint access structures; support SSO/federation (SAML, OAuth2, OIDC).
- Contribute to Conditional Access policy refinement and identity risk investigations.
- Support CyberArk PAM onboarding, credential rotation, API integrations and JML alignment with PAM governance.
- Drive continuous improvement, stay current with IAM trends, and support ICAM leadership with reporting and risk communication.
Required experience & skills
- 4-5 yrs of Extensive, hands-on experience designing, implementing and operating SailPoint Identity/ISC at enterprise scale.
- Sailpoint experience is an absolute must have
- Experience with CyberArk PAM and proven PAM integrations and onboarding.
- Strong practical experience with Microsoft Entra ID / Azure AD, Conditional Access policies, and AD.
- Solid understanding of identity governance, PAM, SSO, MFA, LDAP and federation standards (SAML/OAuth2/OIDC).
- Proficiency with Java / BeanShell for IIQ customizations; PowerShell or other scripting skills desirable.