The position of Identity Governance & Administration (IGA) Engineer will deliver best-in-class design implementation and management of our IGA solution in a large-scale fast-paced retail environment.
This role requires deep SailPoint Identity Security Cloud (ISC) expertise strong operational knowledge and the ability to work effectively across security infrastructure application and business teams.
This position reports to the Vice President CISO.
ESSENTIAL DUTIES AND RESPONSIBILITIES:
Include the following. Other duties may be assigned.
- Own the Identity & Access Management (IAM) architecture roadmap with a strong focus on SailPoint ISC authoritative data sources and core directory services (Active Directory Entra ID)
- Design and govern identity lifecycle and access governance solutions for employees contractors vendors and service accounts
- Architect and oversee implementations between IAM platforms and enterprise systems including POS ERP e-commerce platforms and cloud workloads
- Define and implement robust a RBAC model automated provisioning/deprovisioning and identity workflows within SailPoint
- Provide guidance and architectural support for directory service modernization ensuring security and role modelling across hybrid IT estates
- Lead the secure integration of Authentication & Authorization mechanisms (e.g. SAML OIDC OAuth2) for internal and customer facing applications
- Support audit and compliance initiatives including PCI-DSS GDP and internal policy enforcement
- Evaluate new IAM technologies tools and capabilities to maintain a forward-looking strategic identity architecture
- Collaborate with business and technical stakeholders to gather requirements and translate them into scalable SailPoint configurations
- Integrate SailPoint ISC with enterprise systems and applications (both on-prem and cloud) via out of the box connectors or custom-built connectors
- Implement identity governance policies role models access reviews and segregation of duties (SoD) controls
- Monitor and maintain the health of the SailPoint ISC platform troubleshoot issues and implement enhancements
- Automate provisioning and de-provisioning for user access across multiple systems
- Participate in security audits and contribute to compliance efforts by providing evidence and supporting documentation
- Stay current with SailPoint updates new features and industry best practices in identity and access management
- Support hybrid environments by integrating Privilege Cloud with on-prem infrastructure and identity sources (e.g. Active Directory)
- Collaborate with internal colleagues and teams to maintain optimal configuration availability and performance.
- Participate in security reviews and support audit-related activities related to privileged account governance
- Provide integration support across ITSM ticket systems SIEMs and CI/CD pipelines to ensure secure DevOps practices.
- Perform regular health checks maintenance and upgrades and incident resolution for the SailPoint platform.
- Provide level 2/3 support for SailPoint related issues and alerts.
- Document architecture procedures and incident response playbooks.
- Work with Technology Security and Application teams to understand access needs across the organizations systems and cloud environments
- After hours support required.
- Perform other identity Governance tasks as assigned.
QUALIFICATIONS:
To perform this job successfully an individual must be able to perform each essential duty satisfactorily. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- SailPoint certification (e.g. SailPoint IdentityNow Engineer or Architect)
- Background in broader IAM concepts such as PAM SSO or MFA.
- Security certifications such as CISSP CISM or CCSP are a plus.
- Knowledge of security frameworks regulatory requirements and compliance standards (e.g. NIST PCI DSS GDPR).
EDUCATION and/or EXPERIENCE:
- Proven experience within Identity and Access Management with significant hands-on experience with SailPoint (preferably ISC)
- Strong understanding of identity lifecycle management JML RBAC/ABAC/PBAC access certification and provisioning
- Experience with SailPoint features such as:
- IdentityNow configuration and deployment
- Custom connector development
- REST APIs and web services
- Rules roles polices and workflows in SailPoint ISC
- Familiarity with directory services (AD Entra ID) HR systems and enterprise applications
- Solid understanding of Windows/Linux systems and cloud platforms (AWS Azure GCP)
- Proficient in scripting and development languages such as PowerShell Java or Python and experienced at utilizing SailPoints own REST APIs
- Excellent problem-solving skills and attention to detail
- Strong written and verbal communication and collaboration skills
- Detail-oriented with a strong security mindset and ability to think proactively.
Overall Purpose of the Role:
Hibbett is looking for a hands-on senior-level identity engineer who can own architect and operationalize the companys identity governance platform (SailPoint Identity Security Cloud) within a large complex retail enterprise.
This is not just an administrative or support role its a technical leadership position within the cybersecurity organization reporting directly to the CISO focused on building and maturing Hibbetts IAM and governance capabilities.
Core Mission:
To design implement and maintain secure automated and compliant identity and access governance systems that ensure:
- Every user (employee contractor vendor service account) has the right access.
- Access changes are automated traceable and compliant.
- Integrations across retail systems (POS ERP e-commerce cloud) are secure and seamless.
- The environment aligns with regulatory and audit standards (PCI GDPR etc.).
What Hibbett Specifically Wants
1. Deep SailPoint Identity Security Cloud Expertise
- Act as the subject-matter expert for SailPoint ISC.
- Architect configure and optimize the SailPoint platform (connectors workflows policies).
- Implement RBAC (Role-Based Access Control) automated provisioning/deprovisioning and SoD (Segregation of Duties) controls.
- Maintain platform health troubleshoot issues and perform upgrades.
2. Architectural Ownership
- Own the IAM / IGA roadmap aligning it with broader enterprise security and technology strategy.
- Design integrations with systems like Active Directory Entra ID (Azure AD) POS ERP and e-commerce platforms.
- Lead directory modernization and ensure consistent identity modeling across hybrid environments (on-prem cloud).
3. Integration & Automation Skills
- Build and maintain integrations with enterprise systems via APIs connectors and workflows.
- Automate user lifecycle management across systems.
- Connect SailPoint to ITSM (ServiceNow) SIEM and DevOps pipelines to strengthen identity-driven security automation.
4. Governance & Compliance
- Support audits (PCI-DSS GDPR internal IT policies).
- Provide evidence documentation and reporting for compliance.
- Maintain access certification campaigns and enforce governance controls.
5. Collaboration & Cross-Functional Influence
- Partner with Security Infrastructure HR Application and Business teams.
- Translate business access needs into technical configurations.
- Serve as a technical advisor to leadership and peers on identity-related strategy and risks.
Preferred Experience & Background
- Certifications:
- SailPoint (IdentityNow Engineer or Architect) required/preferred
- CISSP / CISM / CCSP plus
- Technical Exposure:
- Directory services (Active Directory Entra ID/Azure AD)
- Authentication protocols: SAML OAuth2 OIDC
- Privileged Access Management (PAM) and Single Sign-On (SSO)
- Hybrid and cloud environments (Azure AWS)
- Security frameworks: NIST PCI-DSS GDPR compliance
- Soft Skills:
- Strategic mindset (roadmap ownership)
- Strong cross-team communication
- Ability to operate under pressure in a fast-paced retail environment
- Willingness to provide after-hours support
What Success Looks Like in This Role
- SailPoint ISC is fully integrated and automated across all major enterprise systems.
- Identity lifecycle management is streamlined and auditable.
- Hibbetts IAM environment supports zero-trust security goals and regulatory compliance.
- The engineer becomes the go-to internal expert on identity governance influencing architecture tools and policy.
Alternate / Equivalent Job Titles in the Market
Hibbetts IGA Engineer aligns closely with:
- Identity Governance Engineer
- IAM Engineer (SailPoint focus)
- Identity & Access Governance Architect
- Identity Security Engineer
- SailPoint Engineer / Architect
- Identity Solutions Engineer
#LI-DNI
This job description is not intended to cover all aspects duties and/or responsibilities required of employees. Employees may be asked to perform additional duties outside of normal job scope on a temporary or permanent basis per company policy. The company reserves the right to modify this job description with or without notice.
EEO Statement:
The Finish Line Inc. is an Equal Employment Opportunity employer and is committed to complying with all federal state and local EEO laws. The Finish Line Inc. prohibits discrimination against employees and applicants for employment based on race or color religion or creed national origin alienage or citizenship status marital status sex pregnancy status age military status disability or any other characteristic or class protected by law. The Finish Line Inc. provides reasonable accommodations in accordance with applicable laws including for disabilities pregnancy and religious practices.
Need accessibility assistance to apply
Applicants who require accessibility assistance to submit an employment application can either call Finish Line at or email us at A member of our Talent Acquisition team will respond as soon as reasonably possible. (This email address and phone number is only for individuals seeking accommodation when applying for a job.)