الموقع: الرياض، المملكة العربية السعودية — طبيعة العمل: دوام كامل أو عقد لمدة 12 شهرًا مع إمكانية التمديد. الخبرة: 7 سنوات فأكثر في إدارة الهوية والوصول (IAM). الراتب: 16,000–20,000 ريال سعودي شهريًا؛ الموعد المفضل للانضمام: خلال 30 يومًا.
عن الفرصة
نحن نوظف خبيرًا معتمدًا من SailPoint في مجال التحكم في الوصول القائم على الأدوار (RBAC) لدعم تصميم وتنفيذ وحوكمة قدرات التحكم في الوصول للمؤسسات. سيعمل المرشح الناجح في مقر العمل بالرياض وسيتعاون مع فرق الأمن السيبراني والتكنولوجيا والتطبيقات والأعمال لبناء نماذج وصول قابلة للتوسع تتماشى مع مبادئ الحد الأدنى من الامتيازات والامتثال ومتطلبات حوكمة الهوية. نرحب بطلبات المرشحين المتواجدين حاليًا في المملكة العربية السعودية والمرشحين الدوليين المؤهلين الراغبين في الانتقال إلى الرياض.
المسؤوليات الرئيسية: تصميم وتنفيذ نماذج RBAC للمؤسسات باستخدام SailPoint. قيادة عمليات اكتشاف الأدوار، وتنقيب الأدوار، وهندسة الأدوار، وتحسين الأدوار. تطوير أدوار الأعمال، وأدوار تكنولوجيا المعلومات، وتسلسل الأدوار، وتعيينات الاستحقاقات. تكوين ودعم طلبات الوصول، والموافقات، وتوفير الخدمات، وأحداث دورة الحياة، وشهادات الوصول. وضع معايير حوكمة RBAC، وملكيات الأدوار، وعمليات المراجعة الدورية. تحديد الوصول المفرط أو المتضارب أو المهجور أو غير المناسب. دعم سياسات فصل المهام (SoD) ومعالجتها. دمج SailPoint مع الدلائل وتطبيقات المؤسسات وقواعد البيانات ومنصات الحوسبة السحابية. إجراء ورش عمل مع مالكي الأعمال والتطبيقات. إعداد مصفوفات RBAC، وتصاميم الحلول، ووثائق الحوكمة، والإجراءات التشغيلية. دعم عمليات تدقيق IAM والمتطلبات التنظيمية. استكشاف وإصلاح مشكلات إدارة أدوار SailPoint، وسير العمل، والتجميع، وتوفير الخدمات.
الخبرة المطلوبة: 7 سنوات فأكثر من الخبرة في IAM، بما في ذلك خبرة قوية في RBAC للمؤسسات. خبرة عملية مع كل من SailPoint IdentityIQ وIdentity Security Cloud. خبرة قوية في تنقيب الأدوار، وهندسة الأدوار، وحوكمة الأدوار. معرفة بإدارة دورة حياة الهوية، وشهادات الوصول، وتوفير الخدمات، وإدارة الاستحقاقات، وفصل المهام (SoD). خبرة في دمج SailPoint مع تقنيات مثل Active Directory وMicrosoft Entra ID وSAP وOracle وServiceNow وقواعد البيانات وREST APIs. مهارات قوية في إدارة أصحاب المصلحة، والتحليل، والتوثيق. القدرة على العمل في مقر العمل بالرياض.
الشهادة الإلزامية: شهادة محترف معتمد من SailPoint (SailPoint Certified Professional) أو أعلى إلزامية. قد لا يتم النظر في الطلبات التي لا تحتوي على شهادة SailPoint سارية.
المهارات التقنية المفضلة: خبرة في Java أو BeanShell لتخصيص IdentityIQ. مهارات SQL قوية لتحليل الهوية والاستحقاقات. خبرة في REST/SOAP APIs وتكاملات IAM للمؤسسات. فهم لمبادئ SAML وOAuth 2.0 وOpenID Connect وSCIM. معرفة بمبادئ الحد الأدنى من الامتيازات (Least-Privilege) وZero Trust.
التعويضات ودعم الانتقال: راتب شهري يتراوح بين 16,000–20,000 ريال سعودي. رعاية تأشيرة عمل للمرشحين الدوليين المؤهلين. مصاريف السفر الأولية إلى الرياض. سكن أولي لمدة شهر واحد. سيتم مناقشة المزايا الإضافية خلال عملية الاختيار.
Location: Riyadh, Saudi Arabia — Onsite Engagement: Full-Time or 12-Month Contract with Possible Extension Experience: 7+ years in Identity and Access Management Compensation: SAR 16,000–20,000 per month; Joining Timeline: Within 30 days preferred
About the Opportunity
We are hiring an experienced Sail Point-Certified RBAC Expert to support the design, implementation and governance of enterprise Role-Based Access Control capabilities.
The successful candidate will work onsite in Riyadh and collaborate with cybersecurity, technology, application and business teams to build scalable access models aligned with least-privilege, compliance and identity-governance requirements.
Candidates currently based in Saudi Arabia and qualified international candidates willing to relocate to Riyadh are welcome to apply.
Key Responsibilities Design and implement enterprise RBAC models using Sail Point. Lead role discovery, role mining, role engineering and role optimization. Develop business roles, IT roles, role hierarchies and entitlement mappings. Configure and support access requests, approvals, provisioning, lifecycle events and access certifications. Establish RBAC governance standards, role ownership and periodic review processes. Identify excessive, conflicting, orphaned or inappropriate access. Support Segregation of Duties policies and remediation. Integrate Sail Point with directories, enterprise applications, databases and cloud platforms. Conduct workshops with business and application owners. Prepare RBAC matrices, solution designs, governance documentation and operational procedures. Support IAM audits and regulatory requirements. Troubleshoot Sail Point role management, workflow, aggregation and provisioning issues.
Required Experience7+ years of experience in IAM, including strong enterprise RBAC experience. Hands-on experience with both Sail Point Identity IQ and Identity Security Cloud. Strong experience in role mining, role engineering and role governance. Knowledge of identity lifecycle management, access certification, provisioning, entitlement management and SoD. Experience integrating Sail Point with technologies such as Active Directory, Microsoft Entra ID, SAP, Oracle, Service Now, databases and REST APIs. Strong stakeholder-management, analytical and documentation skills. Ability to work onsite in Riyadh.
Mandatory Certification A Sail Point Certified Professional certification or higher is mandatory. Applications without an active Sail Point certification may not be considered.
Preferred Technical Skills Java or Bean Shell experience for Identity IQ customization. Strong SQL skills for identity and entitlement analysis. Experience with REST/SOAP APIs and enterprise IAM integrations. Understanding of SAML, OAuth 2.0, Open ID Connect and SCIM. Knowledge of least-privilege and Zero Trust principles.
Compensation and Relocation Support Monthly package of SAR 16,000–20,000. Employment visa sponsorship for qualified international candidates. Initial travel expenses to Riyadh. One month of initial accommodation. Additional benefits will be discussed during the selection process.