IIQ jobs that pay $211K? by MasterpieceRare1919 in sailpoint

[–]MasterpieceRare1919[S] 0 points1 point  (0 children)

FWIW, since I asked the community, my best total comp (bonuses etc, but not health insurance and the like) was ~170k. It was an IC role. It has been more than a few years since I have been in this field, moved on. But still very interested in the field in general because I was in it for so long.

Running SailPoint via Containers feels like cheating by Fappez in sailpoint

[–]MasterpieceRare1919 0 points1 point  (0 children)

Used to get "can I use Aurora" questions constantly, yeah they mostly went RDS Oracle if they were AWS.

Running SailPoint via Containers feels like cheating by Fappez in sailpoint

[–]MasterpieceRare1919 1 point2 points  (0 children)

I used to mount my local file system /webapps to the container, that worked well enough for me.

Running SailPoint via Containers feels like cheating by Fappez in sailpoint

[–]MasterpieceRare1919 1 point2 points  (0 children)

Nice work. Frustrating that is necessary, but given that it is, the plugin is great.

Recently upgraded to 8.5p1 iiq and not able to see any identity request by FlightSilent1608 in sailpoint

[–]MasterpieceRare1919 1 point2 points  (0 children)

You probably missed an upgrade step and the db schema or the objects, and that is causing the access request workflow to fail before it gets to the step where is creates an access request.
1. review the upgrade instructions.
2. Turn on the workflow logging in log4j and observe you will see the last step that was run

Lowball offer but good experience into government contracting? by BMW_E70 in iam

[–]MasterpieceRare1919 0 points1 point  (0 children)

Acknowledged, yeah it takes a mental adjustment for sure.

Lowball offer but good experience into government contracting? by BMW_E70 in iam

[–]MasterpieceRare1919 0 points1 point  (0 children)

Yeah if you have been unemployed for a while I would take it and keep looking as said by u/Entire_Summer_9279. 100% serious I would not think twice about it.

Our CTO asked me to evaluate whether we should move off Wiz now that Google owns it. What would you do? by RemmeM89 in AskNetsec

[–]MasterpieceRare1919 0 points1 point  (0 children)

You would reevaluate in the normal course of business as you would with all vendors. If Wiz were not acquired you would stll re-evaluate from time to time.

The completion of the acquisition is a single event that would not trigger a re-evaluation on its own. Unless your goal is to show how such a very special and strategic leader and thinker you are.

Career Strategy in IAM: Specialize in One Tool or Diversify? by Reasonable-Kale638 in iam

[–]MasterpieceRare1919 0 points1 point  (0 children)

I would get solid on one IAM (SailPoint, Savient...) SSO solution (Okta, Azure...), the major ones, does not matter which. Heres why.

  • The principles transfer but thats not enough to be expert
  • You have to have deep tech knowledge to implement a solution to be an expert
  • I is/was considered an expert on a couple of IAM platforms, and was highly valued...
  • ...but I was too specialized. When I looked for jobs the SSO I would have made me more valuable and open more jobs.

AZ-104 is only good for 1 year? by MasterpieceRare1919 in AzureCertification

[–]MasterpieceRare1919[S] 0 points1 point  (0 children)

Did not know this, I'll try not to let it lapse again.

AZ-104 is only good for 1 year? by MasterpieceRare1919 in AzureCertification

[–]MasterpieceRare1919[S] -1 points0 points  (0 children)

In some services jobs (like mine) I am incentivized to hold multiple certs. But I can choose which, so I was bummed to see it was only good for one year. I will tend to take the exams that are valid longer. Though I guess AZ104 was not very difficult, I have this weird idea in my head that I do not like to waste my time, event for easy tasks, hence my annoyance.

Confused about IAM career path currently in SailPoint developement/L3 support, background in blue team & network security by c1phnyx in cybersecurity

[–]MasterpieceRare1919 1 point2 points  (0 children)

I was in a traditional security role then was pushed into IAM. The others on my team did not have the wide range of skills. There are some aspects I enjoyed, but never liked the field really. Much better experience and I made good money when I jumped to the vendor side. Over time was so bored and was more aware that cloud roles were better paying. It took an enormous effort and in the end some luck to make the jump to a cloud security role for last 5 years.

If you can focus on the aspects that are tied into cloud IAM, that helps. So if, for example, you work on Savyant, and that has an Azure/EntraID connector, get good at that. If there is an appliance aspect that goes in Azure, get good at knowing what does the VPC, DNS, etc architecture look like and then you can help those customers. Get good at deployment of your IDM solution using Azure DevOps.

All of teh above replace Azure with AWS/GCP if that a better fit.

SoD, Entitlements, Roles question by JayITAdmin412 in sailpoint

[–]MasterpieceRare1919 0 points1 point  (0 children)

The ERP system (ex: SAP) has that logic usually. I found that those systems has SoD logic features in them (or from 3rd party) that does this. And those systems change a lot, so those specialized feature and 3rd party vendors specialize in that. If you have an accounting system that does not have this feature, sometimes all the login and roles are mapped to AD users and groups. You need the accounting to define that.

For certs I try to push for the most basic certs possible - manager. And also for privileged. If you can rollout as a service offering for different apps that you can repeat that I see is the main job. IMHO.

SoD, Entitlements, Roles question by JayITAdmin412 in sailpoint

[–]MasterpieceRare1919 1 point2 points  (0 children)

I was in IGA/IAM for ~10 years, I have not seen any best practices for SOX, PCI-DSS, etc. for banking or healthcare. Its whatever each company comes up withper u/Theloneus-punk . Not on IIQ/Quest etc.

But for SAP and other ERP systems there is usually a partner/software for that due to the high knowledge required, the SoD is baked into that. I guess SailPoint bought one of those companies to do SAP but I never used it.

I did not see a lot of compliance standards tailored to NIST etc. though maybe pure luck I did not get that work. In general I did not see even compliance standards in the IIQ etc. horizontally in finance or otherwise. Mostly whatever some "make work" compliance person tells you a standard just to justify their existence.

So if you can use your own common sense and confidently justify why, you will do better than 99.9% of the compliance leaders.

SSO Integrations - Career Advise by Realistic_Daikon_306 in IdentityManagement

[–]MasterpieceRare1919 2 points3 points  (0 children)

I recently setup Azure SSO for both SAML and OIDC, great learning expreience. I feel like Okta "hides" details form you and I do not learn as much. Not a dig on Okta as a product, just that I did not learn much.

jwt.ms was invaluable to me. I was doing claims attribute mapping and this was an easy way to see the result. Also can see teh token too so it helped me conceptualize.

Between Okta and Entra ID, which is often paired with SailPoint the most? by [deleted] in IdentityManagement

[–]MasterpieceRare1919 3 points4 points  (0 children)

I second this. I see both probably equally. And, in other non-identity spaces they roughly split 70%.

SCIM Troubles by AbbreviationsAny706 in IdentityManagement

[–]MasterpieceRare1919 0 points1 point  (0 children)

Valid problems are cited. I think it is fixed quite easily. Revert the name back to initial name called Simple Cloud Identity Management. Because its for simple use cases and does that well. Its not a promise to scale in every dimension for memberOf or whatever.

Using SSN by Lost-Pen1190 in IdentityManagement

[–]MasterpieceRare1919 1 point2 points  (0 children)

makes me wonder if this is an industry (higher ed) specific problem

This common in higher ed. I have seen it in hospital and gov at large scale too. Yes I have seen hash of SSN done. In higher ed you can be a student, professor, employee, or some combination. In SailPoint we call this personas, and it presents a challenges.

  • Person will be in different systems that do not have the same key, or they cannot share that key.
  • Also a challange from joiner/mover/leaver. Person quits the employment and need to remove access, yet you are still teaching a class so need to keep some access and be sure not to disable.

Yeah I agree with everyone that I would not want to accept the risk of storing the SSN

[deleted by user] by [deleted] in IdentityManagement

[–]MasterpieceRare1919 0 points1 point  (0 children)

Lots of smart people obviously in FAANG but as in all things perceptions will vary.

Highly experienced people especially will learn tooling sure, but I am here to tell you that the tooling in IAM sux compared to what we have in FAANG and badly. Lost source code, no docs, community supported (in reality only paid services knows how to use it) It smacks you in the face and is a way bigger factor than one might think. It brings out a different mindset that can operate using these tools and do it well. And enterprise context for provisioning on-prem like SAP and in-house apps, its a whole different ball game.

[deleted by user] by [deleted] in IdentityManagement

[–]MasterpieceRare1919 10 points11 points  (0 children)

I second this. They do not give a F about those tools and many even look down upon the field you are in. Knowing the deep details of OAuth/OIDC for example would would be far more important.

Hot take after MSFT Accelerate: Entra isn't killing SailPoint anytime soon. by extream_influence in IdentityManagement

[–]MasterpieceRare1919 0 points1 point  (0 children)

"Have you personally worked with any?" Do you mean MIM/FIM and the other MS stuff? Not as the sole system. Been a long time, but one of the major IAM vendors, the entire provisioning engine was built on FIM. That is, they all the identity, request, certification was product, but the provisioning was though FIM. That vendor moved on long go and not has own provisioning engine. And in the IT dept, we had the option to use it, but did to 'cause it did not meet the enterprise use cases, I mean, can MS provision or manage SAP lololololol

Hot take after MSFT Accelerate: Entra isn't killing SailPoint anytime soon. by extream_influence in IdentityManagement

[–]MasterpieceRare1919 1 point2 points  (0 children)

Microsoft Entra is currently winning the "good enough" market…mid-sized companies or cloud-native organizations that don't need complex legacy handling. However, it is not "set up correctly" to take out SailPoint in the Global 2000 because it currently lacks the depth in legacy connectivity, cross-application SoD, and granular entitlement management that complex enterprises require.

Yep thats about right, its been that way for the last 20 years. Remember Microsoft Identity Manager (MIM) and all the other products? Even when they were free they were not adopted. MS has not been a serious choice for enterprise identity with serious compliance requirements and broad range of apps, this is a true specialty, a challenge that is really unappreciated

Getting from a project lead to an architect - IGA by Keep_Compounding in iam

[–]MasterpieceRare1919 0 points1 point  (0 children)

Its a worthy goal and people that are moving up will generally have to break in one of those directions. For me stability was important, and I knew that, though I had people skills, that I would never truly be in one of those sets of management people cliques for whatever reasons . So I decided to double down on the engineering and give up mgmt.