Kalson Karki
@kalsonkarki
Senior IAM engineer specializing in SailPoint IdentityNow/IQ, IAM automation, and PAM integrations for compliant enterprise access.
What I'm looking for
I’m a Sr. IAM Engineer with over 7 years of experience in IAM (Identity Access Management) and Governance programs across healthcare and insurance sectors. I specialize in SailPoint IdentityNow cloud-native deployments, lifecycle automation, and Privileged Access Management, while also supporting legacy IdentityIQ migrations into modern cloud IAM.
I deliver end-to-end identity governance and administration using SailPoint IdentityNow and SailPoint IdentityIQ—covering access certifications, role engineering, and application onboarding. I configure authoritative and target sources, including IdentityNow connector integrations for SCIM 2.0 provisioning and identity lifecycle orchestration via workflows and lifecycle automation.
I strengthen security and operational control by engineering least-privilege access with CyberArk Privileged Access Manager, administering CyberArk PVWA and CyberArk PSM session controls for Just-In-Time Privileged Access. I also implement SSO and federation with Okta using SAML 2.0 and OpenID Connect, and manage directory services including Active Directory and Microsoft Entra ID, with hybrid SCIM-based provisioning.
On the platform side, I enforce Zero Trust principles across AWS IAM and Azure Conditional Access policies for cloud workload identities, and standardize RBAC/ABAC models and entitlement catalogs to support access reviews and Identity Threat Detection and Response (ITDR). I build automation with Python/Java REST integrations and IdentityNow Transforms/Rules to reduce manual joiner-mover-leaver overhead, and I validate SOX, HIPAA, and SOC 2 readiness through access certification campaigns and audit evidence generation.
Experience
Work history, roles, and key accomplishments
Manage SailPoint IdentityNow identity governance and lifecycle automation, onboarding authoritative and target sources and configuring RBAC/access profiles and SCIM 2.0 provisioning. Integrate Okta SSO federation and CyberArk PAM for least-privilege/JIT access, and run identity certifications for HIPAA/SOC 2-aligned audits.
Build and administer SailPoint IdentityIQ governance for insurance joins/movers, including role mining, access certifications, and application onboarding. Implement SSO and entitlement synchronization via PingFederate and Okta, and manage CyberArk PAM-backed privileged access for SOX-controlled workflows.
Support SailPoint IdentityIQ onboarding and lifecycle provisioning for retail and corporate applications using joiner-mover-leaver policies and Birthright Access. Administer directory aggregation (Active Directory/LDAP), coordinate Okta UDD and lifecycle provisioning with SAML 2.0 assignments, and produce PCI-DSS/SOX access review artifacts with basic UEBA alerting support.
Education
Degrees, certifications, and relevant coursework
Southeast Missouri State University
Master of Science, Cybersecurity
Earned a Master of Science in Cybersecurity at Southeast Missouri State University.
London Metropolitan University
Bachelor of Science, Cybersecurity and Networking
Earned a Bachelor of Science in Cybersecurity and Networking at London Metropolitan University.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Kalson?
You can contact Kalson and 90k+ other talented remote workers on Himalayas.
Message KalsonGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
