Knowledge Article

Program staffing considerations

Author

  • ryan_cutter

    SailPoint

Staffing the right mix of roles is critical for a successful identity security program. This goes beyond hiring a few IT specialists; it means assembling a cross-functional team that includes executive sponsor(s), program managers, technical experts, and stakeholder representatives from various departments (e.g., HR, Compliance, Finance).

In this article, we’ll look at common roles, their responsibilities, and typical time commitments. We’ll also examine why engaging a certified implementation partner or SailPoint professional services can help your program succeed more quickly and sustainably.

Key objectives / takeaways

  • Identify the key roles typically required in an identity security program.
  • Understand general role responsibilities and time commitments.
  • Recognize the value of engaging certified implementation partners or SailPoint professional services.
New employee.gif

Roles and responsibilities

Below is a breakdown of common roles, typical time commitments, and the core responsibilities each role plays in the success of your identity security program. These roles may come from various departments, such as IT, Security, HR, or GRC, and can include employees with titles ranging from analyst to senior manager.

Adjust staffing as needed to match the size, complexity, and specific business needs of your program, keeping in mind the value of expert assistance from a certified implementation partner or SailPoint professional services team.

Program Manager

Helps coordinate and run the program while managing the wider influence of the program.

  • During Implementation: 10-20 hours per month
  • Post Implementation: 1-2 hours per month

Project Manager

Ensures adherence to scheduled delivery. Should be tech savvy enough to understand program requirements.

  • During Implementation: 10-20 hours per month
  • Post Implementation: 1-2 hours per month

Technical/Security Architecture Lead

Collaborates on overall solution design and oversight on implementation deliverables.

  • During Implementation: 10-14 hours per month
  • Post Implementation: 0-1 hours per month

Identity Security Cloud Administrator

Owns day to day operations of the application, addresses any automated alerts sent from Identity Security Cloud. Main point of contact for SailPoint Support.

  • During Implementation: 16-20 hours per month
  • Post Implementation: 8-14 hours per month

Identity Security Cloud Engineer

Owns maintenance and ongoing development of cloud-based identity security solutions, including design, configuration, application onboarding, and the writing and implementation of transforms, workflows, and rules.

  • During Implementation: 0-1 hours per month
  • Post Implementation: 8-14 hours per month

Business/Systems Analyst

Communicates overall business processes needing to be factored into solution such as resource onboarding, role based access, out of band provisioning, and certification compliance.

  • During Implementation: 8-12 hours per month
  • Post Implementation: 0-1 hours per month

Source Owner(s)

Acts as a point of contact to provide or validate source specific details associated with connectivity, account and access management.

  • During Implementation: 2-4 hours per month
  • Post Implementation: 1-2 hours per month

Tester

Creates test cases based on requirements, stages data for test cases, and executes System Integration Testing and User Acceptance Testing.

  • During Implementation: 20-30 hours per month
  • Post Implementation: 0-1 hours per month

Risk/Compliance Officer

Works closely with the Identity Security Cloud Administrator during certification campaigns to kick off proper campaigns and review campaign reports to satisfy compliance needs

  • During Implementation: 2-6 hours per month
  • Post Implementation: 2-6 hours per month

Support Helpdesk

Administrates account-level issues associated with enabling, disabling, and unlocking. Views activity and interacts with identity data but they cannot make changes to sources, apps, and many other features within Identity Security Cloud.

  • During Implementation: 6-10 hours per month
  • Post Implementation: 8-10 hours per month

Virtual Appliance Engineer

Installs/Configures Virtual Appliance image, troubleshooting connectivity or other connector related issues. UNIX platform background is strongly recommended.

  • During Implementation: 2-3 hours per month
  • Post Implementation: 0-1 hours per month

Network Engineer

Provides guidance on internal network structure for components in scope, typically during implementation.

  • During Implementation: 2-3 hours per month
  • Post Implementation: 0-1 hours per month

Additional considerations

  • Budgeting: Account for not only upfront costs (licensing, partner fees) but also ongoing operational expenses such as staff training and certifications when managing program budgets.
  • Cross-functional alignment: Encourage collaboration between IT, Security, HR, and other departments, ideally through a steering committee, that manage user data or access requests. This fosters a more holistic identity program.
  • Continuous training: SaaS identity security solutions evolve quickly. Regularly update staff on role-based training, product updates and release notes, security threats, and compliance changes through ongoing training and certifications.
  • Resource flexibility: Some roles may be combined or scaled up/down depending on your program’s maturity and complexity. Ensure you periodically revisit staffing levels.
  • Automation opportunities: Look to automate repetitive tasks (e.g., routine provisioning) so high-value staff can focus on architecture, strategy, and governance.
  • Clear escalation paths: Define how issues or risks surface to the executive sponsor and steering committee. Prompt action often prevents larger setbacks.
  • Leverage community and networking: Engaging with the SailPoint community, attending user groups, or participating in webinars can provide additional insights and best practices from peers.

Engaging a certified implementation partner or SailPoint professional services

When launching or scaling an identity security program, organizations often benefit from the expertise of certified partners or SailPoint professional services. These teams bring invaluable experience with:

  • Accelerating deployment times through proven implementation methodologies.
  • Providing specialized technical and strategic insights for complex identity governance challenges.
  • Offering training and knowledge transfer to your internal staff, reducing long-term dependence on external resources.

In a nutshell

Building an effective identity security program requires the right people in the right roles, collaborating under a well-defined governance structure. By clarifying responsibilities, engaging cross-functional teams, and leveraging specialized expertise—either in-house or through certified partners—you’ll set the stage for smooth implementations and long-term program success.

Consider the following next steps:

  • Evaluate your current team to identify role gaps. Recruit or train staff to cover those essential skill areas.
  • Develop clear RACI matrices to ensure accountability and prevent duplicative efforts.
  • Engage with a SailPoint-certified implementation partner or professional services to fast-track deployments or handle complex integrations.
  • Attend SailPoint's annual Navigate Conference, other events and webinars, and join SailPoint user groups to exchange insights on staffing models, partner experiences, and ongoing identity security best practices.