This guest post reflects the views of the author and does not necessarily represent the views of KuppingerCole Analysts. It is provided for informational purposes only and should not be interpreted as independent research, analysis, endorsement, or advisory services by KuppingerCole Analysts.
From developer to architect, sysadmin to IGA consultant - a structured guide to entering identity management from any IT background
Not long ago, identity management meant one thing in most organisations: a sysadmin who managed Active Directory groups, a password policy that enforced a change every twelve months, and a rough understanding of who was in which department. That was sufficient. It was not glamorous, but it worked well enough for the threat environment of the time.
The world that produced that model no longer exists.
Today, the same discipline has grown a full vocabulary of hashtag-worthy abbreviations (#IGA, #PAM, #CIAM, #ITDR, #NHI, #ZeroTrust) fills dedicated conference tracks at every major security event, and commands the attention of CISOs, regulators, and board-level risk committees simultaneously. IAM has become, without much ceremony, one of the most structurally important specialisations in enterprise security. It is also one of the most underserved in terms of qualified talent.
I have watched this shift accelerate over the past two years from the recruiting and market research side, and the pattern is now legible enough to describe clearly. In this piece I want to explain why it is happening, what it means for professionals who want to move toward IAM, and specifically which existing skills and backgrounds translate most directly into the roles the market is actually hiring for. The data and job market references throughout this article draw primarily on the German market, which I have analysed in detail. The structural patterns - which technical backgrounds transfer, which platforms are worth learning, and how to build credibility without years of IAM-specific experience - apply broadly across European and global markets.
Why IAM Has Real and Durable Career Potential
The demand for IAM professionals is not a trend driven by vendor marketing cycles. It is driven by three structural forces that are not going away.
The first is regulation. NIS2, which came into force across EU member states in October 2024, mandates that organisations in critical sectors implement identity-based access controls, enforce least-privilege principles, and demonstrate governance over who can access sensitive systems. DORA, the Digital Operational Resilience Act applying to financial entities from January 2025, adds requirements for managing access to critical functions and third-party access governance. GDPR has long required organisations to demonstrate that personal data is accessed only by those with legitimate need. These are not soft compliance expectations. Non-compliance carries penalties reaching 4% of global annual revenue. Organisations that have not yet invested in mature IAM programmes are building them under regulatory pressure, and they are discovering that they cannot find enough people to do the work.
The second is the threat landscape. Identity-based attacks now represent the primary vector in the majority of enterprise breaches. Organisations are investing in IAM not only because regulators require it, but because their insurers increasingly mandate it and their incident post-mortems keep pointing to the same root causes: over-privileged accounts, unmanaged service accounts, access that was never removed after role changes, and credentials that were never properly governed.
The third, which is obviously an obvious consequence of the first two points, is the talent gap, and it is severe. In my analysis of 10,098 open IAM positions on StepStone you can check the data in detail.
What matters for anyone considering a move toward IAM is this: the demand is structural and regulatory in origin, the talent supply is not keeping up, and the organisations feeling the most pressure (German banks, insurers, manufacturers, and public sector bodies) are among the most willing to pay for qualified people. The door is open. The question is how to position yourself to walk through it.
What Technical Tools Experience You Can Bring Directly Into IAM
The fastest transitions into IAM are the ones where a professional arrives with technical skills that map onto specific platform requirements without needing to be retrained from zero. These mappings are more specific than most career guides acknowledge.
Java developers → SailPoint. SailPoint is the IGA platform that saw the largest year-on-year demand increase in German job postings in 2025. It exists in two distinct forms, and the distinction matters for where you invest your learning. SailPoint IdentityIQ (IIQ) is the legacy on-premises product, widely deployed in large German enterprises, particularly banking and insurance, that have not yet migrated to the cloud. IIQ is Java-based at its core: custom connectors, provisioning rules, correlation logic, and workflow automation are all written in Java and BeanShell, a Java-compatible scripting language. A Java developer can reach productive implementation depth on IIQ faster than almost any other route into SailPoint consulting. However, SailPoint's strategic direction is firmly toward Identity Security Cloud (ISC), its SaaS platform. New implementations increasingly favour ISC, and SailPoint's own certification programme now centres on it. The practical recommendation for Java developers is to understand both: IIQ knowledge is immediately billable given the volume of existing on-premises deployments, but ISC fluency is where the market is heading. Starting with IIQ concepts and transitioning toward ISC as you build experience is the realistic path for most consultants entering the SailPoint ecosystem today.
.NET and C# developers → Omada. Omada Identity is a European IGA platform with strong market penetration in German mid-market and public sector organisations. It runs on the Microsoft .NET stack. Workflow customisation, connector development, and integration logic in Omada are written in the same language ecosystem that .NET developers already work in daily. The transition here is one of domain knowledge, not technology relearning. A C# developer who spends two to three months learning Omada's IdentityPROCESS+ methodology and identity governance concepts can arrive in the consulting market at a level that would take a non-developer significantly longer to reach.
Python developers and scripters → Cross-platform IAM automation. Every major IAM platform (Okta, SailPoint Identity Security Cloud, Microsoft Entra ID, CyberArk) exposes REST APIs. Python SDKs exist for most of them. The work of writing provisioning scripts, building automated joiner/mover/leaver workflows, scripting access certification reporting, and integrating IAM platforms with HR systems or ticketing tools falls naturally to Python developers with API experience. This is platform-agnostic value, which means Python skills open doors across the entire IAM toolset rather than in one specific niche.
PowerShell experience → Microsoft identity stack. Microsoft Entra ID remains the most widely deployed identity platform in Germany, present in 68% of IAM job postings. Professionals who manage Active Directory, Azure AD Connect, Group Policy, and Entra conditional access policies through PowerShell already operate the foundation layer of the German enterprise IAM market. The transition requires adding governance knowledge and regulatory context on top of operational fluency.
LDAP and directory services experience → Any enterprise IAM project. LDAP is the protocol that underpins identity resolution across virtually every enterprise IAM integration. Professionals who have managed OpenLDAP, Novell eDirectory, or Red Hat Directory Server carry a conceptual understanding of directory hierarchies, attribute mapping, and schema design that translates directly into IAM connector configuration, source correlation, and identity data quality troubleshooting.
What Field Experience Transfers Into IAM, and Where It Lands
Tools are one dimension. The other is the broader professional background that shapes which IAM roles you are naturally positioned for. The German market rewards several transition paths consistently.
Cybersecurity analysts → PAM and ITDR. The mental model of a security analyst (threat vectors, privilege escalation paths, lateral movement techniques, log analysis) maps directly onto Privileged Access Management and Identity Threat Detection and Response. A security analyst who understands how attackers exploit over-privileged service accounts or compromised credentials arrives in PAM and ITDR with a perspective that purely administrative IAM professionals lack. CyberArk, BeyondTrust, and the emerging ITDR vendors are the platforms where this background translates most directly.
System administrators and engineers → IGA operations and implementation. This is the most established transition path in the market, and it works because sysadmins already perform the operational core of IAM: provisioning accounts, managing group memberships, handling access requests, maintaining the directory. The gap to close is strategic and conceptual: identity governance frameworks, regulatory compliance context, IGA platform knowledge, and the ability to speak to access decisions in business language rather than technical configuration terms. A sysadmin who adds SailPoint or Omada platform knowledge and earns a vendor certification does not look like someone changing careers. They look like an IAM professional who already understands the infrastructure.
DevOps engineers and CI/CD practitioners → Cloud IAM and machine identity. The shift toward Zero Trust architectures, cloud-native IAM, and the governance of non-human identities is pulling DevOps skills directly into the identity domain. DevOps professionals who understand Infrastructure-as-Code, secrets management with tools like HashiCorp Vault, container identity in Kubernetes environments, and CI/CD pipeline security bring a technical foundation that is specifically relevant to the fastest-growing corner of the market. According to Entro's follow-up NHI & Secrets Risk Report H1 2025 (July 2025; public summary at nhimg.org) the workload-to-human identity ratio in German organisations reached 144:1 by the end of 2025 - up from 92:1 the previous year (2025 State of Non-Human Identities and Secrets in Cybersecurity, September 2024). Managing that explosion of machine identities requires people who understand how software is deployed, not just how users are managed.
Cloud architects and engineers → Cloud IAM specialisation. Deep familiarity with AWS IAM policy structures, Azure RBAC and Entra ID Governance, or GCP Identity is no longer a subset of cloud knowledge, it is an IAM specialisation in its own right. Cloud-heavy organisations dealing with multi-cloud entitlement sprawl, CIEM (Cloud Infrastructure Entitlement Management), and hybrid identity architectures are actively looking for people who understand both the cloud layer and the identity governance layer simultaneously. This is a relatively young specialisation where the talent supply is even thinner than in traditional IGA or PAM.
AI and machine learning practitioners → The emerging ITDR and AI agent identity frontier. This is the transition path that barely existed two years ago. Identity platforms are now embedding ML-based anomaly detection, AI-driven access recommendations, and behavioural analytics into their core governance capabilities. At the same time, the governance of AI agent identities - managing what credentials an autonomous AI process can access, under what conditions, and with what accountability trail - is a problem that no established professional community has fully solved yet. Professionals with ML background who understand model behaviour, probabilistic risk scoring, and anomaly detection have an opportunity to enter IAM at the frontier of its most technically demanding open questions.
IT consultants → IAM programme management and advisory. The most overlooked supply of IAM talent is in the general IT consulting community. Professionals who have delivered enterprise technology programmes, managed stakeholder relationships across business and IT, and translated business requirements into technical architectures are carrying skills that senior IAM roles depend on but rarely find in purely technical candidates.
Education: Starting from Scratch or Catching Up Fast
If you are planning a longer-term path from the beginning, a Bachelor's degree in Computer Science, Applied Informatics, or Business Informatics (Wirtschaftsinformatik) remains the standard entry expectation at German consulting firms and enterprise teams. The degree choice shapes where you land. Wirtschaftsinformatik, offered at universities including TU Darmstadt, University of Mannheim, and Leuphana University Lüneburg, specifically develops the combination of IT architecture understanding and business process literacy that senior IAM consulting roles require. A Master's in Cybersecurity or Information Security - offered at TU Berlin, Ruhr University Bochum, and the University of Applied Sciences Munich (Hochschule München), among others - provides deeper technical depth for those targeting engineering and architecture roles. If you are already in a Bachelor's programme in a related field, a specialisation in cybersecurity or digital identity at Master's level is a direct path to IAM without requiring a full career pivot.
If you want to transition as quickly as possible with existing IT experience, the certification sequence that produces the best results in the German market follows a clear order:
Free and immediate (start today):
- SailPoint's Identity Security Leader credential is 4.5 hours of structured, vendor-agnostic IGA learning available without charge through SailPoint's Identity University. It removes the conceptual gaps that disqualify candidates at screening.
- Microsoft's free SC-900 (Security, Compliance and Identity Fundamentals) is a two-to-three-week self-study path that establishes the Microsoft identity vocabulary that appears in nearly every German IAM context.
Short investment, high return (4–8 weeks):
- Microsoft SC-300 (Identity and Access Administrator) is a four-to-six-week preparation path that leads to a certification directly relevant to Entra ID configuration.
- Okta's Professional certification path typically requires six to eight weeks of study plus access to a free Okta developer account for hands-on practice; the Okta Certified Professional exam costs around $250 and validates the foundational Okta skills.
- Keycloak deployment and configuration, while not vendor-certified, can be set up in a home lab environment over a weekend and learned to production-competency level in four to six weeks; it teaches SAML, OIDC, OAuth 2.0, and LDAP federation in a free, open-source context.
Medium investment, specialist credibility (2–4 months):
- CyberArk's Defender certification covers PAM architecture, vault configuration, and privileged session management; the official training is a two-to-three-week instructor-led course, and the exam is widely recognised in German banking and critical infrastructure hiring.
- SailPoint's Identity Security Cloud Administrator credential (formerly IdentityNow) requires approximately two months of structured learning plus hands-on platform access; SailPoint recommends six months of practical experience before sitting the full engineer certification, but the administrator path is accessible earlier and already valued by consulting partners.
- Omada's partner training programme is the most direct route into Omada-specific skills for .NET developers; the programme is delivered through Omada's partner network and typically runs two to four weeks of structured content.
- CIAM (Certified Identity and Access Manager) from the Identity Management Institute is the most IAM-specific governance credential available and is directly relevant for those targeting programme management and advisory roles. It requires roughly 4 years of combined IT background to qualify, involves around 2 months of self-study, and costs $390 including the study guide and up to three exam attempts. For professionals already working in IT who are transitioning toward IAM consulting or programme ownership, it sits comfortably within a two-month preparation window.
IAM did not become the most structurally important security discipline by accident. It became that because everything else in enterprise security - Zero Trust, NIS2 compliance, cloud adoption, AI agent governance - ultimately depends on knowing who has access to what, when, and why. The organisations that cannot answer that question clearly are the ones that appear in the breach reports. The organisations that can are the ones investing aggressively in building the teams that make it possible.
The market is not waiting for the university pipeline to produce certified IAM graduates. It is pulling in developers who already know Java, consultants who already understand regulatory frameworks, DevOps engineers who already manage secrets, and security analysts who already think in terms of privilege escalation. The platforms, certifications, and learning paths exist to close the remaining gaps. The question is whether you recognise the skills you are already carrying as the entry credential they actually are.
Two years from now, the professionals who acted on that recognition in 2026 will be the senior specialists and architects that the next round of recruiters cannot find. That pattern is already visible in the data. The only variable is which side of it you end up on.