Identity and Access Security Engineer

Jobtailor

Baltimore (MD)

On-site

USD 120,000 - 160,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor seeks an IAM security professional to govern identity controls across Okta, Entra ID, and Active Directory. You will manage privileged access, implement MFA/SSO, and lead remediation of exposure gaps in regulated environments.

You will work with Infrastructure and Security teams to improve identity lifecycle workflows, perform access reviews, and contribute to evidence collection and policy reporting.

Qualifications

  • Bachelor's degree or equivalent professional experience in cybersecurity, CS, info systems, engineering, or related field.
  • 4–8 years of information security, identity and access management, or related work.
  • Hands-on with identity controls in Microsoft Entra ID and Active Directory.
  • Experience with Okta or another enterprise identity provider preferred.
  • Hands-on with privileged-access management platforms; CyberArk preferred.
  • Experience with BloodHound Enterprise or similar for attack-path analysis.
  • Knowledge of identity governance, access certification, and role governance.
  • Strong communication skills and cross-team collaboration.
  • Authorized to work in the United States without current or future sponsorship.

Responsibilities

  • Own day-to-day security governance and engineering of identity controls across Okta, Entra ID, AD, MFA, Conditional Access, privileged access, and identity lifecycle.
  • Design, implement, operate, and improve CyberArk privileged-access controls, including onboarding, rotation, and evidence collection.
  • Govern privileged human and non-human identities across admin, service, and machine accounts.
  • Identify unmanaged or noncompliant accounts and coordinate remediation or retirement.
  • Develop and maintain CyberArk safes, policies, and recovery documentation.
  • Operate BloodHound Enterprise to analyze attack paths and privilege relationships.
  • Translate findings into prioritized remediation plans and validate via rescans and evidence.

Skills

Identity Governance
Privileged Access Management
Microsoft Entra ID Administration
BloodHound Enterprise Analysis
Access Reviews and Remediation
PowerShell Scripting
REST API Automation
Credential Rotation
Active Directory Security
MFA / SSO Implementation

Education

Bachelor's degree in cybersecurity, computer science, information systems, engineering, or equivalent

Tools

Okta
Microsoft Entra ID
Active Directory
CyberArk
BloodHound Enterprise
SIEM
Microsoft 365
OAuth 2.0
SAML
SCIM

Job description

  • Own day-to-day security governance and engineering of identity controls across Okta, Microsoft Entra ID, Active Directory, MFA, Conditional Access, privileged access, and identity lifecycle workflows
  • Design, implement, operate, and improve CyberArk privileged-access controls, including account discovery, vault onboarding, credential rotation, access workflows, session controls, monitoring, break-glass access, and evidence collection
  • Govern privileged human and non-human identity lifecycles, including administrator accounts, service accounts, application credentials, scheduled-task accounts, emergency accounts, and machine identities
  • Identify unmanaged, misconfigured, inactive, or noncompliant privileged and service accounts and coordinate onboarding, remediation, or retirement
  • Develop and maintain CyberArk safes, platforms, policies, account ownership models, reconciliation processes, permissions, procedures, and recovery documentation
  • Operate BloodHound Enterprise to analyze attack paths, Tier Zero relationships, excessive privilege, nested groups, delegated permissions, and identity weaknesses
  • Translate BloodHound findings into prioritized remediation plans and validate remediation through rescanning, attack-path analysis, ticket evidence, exceptions, and exposure metrics
  • Maintain Tier Zero and critical-identity models across Active Directory, Entra ID, privileged platforms, administrative systems, and infrastructure
  • Assess and improve Active Directory security, including privileged groups, delegated rights, nested groups, service accounts, stale privileges, trusts, and administrative-tier separation
  • Partner with Infrastructure to reduce standing privilege and implement secure administrative patterns
  • Integrate applications with Okta and Entra ID using secure authentication, authorization, SSO, provisioning, deprovisioning, and lifecycle-management patterns
  • Lead access reviews for critical systems, privileged roles, SaaS platforms, and regulated processes
  • Partner with HR, Compliance, Operations, and application owners to improve identity lifecycle workflows
  • Integrate identity telemetry into SIEM and investigation workflows and support investigations into suspicious authentication, credential misuse, privileged activity, role changes, OAuth grants, service-account behavior, and identity-based lateral movement
  • Support SaaS identity, authorization, administrative-role, and data-access controls
  • Define and report identity-security metrics and maintain standards, procedures, evidence, risk documentation, metrics, and leadership reporting
  • Drive remediation of audit findings, penetration-test findings, policy exceptions, BloodHound findings, and access-control gaps
  • Provide guidance on secure identity patterns and support continuous improvement and new technology adoption
Requirements
  • Bachelor's degree in cybersecurity, computer science, information systems, engineering, or a relevant field, or equivalent professional experience
  • 4–8 years of experience in information security, identity and access management, infrastructure security, cloud security, or related technical work
  • Hands-on experience administering or engineering identity controls in Microsoft Entra ID and Active Directory
  • Experience with Okta or another enterprise identity provider strongly preferred
  • Hands-on experience with a privileged-access management platform; CyberArk experience strongly preferred
  • Experience identifying and remediating Active Directory or cloud identity attack paths using BloodHound Enterprise, BloodHound Community Edition, or a comparable platform
  • Experience governing service accounts, application identities, privileged accounts, secrets, and other non-human identities
  • Experience with access reviews, MFA, SSO, provisioning, deprovisioning, Conditional Access, and identity governance in a regulated environment
  • Experience with PowerShell, Microsoft Graph, REST APIs, or other automation methods
  • Experience working with infrastructure teams to remediate complex privilege relationships without disrupting business-critical systems
  • CISSP, Microsoft identity/security, CyberArk, Okta, or other relevant certifications preferred
  • Knowledge of Okta, Microsoft Entra ID, Active Directory, Microsoft 365, MFA, Conditional Access, SSO, SCIM, SAML, OAuth 2.0, OpenID Connect, lifecycle automation, group governance, enterprise applications, managed identities, and application registrations
  • Knowledge of CyberArk vaulting, safes, platforms, credential rotation, reconciliation, privileged session controls, account discovery, onboarding, access workflows, reporting, service accounts, emergency access, and operational recovery
  • Knowledge of BloodHound Enterprise or comparable attack-path management, Tier Zero analysis, transitive privilege, nested groups, delegated permissions, remediation validation, and exposure metrics
  • Knowledge of identity governance, access certification, role and entitlement governance, segregation of duties, exception handling, contractor/vendor access, evidence collection, and control reporting
  • Knowledge of structured data analysis, identity inventory reconciliation, workflow automation, and integrations with ticketing, SIEM, and reporting platforms
  • Strong communication skills and ability to work across technical teams, business owners, Compliance, HR, and Operations
  • Must be authorized to work in the United States without current or future employer-sponsored work authorization
Core Competencies

Demonstrates expertise in identity and access management, particularly with Microsoft Entra ID, Active Directory, and CyberArk. Proficient in governing privileged access, conducting access reviews, and remediating identity-related security issues.

Highest-signal resume keywords
  • Identity Governance
  • CyberArk Privileged-Access Management
  • Microsoft Entra ID Administration
  • BloodHound Enterprise Analysis
  • Access Reviews and Remediation
ATS Optimization Keywords
Hard Skills
  • Identity Controls Engineering
  • Privileged Access Management
  • Active Directory Security
  • MFA Implementation
  • SSO Integration
  • PowerShell Scripting
  • REST API Automation
  • Credential Rotation
  • Identity Lifecycle Management
  • Access Workflow Design
Soft Skills
  • Strong Communication Skills
  • Collaboration Across Teams
Certifications & Qualifications
  • CISSP
  • Microsoft Identity/Security
  • CyberArk Certification
  • Okta Certification
Industry Keywords
  • Identity and Access Management
  • Infrastructure Security
  • Cloud Security
  • Regulated Environment
  • Privileged Accounts Governance
  • Service Accounts Management
  • Access Certification
  • Segregation of Duties
  • Evidence Collection
  • Control Reporting
Tools & Technologies
  • Okta
  • Microsoft Entra ID
  • Active Directory
  • CyberArk
  • BloodHound Enterprise
  • SIEM Integration
  • Microsoft 365
  • OAuth 2.0
  • SAML
  • SCIM
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Identity and Access Engineer
Senior Identity and Access Engineer

Jobtailor • Town of Florida (NY)

Hybrid
USD 120,000 - 180,000
None
Identity & Access Management Engineer
Identity & Access Management Engineer

Jobtailor • Westbrook (ME)

On-site
USD 120,000 - 180,000
Manager, Privileged Access Management – PAM
Manager, Privileged Access Management – PAM

Jobtailor • Town of Florida (NY)

On-site
USD 120,000 - 190,000
Cyber Security Identity Staff Engineer
Cyber Security Identity Staff Engineer

Jobtailor • California (MO)

On-site
USD 110,000 - 170,000
Senior Infrastructure Services Analyst
Senior Infrastructure Services Analyst

Jobtailor • Atlanta (GA)

On-site
USD 120,000 - 180,000
Identity Governance & Administration Leader
Identity Governance & Administration Leader

Jobtailor • McLean (VA)

On-site
USD 170,000 - 250,000
Senior Identity Engineer
Senior Identity Engineer

Tyler Technologies • United States

On-site
USD 140,000 - 200,000
Senior Manager, IT Security Operations
Senior Manager, IT Security Operations

Jobtailor • Washington

On-site
USD 140,000 - 180,000
Systems Engineer
Systems Engineer

Insight Global • Houston (TX)

On-site
USD 120,000 - 150,000
Entra ID – AD Architect
Entra ID – AD Architect

Jobtailor • Austin (TX)

On-site
USD 150,000 - 190,000