- Own day-to-day security governance and engineering of identity controls across Okta, Microsoft Entra ID, Active Directory, MFA, Conditional Access, privileged access, and identity lifecycle workflows
- Design, implement, operate, and improve CyberArk privileged-access controls, including account discovery, vault onboarding, credential rotation, access workflows, session controls, monitoring, break-glass access, and evidence collection
- Govern privileged human and non-human identity lifecycles, including administrator accounts, service accounts, application credentials, scheduled-task accounts, emergency accounts, and machine identities
- Identify unmanaged, misconfigured, inactive, or noncompliant privileged and service accounts and coordinate onboarding, remediation, or retirement
- Develop and maintain CyberArk safes, platforms, policies, account ownership models, reconciliation processes, permissions, procedures, and recovery documentation
- Operate BloodHound Enterprise to analyze attack paths, Tier Zero relationships, excessive privilege, nested groups, delegated permissions, and identity weaknesses
- Translate BloodHound findings into prioritized remediation plans and validate remediation through rescanning, attack-path analysis, ticket evidence, exceptions, and exposure metrics
- Maintain Tier Zero and critical-identity models across Active Directory, Entra ID, privileged platforms, administrative systems, and infrastructure
- Assess and improve Active Directory security, including privileged groups, delegated rights, nested groups, service accounts, stale privileges, trusts, and administrative-tier separation
- Partner with Infrastructure to reduce standing privilege and implement secure administrative patterns
- Integrate applications with Okta and Entra ID using secure authentication, authorization, SSO, provisioning, deprovisioning, and lifecycle-management patterns
- Lead access reviews for critical systems, privileged roles, SaaS platforms, and regulated processes
- Partner with HR, Compliance, Operations, and application owners to improve identity lifecycle workflows
- Integrate identity telemetry into SIEM and investigation workflows and support investigations into suspicious authentication, credential misuse, privileged activity, role changes, OAuth grants, service-account behavior, and identity-based lateral movement
- Support SaaS identity, authorization, administrative-role, and data-access controls
- Define and report identity-security metrics and maintain standards, procedures, evidence, risk documentation, metrics, and leadership reporting
- Drive remediation of audit findings, penetration-test findings, policy exceptions, BloodHound findings, and access-control gaps
- Provide guidance on secure identity patterns and support continuous improvement and new technology adoption
Requirements
- Bachelor's degree in cybersecurity, computer science, information systems, engineering, or a relevant field, or equivalent professional experience
- 4–8 years of experience in information security, identity and access management, infrastructure security, cloud security, or related technical work
- Hands-on experience administering or engineering identity controls in Microsoft Entra ID and Active Directory
- Experience with Okta or another enterprise identity provider strongly preferred
- Hands-on experience with a privileged-access management platform; CyberArk experience strongly preferred
- Experience identifying and remediating Active Directory or cloud identity attack paths using BloodHound Enterprise, BloodHound Community Edition, or a comparable platform
- Experience governing service accounts, application identities, privileged accounts, secrets, and other non-human identities
- Experience with access reviews, MFA, SSO, provisioning, deprovisioning, Conditional Access, and identity governance in a regulated environment
- Experience with PowerShell, Microsoft Graph, REST APIs, or other automation methods
- Experience working with infrastructure teams to remediate complex privilege relationships without disrupting business-critical systems
- CISSP, Microsoft identity/security, CyberArk, Okta, or other relevant certifications preferred
- Knowledge of Okta, Microsoft Entra ID, Active Directory, Microsoft 365, MFA, Conditional Access, SSO, SCIM, SAML, OAuth 2.0, OpenID Connect, lifecycle automation, group governance, enterprise applications, managed identities, and application registrations
- Knowledge of CyberArk vaulting, safes, platforms, credential rotation, reconciliation, privileged session controls, account discovery, onboarding, access workflows, reporting, service accounts, emergency access, and operational recovery
- Knowledge of BloodHound Enterprise or comparable attack-path management, Tier Zero analysis, transitive privilege, nested groups, delegated permissions, remediation validation, and exposure metrics
- Knowledge of identity governance, access certification, role and entitlement governance, segregation of duties, exception handling, contractor/vendor access, evidence collection, and control reporting
- Knowledge of structured data analysis, identity inventory reconciliation, workflow automation, and integrations with ticketing, SIEM, and reporting platforms
- Strong communication skills and ability to work across technical teams, business owners, Compliance, HR, and Operations
- Must be authorized to work in the United States without current or future employer-sponsored work authorization
Core Competencies
Demonstrates expertise in identity and access management, particularly with Microsoft Entra ID, Active Directory, and CyberArk. Proficient in governing privileged access, conducting access reviews, and remediating identity-related security issues.
Highest-signal resume keywords
- Identity Governance
- CyberArk Privileged-Access Management
- Microsoft Entra ID Administration
- BloodHound Enterprise Analysis
- Access Reviews and Remediation
ATS Optimization Keywords
Hard Skills
- Identity Controls Engineering
- Privileged Access Management
- Active Directory Security
- MFA Implementation
- SSO Integration
- PowerShell Scripting
- REST API Automation
- Credential Rotation
- Identity Lifecycle Management
- Access Workflow Design
Soft Skills
- Strong Communication Skills
- Collaboration Across Teams
Certifications & Qualifications
- CISSP
- Microsoft Identity/Security
- CyberArk Certification
- Okta Certification
Industry Keywords
- Identity and Access Management
- Infrastructure Security
- Cloud Security
- Regulated Environment
- Privileged Accounts Governance
- Service Accounts Management
- Access Certification
- Segregation of Duties
- Evidence Collection
- Control Reporting
Tools & Technologies
- Okta
- Microsoft Entra ID
- Active Directory
- CyberArk
- BloodHound Enterprise
- SIEM Integration
- Microsoft 365
- OAuth 2.0
- SAML
- SCIM