Identity and Security Engineer

Ledgent Technology

Houston (TX)

Hybrid

USD 130,000 - 140,000

Full time

12 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Ledgent Technology seeks an Identity & Security Engineer in Houston to own architecture, engineering, and monitoring of enterprise identity services across hybrid environments. Focus areas include Active Directory, Entra ID, IAM, PAM, PKI, governance, and cloud identity integrations.

The role emphasizes strong Microsoft identity technologies, security engineering, and modernization initiatives across on‑prem and cloud ecosystems.

Qualifications

  • 8+ years of experience supporting and engineering enterprise Active Directory environments.
  • 5+ years of hands-on experience with Microsoft Entra ID in hybrid environments.
  • Deep expertise with Active Directory Domain Services (AD DS), Entra ID, ADCS, and Single Sign-On technologies.
  • Strong understanding of identity and access management principles, RBAC, and identity governance.
  • Experience designing and supporting federation, SSO, and MFA solutions.
  • Strong knowledge of authentication protocols including Kerberos, LDAP, SAML, OAuth 2.0, and OIDC.
  • Hands-on experience with PKI, AD Certificate Services, and certificate lifecycle management.
  • Experience with PAM platforms and privileged access controls.
  • Advanced PowerShell scripting and automation experience.
  • Experience with Microsoft Graph API, Python, Terraform, or similar automation technologies.
  • Strong understanding of Zero Trust concepts and identity protection strategies.
  • Experience with Defender for Identity, Entra ID Protection, Defender XDR, or similar platforms.

Responsibilities

  • Design, implement, optimize, and maintain enterprise identity platforms including AD DS and Entra ID.
  • Architect secure identity frameworks with RBAC, CA, least privilege, and Just‑In‑Time access.
  • Develop identity governance programs and access lifecycle processes.
  • Lead design and administration of identity services across hybrid environments.
  • Establish governance and security controls for service accounts and non-human identities.
  • Integrate identity platforms with enterprise applications and business systems.
  • Partner with security, compliance, infrastructure, and DevOps teams to implement identity practices.
  • Lead PKI design, certificate lifecycle management, and authentication modernization.
  • Engineer privileged access management and secure vendor remote access solutions.
  • Develop identity monitoring, auditing, and detection capabilities.
  • Support identity threat detection and response using ITDR, EDR, and SIEM platforms.
  • Provide Tier 3 escalation for complex authentication and access issues.
  • Create technical documentation, runbooks, and standards.

Skills

Active Directory
Entra ID
IAM
PAM
PKI
Identity governance
RBAC
Conditional Access
MFA
Single Sign-On
PowerShell
Microsoft Graph API
Python
Terraform

Tools

Microsoft Graph API
Python
Terraform

Job description

Identity and Security Engineer (JN -092026-429932) Houston, Texas

Salary: USD130000 - USD140000 per year + + bonus

Location: Atlanta, Austin, Houston, Dallas, Miramar, Orlando, Tallahassee, West Palm Beach, Fort Lauderdale, Phoenix, or Charlotte

Schedule: Remote - *Some onsite/local presence is needed*

Employment Type: Full-Time

Compensation: $130-140k

No C2C at this time

Overview

Our client is seeking an Identity & Security Engineer to serve as a lead technical resource responsible for the architecture, engineering, security, and monitoring of enterprise identity services across hybrid environments. This role will focus heavily on Active Directory, Entra ID, Identity and Access Management (IAM), Privileged Access Management (PAM), PKI, identity governance, and cloud identity integrations. The ideal candidate will have deep expertise in Microsoft identity technologies, strong security engineering capabilities, and experience driving modernization initiatives across both on-premises and cloud environments.

Responsibilities
  • Design, implement, optimize, and maintain enterprise identity platforms including Active Directory Domain Services, Entra ID, Single Sign-On (SSO), and Multifactor Authentication (MFA).
  • Architect secure identity frameworks utilizing RBAC, Conditional Access, least privilege, and Just-in-Time (JIT) access models.
  • Develop identity governance programs and access lifecycle management processes.
  • Lead the design and administration of identity services across hybrid cloud and on-premises environments.
  • Establish governance and security controls for service accounts, application registrations, and other non-human identities.
  • Integrate identity platforms with enterprise applications and business systems.
  • Partner with security, compliance, infrastructure, application, and DevOps teams to implement secure identity practices.
  • Lead PKI design, hardening initiatives, certificate lifecycle management, and authentication modernization efforts.
  • Engineer and support privileged access management and secure vendor remote access solutions.
  • Develop identity monitoring, auditing, and detection capabilities to identify suspicious or anomalous activity.
  • Support identity threat detection and response using ITDR, EDR, and SIEM platforms.
  • Perform root cause analysis and provide Tier 3 escalation support for complex authentication, authorization, and access-related issues.
  • Implement security controls to protect enterprise infrastructure from unauthorized access and identity-based threats.
  • Develop PowerShell automation, API integrations, and infrastructure-as-code solutions to reduce manual efforts.
  • Support compliance initiatives through identity-focused controls, governance, auditing, and evidence collection.
  • Lead identity-related projects through design, implementation, testing, deployment, and operational transition.
  • Create and maintain technical documentation, standards, procedures, and runbooks.
  • Evaluate emerging IAM and security technologies and recommend improvements to identity architecture and security posture.
Requirements
  • 8+ years of experience supporting and engineering enterprise Active Directory environments.
  • 5+ years of hands‑on experience with Microsoft Entra ID in hybrid environments.
  • Deep expertise with Active Directory Domain Services (AD DS), Entra ID, ADCS, and Single Sign-On technologies.
  • Strong understanding of identity and access management principles, role‑based access controls, and identity governance.
  • Experience designing and supporting federation, SSO, and MFA solutions.
  • Strong knowledge of authentication and authorization protocols including Kerberos, LDAP, SAML, OAuth 2.0, and OpenID Connect (OIDC).
  • Hands‑on experience with Public Key Infrastructure (PKI), AD Certificate Services, and certificate lifecycle management.
  • Experience with Privileged Access Management (PAM) platforms and privileged access controls.
  • Advanced PowerShell scripting and automation experience.
  • Experience with Microsoft Graph API, Python, Terraform, or similar automation technologies.
  • Strong understanding of Zero Trust security concepts and identity protection strategies.
  • Experience with Microsoft Defender for Identity, Entra ID Protection, Microsoft Defender XDR, or similar security platforms.
  • Strong troubleshooting, analytical, and problem‑solving skills.
  • Excellent communication skills with the ability to work across technical and non‑technical teams.
  • Ability to work independently, lead initiatives, and serve as a senior technical resource.
  • Ability to participate in an on‑call rotation and support critical production systems.
Preferred Experience
  • Experience with Okta, Ping Identity, or other enterprise IAM platforms.
  • Microsoft Entra Suite architecture and administration experience.
  • Certificate‑based authentication modernization initiatives.
  • AWS and/or GCP cloud experience.
  • Microsoft certifications such as Azure Security Engineer Associate or Identity and Access Administrator Associate.
  • CISSP or other cybersecurity certifications.
  • Experience supporting large enterprise, professional services, legal, or highly regulated environments.
  • Experience with identity threat detection and response (ITDR) programs and identity‑focused security operations.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Identity Security Engineer Active Directory & Entra ID
Sr. Identity Security Engineer Active Directory & Entra ID

MathWorks • Natick (MA)

On-site
USD 122,000 - 190,000
Identity and Security Engineer
Identity and Security Engineer

GT Restructuring • Atlanta (LA)

On-site
USD 120,000 - 150,000
Competitive compensation
Excellent benefits package
Innovative work environment
Senior Identity Engineer
Senior Identity Engineer

Tyler-Technologies-29572f8 • Plano (TX)

On-site
USD 110,000 - 140,000
Solutions Architect - AD/Entra Architect
Solutions Architect - AD/Entra Architect

Texas Instruments • Dallas (TX)

On-site
USD 140,000 - 200,000
Identity and Access Management Engineer
Identity and Access Management Engineer

Princeton IT Services, Inc • New York (NY)

Hybrid
USD 96,000 - 179,000
Solutions Architect - AD/Entra Architect
Solutions Architect - AD/Entra Architect

Texas Instruments Incorporated • Dallas (TX), Northern (KY)

Hybrid
USD 140,000 - 190,000
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000
Active Directory Specialist
Active Directory Specialist

Compunnel, Inc. • Richmond (VA)

On-site
USD 100,000 - 130,000
IAM Architect
IAM Architect

Conexess Group • Farmington Hills (MI)

On-site
USD 130,000 - 170,000
Sr. IAM Engineer, Infrastructure Services
Sr. IAM Engineer, Infrastructure Services

Scorpion Therapeutics • Bridgewater (MA)

On-site
USD 120,000 - 180,000