Identity and Security Engineer

Ledgent Technology

United States

Hybrid

USD 130,000 - 140,000

Full time

2 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Ledgent Technology is seeking an Identity and Security Engineer to lead architecture, engineering, and monitoring of enterprise identity services for hybrid environments. The role emphasizes AD, Entra ID, IAM, PAM, PKI, and cloud integrations across on-prem and cloud.

The ideal candidate will drive modernization initiatives, design secure identity frameworks, and collaborate with security, compliance, and DevOps teams. Strong PowerShell and IaC skills are expected.

Qualifications

  • 8+ years of experience engineering enterprise Active Directory environments.
  • 5+ years of hands-on experience with Microsoft Entra ID in hybrid environments.
  • Deep expertise with AD DS, Entra ID, ADCS, and SSO technologies.
  • Strong understanding of IAM principles, RBAC, and identity governance.
  • Experience designing federation, SSO, and MFA solutions.
  • Knowledge of Kerberos, LDAP, SAML, OAuth 2.0, OIDC.
  • Experience with PKI, AD Certificate Services, and certificate lifecycle management.
  • Experience with PAM platforms and privileged access controls.
  • PowerShell scripting and automation capability.
  • Experience with Microsoft Graph API and Terraform or similar tools.
  • Understanding of Zero Trust concepts and identity protection.
  • Experience with Defender for Identity, Entra ID Protection, and XDR platforms.

Responsibilities

  • Design, implement, optimize, and maintain enterprise identity platforms (AD DS, Entra ID, SSO, MFA).
  • Architect secure identity frameworks using RBAC, CA, least privilege, and JIT access.
  • Develop identity governance programs and access lifecycle processes.
  • Lead identity services across hybrid cloud and on-premises environments.
  • Establish governance and security controls for service accounts and non-human identities.
  • Integrate identity platforms with enterprise apps and business systems.
  • Partner with security, compliance, infra, apps, and DevOps teams to enforce secure identity practices.
  • Lead PKI design, certificate lifecycle, and authentication modernization.
  • Engineer PAM & secure vendor remote access solutions.
  • Develop identity monitoring, auditing, and anomaly detection capabilities.
  • Support identity threat detection and response using ITDR, EDR, SIEM.
  • Provide Tier 3 escalation for complex auth issues.
  • Implement security controls to prevent identity-based threats.
  • Create PowerShell automation and API integrations; pursue IaC solutions.
  • Support audits with identity-focused controls and evidence.
  • Lead identity-centric projects through design to operational transition.
  • Create and maintain technical runbooks and docs.
  • Evaluate emerging IAM/security technologies and propose improvements.

Skills

Active Directory
Entra ID
IAM
PAM
PKI
RBAC
Conditional Access
Just-in-Time (JIT) access
SAML
OAuth 2.0
OIDC
PowerShell
Terraform
Microsoft Graph API
Python
ITDR
EDR
SIEM
Zero Trust
On-call support

Tools

PowerShell
Terraform
Microsoft Graph API
Python

Job description

Identity and Security Engineer (JN -092026-429932) Houston, Texas

Salary: USD130000 - USD140000 per year + + Bonus

Title: Security and Identity Engineer

Location: Atlanta, Austin, Houston, Dallas, Miramar, Orlando, Tallahassee, West Palm Beach, Fort Lauderdale, Phoenix, Las Vegas or Charlotte

Schedule: Remote - Some onsite/local presence is needed

Employment Type: Full-Time

Compensation: $130-140k

No C2C at this time

Overview

Our client is seeking an Identity & Security Engineer to serve as a lead technical resource responsible for the architecture, engineering, security, and monitoring of enterprise identity services across hybrid environments. This role will focus heavily on Active Directory, Entra ID, Identity and Access Management (IAM), Privileged Access Management (PAM), PKI, identity governance, and cloud identity integrations. The ideal candidate will have deep expertise in Microsoft identity technologies, strong security engineering capabilities, and experience driving modernization initiatives across both on-premises and cloud environments.

Responsibilities
  • Design, implement, optimize, and maintain enterprise identity platforms including Active Directory Domain Services, Entra ID, Single Sign-On (SSO), and Multifactor Authentication (MFA).
  • Architect secure identity frameworks utilizing RBAC, Conditional Access, least privilege, and Just-in-Time (JIT) access models.
  • Develop identity governance programs and access lifecycle management processes.
  • Lead the design and administration of identity services across hybrid cloud and on-premises environments.
  • Establish governance and security controls for service accounts, application registrations, and other non-human identities.
  • Integrate identity platforms with enterprise applications and business systems.
  • Partner with security, compliance, infrastructure, application, and DevOps teams to implement secure identity practices.
  • Lead PKI design, hardening initiatives, certificate lifecycle management, and authentication modernization efforts.
  • Engineer and support privileged access management and secure vendor remote access solutions.
  • Develop identity monitoring, auditing, and detection capabilities to identify suspicious or anomalous activity.
  • Support identity threat detection and response using ITDR, EDR, and SIEM platforms.
  • Perform root cause analysis and provide Tier 3 escalation support for complex authentication, authorization, and access-related issues.
  • Implement security controls to protect enterprise infrastructure from unauthorized access and identity-based threats.
  • Develop PowerShell automation, API integrations, and infrastructure-as-code solutions to reduce manual efforts.
  • Support compliance initiatives through identity-focused controls, governance, auditing, and evidence collection.
  • Lead identity-related projects through design, implementation, testing, deployment, and operational transition.
  • Create and maintain technical documentation, standards, procedures, and runbooks.
  • Evaluate emerging IAM and security technologies and recommend improvements to identity architecture and security posture.
Requirements
  • 8+ years of experience supporting and engineering enterprise Active Directory environments.
  • 5+ years of hands-on experience with Microsoft Entra ID in hybrid environments.
  • Deep expertise with Active Directory Domain Services (AD DS), Entra ID, ADCS, and Single Sign-On technologies.
  • Strong understanding of identity and access management principles, role-based access controls, and identity governance.
  • Experience designing and supporting federation, SSO, and MFA solutions.
  • Strong knowledge of authentication and authorization protocols including Kerberos, LDAP, SAML, OAuth 2.0, and OpenID Connect (OIDC).
  • Hands-on experience with Public Key Infrastructure (PKI), AD Certificate Services, and certificate lifecycle management.
  • Experience with Privileged Access Management (PAM) platforms and privileged access controls.
  • Advanced PowerShell scripting and automation experience.
  • Experience with Microsoft Graph API, Python, Terraform, or similar automation technologies.
  • Strong understanding of Zero Trust security concepts and identity protection strategies.
  • Experience with Microsoft Defender for Identity, Entra ID Protection, Microsoft Defender XDR, or similar security platforms.
  • Strong troubleshooting, analytical, and problem-solving skills.
  • Excellent communication skills with the ability to work across technical and non-technical teams.
  • Ability to work independently, lead initiatives, and serve as a senior technical resource.
  • Ability to participate in an on-call rotation and support critical production systems.
Preferred Experience
  • Experience with Okta, Ping Identity, or other enterprise IAM platforms.
  • Microsoft Entra Suite architecture and administration experience.
  • Certificate-based authentication modernization initiatives.
  • AWS and/or GCP cloud experience.
  • Microsoft certifications such as Azure Security Engineer Associate or Identity and Access Administrator Associate.
  • CISSP or other cybersecurity certifications.
  • Experience supporting large enterprise, professional services, legal, or highly regulated environments.
  • Experience with identity threat detection and response (ITDR) programs and identity-focused security operations.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity & Security Engineer
Identity & Security Engineer

Coda Search│Staffing • Town of Texas (WI)

Hybrid
USD 110,000 - 170,000
Sr. Identity Security Engineer Active Directory & Entra ID
Sr. Identity Security Engineer Active Directory & Entra ID

MathWorks • Natick (MA)

On-site
USD 122,000 - 190,000
Senior Identity Engineer (Cloud & Microsoft 365)
Senior Identity Engineer (Cloud & Microsoft 365)

Teledyne Technologies Incorporated • Stillwater (OK)

On-site
USD 110,000 - 170,000
Identity & Access Management (IAM)- Senior Engineer - Microsoft Entra
Identity & Access Management (IAM)- Senior Engineer - Microsoft Entra

ARK Infotech Spectrum India Pvt. Ltd • Dallas (TX)

Hybrid
USD 110,000 - 150,000
Hybrid work arrangement
System Engineer
System Engineer

Franklin Fitch • Houston (TX)

On-site
USD 130,000 - 170,000
Solutions Architect - AD/Entra Architect
Solutions Architect - AD/Entra Architect

Texas Instruments Incorporated • Dallas (TX), Northern (KY)

On-site
USD 140,000 - 190,000
Identity and Access Management Engineer
Identity and Access Management Engineer

Princeton IT Services, Inc • New York (NY)

On-site
USD 96,000 - 179,000
IAM Architect
IAM Architect

Conexess Group • Farmington Hills (MI)

On-site
USD 130,000 - 170,000
Senior Identity and Access Management Analyst
Senior Identity and Access Management Analyst

Baptist Memorial Health Care Corporation • Memphis (TN)

On-site
USD 110,000 - 140,000
Senior Identity & Access Architect
Senior Identity & Access Architect

OEC • United States

On-site
USD 140,000 - 190,000