Description:
Hybrid in Cary, NC
Our client seeks an Identity Security Engineer to strengthen identity security and reduce privileged access risk across cloud, on-premises, and hybrid environments. You will engineer and support IAM and PAM solutions, advance Zero Trust through Zero Standing Privilege and Just-In-Time access, and partner with cross-functional teams to enable secure access to enterprise systems, data, and cloud resources.
This is a full-time, permanent opportunity, offering a competitive salary and comprehensive benefits package. Qualified applicants must be willing and able to work on a w2 basis.
Salary: $111,000 - $116,000/ yr. w2 plus 10% bonus
Responsibilities:
- Design, implement, and support enterprise IAM and PAM solutions across cloud, on-premises, and hybrid environments.
- Engineer privileged access capabilities including credential vaulting, password rotation, session management, privileged account onboarding, break-glass access, and account lifecycle management.
- Advance ZSP, JIT access, least privilege, privileged access reduction, and RBAC initiatives.
- Implement and support Microsoft Entra ID capabilities including Conditional Access, PIM, MFA, Identity Protection, passwordless authentication, and access security controls.
- Design and support application access management, SSO, federation, and modern authentication integrations using SAML, OAuth 2.0, OIDC, LDAP, and directory services.
- Secure privileged users, administrative accounts, service accounts, application identities, machine identities, agentic identities, and other non-human identities.
- Partner with infrastructure, cloud, application, and platform teams to onboard systems, applications, servers, databases, endpoints, and cloud resources into PAM and identity security platforms.
- Develop and maintain privileged access standards, administrative access models, engineering runbooks, operational procedures, and Zero Trust access control patterns.
- Automate identity and privileged access processes using PowerShell, Python, REST APIs, workflow orchestration, and platform integrations.
- Troubleshoot IAM and PAM platform issues, perform root cause analysis, and implement corrective actions to improve reliability and operational stability.
- Collaborate with Security Operations to investigate identity-related incidents, privileged access risks, control gaps, and suspicious activity involving high-risk identities.
- Communicate identity security risks, technical recommendations, and remediation plans to cross-functional teams, senior management, and business stakeholders.
- Other duties as assigned.
Experience Requirements:
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent combination of education and experience.
- 3+ years of experience designing, implementing, and supporting IAM, PAM, and identity security solutions in large enterprise environments.
- 2+ years of hands-on administration with CyberArk Privilege Cloud, CyberArk PAM, Delinea, BeyondTrust, or comparable PAM platforms.
- Demonstrated ability to own and improve ZSP, JIT access, least privilege, RBAC, break-glass access, and privileged access reduction capabilities.
- Strong working knowledge of Microsoft Entra ID, Conditional Access, PIM, MFA, Identity Protection, directory services, and modern authentication controls.
- Understanding of SSO, federation, authentication, and authorization technologies such as SAML, OAuth 2.0, OIDC, LDAP, Active Directory, and cloud identity platforms.
- Capability to deliver automation or integration using PowerShell, Python, REST APIs, or workflow automation is preferred.
- Proven ability to assess identity security risks, identify control gaps, recommend remediation, and communicate with technical and non-technical stakeholders.
- Strong judgment, ownership, urgency, customer focus, integrity, and ability to prioritize in a fast-paced environment.
- Approximately 5% travel may be required.
Education Requirements:
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent experience.