Identity Security Engineer

Eliassen Group

Cary (NC)

Hybrid

USD 111,000 - 116,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Eliassen Group is seeking an Identity Security Engineer in Cary, NC to strengthen identity security across cloud, on-premises, and hybrid environments. You will design and support IAM and PAM solutions, advance Zero Trust through ZSP and JIT access, and work with cross-functional teams to enable secure access to systems and cloud resources.

The role requires 3+ years of IAM/PAM experience, CyberArk/Delinea/BeyondTrust familiarity, and strong Entra ID capabilities.

Qualifications

  • 3+ years designing, implementing, and supporting IAM, PAM, and identity security solutions in large enterprise environments.
  • 2+ years hands-on administration with CyberArk Privilege Cloud, CyberArk PAM, Delinea, BeyondTrust or comparable PAM platforms.
  • Strong knowledge of Microsoft Entra ID, Conditional Access, MFA, Identity Protection, and modern authentication controls.

Responsibilities

  • Design, implement, and support enterprise IAM and PAM solutions across cloud, on-premises, and hybrid environments.
  • Engineer privileged access capabilities including credential vaulting, password rotation, session management, and break-glass access.
  • Advance Zero Standing Privilege and Just-In-Time access, RBAC initiatives, and least privilege.
  • Implement and support Microsoft Entra ID capabilities including Conditional Access, PIM, MFA, and access security controls.
  • Collaborate with cross-functional teams to onboard systems and cloud resources into PAM and identity security platforms.
  • Automate identity and privileged access processes using PowerShell, Python, REST APIs, and workflow orchestration.

Skills

IAM design
PAM administration
Zero Trust
Automation scripting
Cloud & on-prem
RBAC

Education

Bachelor's degree in Cybersecurity / IT / CS / Engineering

Tools

CyberArk Privilege Cloud
CyberArk PAM
Delinea
BeyondTrust

Job description

Description:

Hybrid in Cary, NC

Our client seeks an Identity Security Engineer to strengthen identity security and reduce privileged access risk across cloud, on-premises, and hybrid environments. You will engineer and support IAM and PAM solutions, advance Zero Trust through Zero Standing Privilege and Just-In-Time access, and partner with cross-functional teams to enable secure access to enterprise systems, data, and cloud resources.

This is a full-time, permanent opportunity, offering a competitive salary and comprehensive benefits package. Qualified applicants must be willing and able to work on a w2 basis.

Salary: $111,000 - $116,000/ yr. w2 plus 10% bonus

Responsibilities:
  • Design, implement, and support enterprise IAM and PAM solutions across cloud, on-premises, and hybrid environments.
  • Engineer privileged access capabilities including credential vaulting, password rotation, session management, privileged account onboarding, break-glass access, and account lifecycle management.
  • Advance ZSP, JIT access, least privilege, privileged access reduction, and RBAC initiatives.
  • Implement and support Microsoft Entra ID capabilities including Conditional Access, PIM, MFA, Identity Protection, passwordless authentication, and access security controls.
  • Design and support application access management, SSO, federation, and modern authentication integrations using SAML, OAuth 2.0, OIDC, LDAP, and directory services.
  • Secure privileged users, administrative accounts, service accounts, application identities, machine identities, agentic identities, and other non-human identities.
  • Partner with infrastructure, cloud, application, and platform teams to onboard systems, applications, servers, databases, endpoints, and cloud resources into PAM and identity security platforms.
  • Develop and maintain privileged access standards, administrative access models, engineering runbooks, operational procedures, and Zero Trust access control patterns.
  • Automate identity and privileged access processes using PowerShell, Python, REST APIs, workflow orchestration, and platform integrations.
  • Troubleshoot IAM and PAM platform issues, perform root cause analysis, and implement corrective actions to improve reliability and operational stability.
  • Collaborate with Security Operations to investigate identity-related incidents, privileged access risks, control gaps, and suspicious activity involving high-risk identities.
  • Communicate identity security risks, technical recommendations, and remediation plans to cross-functional teams, senior management, and business stakeholders.
  • Other duties as assigned.
Experience Requirements:
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent combination of education and experience.
  • 3+ years of experience designing, implementing, and supporting IAM, PAM, and identity security solutions in large enterprise environments.
  • 2+ years of hands-on administration with CyberArk Privilege Cloud, CyberArk PAM, Delinea, BeyondTrust, or comparable PAM platforms.
  • Demonstrated ability to own and improve ZSP, JIT access, least privilege, RBAC, break-glass access, and privileged access reduction capabilities.
  • Strong working knowledge of Microsoft Entra ID, Conditional Access, PIM, MFA, Identity Protection, directory services, and modern authentication controls.
  • Understanding of SSO, federation, authentication, and authorization technologies such as SAML, OAuth 2.0, OIDC, LDAP, Active Directory, and cloud identity platforms.
  • Capability to deliver automation or integration using PowerShell, Python, REST APIs, or workflow automation is preferred.
  • Proven ability to assess identity security risks, identify control gaps, recommend remediation, and communicate with technical and non-technical stakeholders.
  • Strong judgment, ownership, urgency, customer focus, integrity, and ability to prioritize in a fast-paced environment.
  • Approximately 5% travel may be required.
Education Requirements:

Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent experience.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

CDW • Cary (NC)

Hybrid
USD 110,000 - 160,000
Identity Security Engineer: IAM & PAM, Zero Trust
Identity Security Engineer: IAM & PAM, Zero Trust

Eliassen Group • Cary (NC)

Hybrid
USD 111,000 - 116,000
Senior IAM Engineer
Senior IAM Engineer

Franklin Fitch • New York (NY)

Hybrid
USD 140,000 - 190,000
Identity Security Engineer — IAM/PAM, ZSP & JIT
Identity Security Engineer — IAM/PAM, ZSP & JIT

CDW • Cary (NC)

Hybrid
USD 110,000 - 160,000
Identity and Security Engineer
Identity and Security Engineer

Ledgent Technology • Houston (TX)

On-site
USD 130,000 - 140,000
Senior Identity Security Engineer
Senior Identity Security Engineer

Talent Mappers • Illinois

Hybrid
USD 140,000 - 160,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Eliassen Group • Cary (NC)

Hybrid
USD 130,000 - 135,000
Senior Identity Security Engineer
Senior Identity Security Engineer

Talent Mappers • Denver (CO)

Hybrid
USD 140,000 - 160,000
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000
Senior Security Engineer 5529
Senior Security Engineer 5529

Tier4 Group • Chicago (IL)

On-site
USD 140,000 - 200,000