Identity Security Engineer

ECS

Washington (District of Columbia)

Hybrid

USD 120,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Everforth ECS in Washington, DC/remote is seeking an Identity Security Engineer to join our security operations division. The role focuses on designing and evolving identity systems, with emphasis on Windows Server infrastructure and zero-trust posture.

You will operate in a hybrid model with emphasis on secure, engineering-level work. The position requires 5+ years in identity security and Windows server administration, with preferred hands-on Zero Trust experience and strong collaboration

Qualifications

  • 5+ years of progressive experience in identity security and Windows server administration.
  • Experience with IAM architecture, governance, and security operations.
  • Ability to monitor identity health, detect suspicious activity, and investigate identity-based threats.
  • Hands-on with Entra ID/Azure AD, PIM, and just-in-time access controls.
  • Experience enforcing least privilege, RBAC, and automated provisioning/deprovisioning.

Responsibilities

  • Design, harden, and evolve identity systems as part of a security engineering team.
  • Assess identity architecture against modern security frameworks and drive improvements.
  • Lead initiatives to reduce identity-based risk and mature identity posture.
  • Ensure Windows Server environments are configured, documented, and defended.
  • Collaborate across cybersecurity, networking, and systems teams; communicate risks clearly.

Skills

IAM architecture
Identity protection
Security analytics
Entra ID / Azure AD
PIM / just-in-time access
RBAC / least privilege
Zero Trust principles
Workload identities
Federation decommissioning
Windows Server administration
Active Directory / ADFS / GPOs
Security monitoring of Windows
Documentation & policy
Patching & risk assessments
Cross-team collaboration
Threat detection
Security reporting to leadership

Education

Bachelor's degree in Cybersecurity/Computer Science/IT

Tools

Microsoft Entra ID (Azure AD)
Privileged Identity Management (PIM)
Microsoft Defender for Identity
Splunk
PowerShell
Bash
Python
Azure
AWS IAM
SAML / OAuth 2.0 / OpenID Connect

Job description

Job Description

Everforth ECS is seeking an Identity Security Engineer to work in our Washington, DC office / remote. The role is contingent upon additional funding. We are seeking a technically experienced Identity Security Engineer to join our security operations division — a full-spectrum cybersecurity organization covering endpoint security, event monitoring, threat intelligence, and advanced incident response. This is a security engineering role, meaning you are not simply administering identity systems but are designing, hardening, and evolving them.

Your work sits at the intersection of two critical disciplines: identity security and Windows server infrastructure. You will assess the organization's identity architecture against modern security frameworks, lead initiatives to reduce identity-based risk, and ensure that the Windows server environment supporting those identity systems is configured, documented, and defended to the highest standard.

This role requires someone who understands identity not just as an IT function but as a primary security control and who can operate with engineering depth and strategic thinking.

Salary Range

$120,000 - $130,000

General Description Of Benefits
Required Skills
Identity Security
  • Deep understanding of enterprise identity and access management (IAM) architecture, governance, and security operations
  • Experience integrating identity signals into security operations, including identity protection, threat detection, and centralized logging
  • Ability to monitor identity health, detect suspicious activity, and investigate identity-based threats using security analytics and operational playbooks
  • Hands‑on experience with Microsoft Entra ID (Azure Active Directory), Privileged Identity Management (PIM), and just‑in‑time access controls
  • Experience enforcing least privilege, role‑based access control (RBAC), and automating access provisioning and deprovisioning workflows
  • Familiarity with Zero Trust identity principles — verify explicitly, enforce least privilege, and assume breach — and the ability to assess and mature an organization's identity posture against those principles
  • Experience securing workload identities, service principals, and high‑risk administrative accounts
  • Ability to decommission legacy federation infrastructure and migrate applications to modern, standards‑based authentication
Windows Server
  • Strong experience administering and hardening Windows Server environments in an enterprise setting
  • Proficiency with Microsoft Active Directory, Active Directory Federation Services, and Group Policy Objects (GPOs) from a security engineering perspective
  • Ability to monitor and analyze Windows‑based architecture, communication, policies, and protocols from a cybersecurity lens
  • Experience performing system monitoring, reviewing logs, and taking corrective action to maintain server integrity and availability
  • Ability to create and maintain thorough system documentation covering installation, configuration, and troubleshooting procedures
  • Experience supporting security continuous monitoring efforts including risk assessments and system patching within Windows server environments
Security Engineering & Collaboration
  • Ability to identify gaps in current identity and server security capabilities and recommend both technical and process‑level improvements
  • Experience developing and contributing to technical security standards, monitoring standards, and security architecture documentation
  • Comfortable working across teams including cybersecurity, networking, systems administration, and technology support partners
  • Ability to communicate findings and risks clearly to both technical peers and senior leadership

A minimum of 5+ years of progressive experience in identity security and Windows server administration is required, with demonstrated experience operating at an engineering level rather than a purely operational or support capacity. Candidates with hands‑on Zero Trust identity implementation experience will be strongly preferred.

Desired Skills
  • Experience with Microsoft Defender for Identity and integration with SIEM platforms such as Splunk
  • Scripting and automation experience in PowerShell, Bash, or Python to support identity operations and reporting
  • Familiarity with hybrid identity environments and cloud identity platforms such as Microsoft Azure or AWS IAM
  • Experience with Single Sign‑On (SSO), SAML, OAuth 2.0, and OpenID Connect protocols
  • Knowledge of Kerberos delegation risks, lateral movement detection, and privilege escalation monitoring
  • Microsoft License Management experience
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field preferred
  • Relevant certifications such as Microsoft Identity and Access Administrator (SC‑300), Microsoft Cybersecurity Architect (SC‑100), CISSP, or equivalent are strongly preferred

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS is the federal segment of Everforth, a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission‑critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We Value
  • Attracting and developing top talent and high‑performing teams
  • Fostering a culture that is engaging, accountable, and mission‑driven

Meet the challenge. Make a difference with Everforth ECS!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Identity Security Engineer
Identity Security Engineer

Socket.dev • Washington

Hybrid
USD 120,000 - 130,000
Identity Infrastructure Engineer
Identity Infrastructure Engineer

ECS • Washington

Hybrid
USD 120,000 - 130,000
Identity Infrastructure Engineer
Identity Infrastructure Engineer

Socket.dev • Washington

Hybrid
USD 120,000 - 130,000
Cloud Security Engineer
Cloud Security Engineer

ECS • Washington

Hybrid
USD 120,000 - 130,000
Authentication Engineer
Authentication Engineer

ECS • Washington

Hybrid
USD 120,000 - 130,000
Cybersecurity Operations Manager
Cybersecurity Operations Manager

ECS • Washington

Hybrid
USD 155,000 - 165,000
Information Systems Security Engineer SME
Information Systems Security Engineer SME

ECS • Stafford (VA)

On-site
USD 120,000 - 150,000
Identity Security Engineer — Zero Trust & Windows Server
Identity Security Engineer — Zero Trust & Windows Server

Socket.dev • Washington

Hybrid
USD 120,000 - 130,000
Senior Security Engineer
Senior Security Engineer

ECS • Washington

On-site
USD 145,000 - 165,000
General Description of Benefits
Identity Security Engineer - Zero Trust & Windows
Identity Security Engineer - Zero Trust & Windows

ECS • Washington

Hybrid
USD 120,000 - 130,000