Information Technology Security Engineer

IZAR Associates, Inc.

United States

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A cybersecurity firm in the United States is seeking an experienced Information Technology Security Engineer to enhance privileged access management and endpoint controls. The ideal candidate will have over 7 years of experience in IAM/PAM, familiarity with cloud platforms, and strong skills in documentation and communication. This role emphasizes reducing attack surfaces and improving identity hygiene through detailed processes and compliance solutions.

Qualifications

  • 7+ years of experience in PAM, IAM, or related security engineering roles.
  • Hands-on experience with AD, Entra ID, Linux, and at least one major cloud platform (Azure, AWS, or GCP).
  • Strong knowledge of vaulting technologies and endpoint privilege management practices.
  • Proficiency with authentication methods: MFA, SSO, passwordless, Kerberos, and certificate-based access.
  • Excellent documentation and communication abilities.

Responsibilities

  • Administer and enhance the corporate vaulting platform to manage privileged credentials.
  • Implement and maintain endpoint least-privilege policies across multiple environments.
  • Lead local administrator cleanup projects and enforce removal of unauthorized admin rights.
  • Contribute to enterprise Zero Trust architecture initiatives.
  • Create and maintain technical runbooks and operational procedures.

Skills

Privileged Access Management
Identity and Access Management
Security Engineering
Documentation Skills
Zero Trust Principles

Education

7+ years in security roles

Tools

Active Directory
Entra ID
AWS
Azure
GCP

Job description

Information Technology Security Engineer
Role Overview

We are seeking a skilled Privileged Access Management (PAM) Engineer to join our cybersecurity team. This role will focus on securing privileged identities across Active Directory (AD), Entra ID, Linux, and major cloud platforms (Azure, AWS, and GCP). The PAM Engineer will design, implement, and maintain controls that ensure administrators and endpoints only have the access they need—at the right time and with the least privilege possible.

The ideal candidate will have strong expertise in vaulting platforms, endpoint privilege management, and zero‑trust principles, with a proven track record of reducing attack surfaces and improving identity hygiene.

Privileged Identity Security
  • Administer and enhance the corporate vaulting platform to manage privileged credentials across AD, Entra, Linux, and cloud platforms (Azure, AWS, GCP).
  • Implement credential randomization for local/built‑in administrator accounts, service accounts, and cloud root/admin accounts.
  • Ensure time‑bound, approval‑based access for administrators following least privilege and just‑in‑time (JIT) principles.
Endpoint Privilege Management
  • Implement and maintain endpoint least‑privilege policies across Windows, Linux, and macOS environments.
  • Replace standing local admin rights with controlled privilege elevation workflows.
  • Apply application control and privilege granularity to reduce risks from malware, ransomware, and insider threats.
  • Partner with desktop engineering teams to improve usability while enforcing strong endpoint controls.
Identity Hardening & Hygiene
  • Lead local administrator cleanup projects and enforce removal of unauthorized admin rights.
  • Harden Entra ID and cloud tenant hygiene by monitoring stale accounts, privileged roles, and excessive permissions.
  • Apply ITDR (Identity Threat Detection & Response) practices to detect and mitigate suspicious privileged activity across on‑prem and cloud platforms.
Security Architecture & Standards
  • Contribute to enterprise Zero Trust architecture initiatives for hybrid and multi‑cloud environments.
  • Align privileged access controls with NIST standards and organizational policies.
  • Drive adoption of passwordless authentication, MFA, and SSO for both on‑prem and cloud privileged identities.
Cloud Identity & Access
  • Manage and monitor privileged roles and accounts in Azure AD (Entra ID), AWS IAM, and GCP IAM.
  • Implement least‑privilege design for cloud workloads, service principals, keys, and secrets.
  • Integrate cloud platform identities with PAM vaulting, session recording, and access approval workflows.
Identity Lifecycle Management
  • Collaborate with IGA teams to automate provisioning, deprovisioning, and recertification of privileged accounts across on‑prem and cloud.
  • Ensure privileged entitlements are tied to clear business justification and ownership.
Documentation & Governance
  • Create and maintain technical runbooks, architecture diagrams, and operational procedures.
  • Provide reporting on privileged access usage, endpoint privilege management, hygiene metrics, and compliance results.
  • Partner with audit, compliance, and risk teams to demonstrate control effectiveness.
Required Qualifications
  • 7+ years of experience in PAM, IAM, or related security engineering roles.
  • Hands‑on experience with AD, Entra ID, Linux, and at least one major cloud platform (Azure, AWS, or GCP).
  • Strong knowledge of vaulting technologies and endpoint privilege management practices (least privilege, privilege elevation, application control).
  • Proficiency with authentication methods: MFA, SSO, passwordless, Kerberos, and certificate‑based access.
  • Familiarity with NIST 800‑63B, Zero Trust frameworks, ITDR, and cloud security standards (CIS, CSA, etc.).
  • Excellent documentation and communication abilities.
Preferred Qualifications
  • Experience securing privileged access in multi‑cloud environments (Azure, AWS, GCP).
  • Knowledge of Entra ID Conditional Access, PIM, AWS IAM policies, and GCP IAM roles.
  • Experience integrating PAM solutions with CI/CD pipelines, DevOps tools, or ITSM workflows.
  • Industry certifications are a plus (SailPoint, CISSP, CISM, CCSP, Azure Security Engineer, AWS Security Specialty, GIAC, etc.).
Success in This Role Looks Like
  • Reduction of standing local administrator rights and adoption of endpoint least‑privilege controls.
  • Demonstrated adoption of MFA, passwordless, vault‑based workflows, and privilege elevation.
  • Improved audit and compliance posture with clear reporting of privileged activity and endpoint control enforcement.
  • Measurable reduction in attack surface through consistent identity hygiene and lifecycle management.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Technology Security Engineer
Information Technology Security Engineer

IZAR Associates, Inc. • United States

Hybrid
USD 100,000 - 130,000
Privileged Access Management (PAM) Engineer
Privileged Access Management (PAM) Engineer

Veriipro • Dallas (TX)

On-site
USD 120,000 - 170,000
Identity & PAM Security Engineer
Identity & PAM Security Engineer

ApplyMint • United States

On-site
USD 120,000 - 160,000
PAM Lead
PAM Lead

Veriipro • Irvine (CA)

On-site
USD 130,000 - 160,000
PAM Specialist
PAM Specialist

Shain Associates • New York (NY)

On-site
USD 150,000 - 230,000
Senior Manager, Privileged Access Management – PAM
Senior Manager, Privileged Access Management – PAM

Jobtailor • Town of Florida (NY)

On-site
USD 140,000 - 185,000
Senior Technology Security Engineer (IAM)
Senior Technology Security Engineer (IAM)

Pointwest-North America • Des Moines (IA)

On-site
USD 100,000 - 130,000
PAM Security Architect
PAM Security Architect

Compunnel, Inc. • Westlake (OH)

On-site
USD 120,000 - 150,000
PAM Engineer
PAM Engineer

Talon Professional Services • New York (NY)

Hybrid
USD 120,000 - 150,000
Senior Privileged Access Management (PAM) Specialist
Senior Privileged Access Management (PAM) Specialist

ECLARO • Canton (CT)

On-site
USD 90,000 - 130,000
401(k) Retirement Savings Plan
Commuter Check pre-tax commuter benefits
Medical, Dental & Vision Insurance eligibility