Security Engineer

CDW

Cary (NC)

Hybrid

USD 110,000 - 160,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

CDW in Cary, NC is seeking an Identity Security Engineer for a 6-month contract to hire in a hybrid on-site role. You will strengthen identity security, reduce privileged access risk, and enable secure access across enterprise systems, data, and cloud resources.

You will engineer and support IAM and PAM solutions across cloud, on-prem, and hybrid environments, with a focus on ZSP, JIT, least privilege, RBAC, Conditional Access, and modern authentication.

Qualifications

  • Bachelor’s degree or equivalent experience in a cybersecurity-related field.
  • 3+ years of experience designing, implementing, or supporting IAM, PAM, or enterprise identity security solutions.
  • 2+ years of hands-on PAM experience with CyberArk Privilege Cloud, CyberArk PAM, Delinea, BeyondTrust, or a comparable platform.

Responsibilities

  • Design, implement, and support IAM and PAM solutions across cloud, on-premises, and hybrid environments.
  • Engineer privileged access capabilities including credential vaulting, password rotation, session management, and lifecycle management.
  • Advance ZSP, JIT access, least privilege, RBAC, and privileged access reduction initiatives.
  • Implement and support Microsoft Entra ID, including Conditional Access, PIM, MFA, Identity Protection, passwordless authentication, and access controls.
  • Support application access, SSO, federation, and authentication integrations using SAML, OAuth 2.0, OIDC, LDAP, Active Directory, and directory services.
  • Secure privileged users, administrative and service accounts, application identities, machine identities, and other non-human identities.
  • Onboard applications, servers, databases, endpoints, and cloud resources into PAM and identity security platforms.
  • Develop privileged access standards, engineering runbooks, operational procedures, and Zero Trust access patterns.
  • Automate identity and privileged access processes using PowerShell, Python, REST APIs, and workflow integrations.
  • Troubleshoot IAM/PAM issues, perform root cause analysis, and remediate identity-related security risks and control gaps.
  • Partner with security, infrastructure, cloud, application, and business teams on identity security initiatives.

Skills

IAM
PAM
Zero Standing Privilege
Just-In-Time access
least privilege
RBAC
Conditional Access
MFA
SSO
Active Directory
PowerShell
Python
REST APIs

Education

Bachelor's degree in Cybersecurity, IT, Computer Science, Engineering, or related field

Tools

CyberArk Privilege Cloud
CyberArk PAM
Delinea
BeyondTrust

Job description

We are seeking an Identity Security Engineer for a 6-month contract to hire hybrid role on site in Cary, NC to strengthen identity security, reduce privileged access risk, and enable secure access across enterprise systems, data, and cloud resources.

This role will engineer and support identity and privileged access solutions across cloud, on-premises, and hybrid environments, with a strong focus on Zero Standing Privilege (ZSP), Just-In-Time (JIT) access, least privilege, RBAC, Conditional Access, and modern authentication.

Responsibilities
  • Design, implement, and support enterprise IAM and PAM solutions across cloud, on-premises, and hybrid environments.
  • Engineer privileged access capabilities including credential vaulting, password rotation, session management, account onboarding, break-glass access, and lifecycle management.
  • Advance ZSP, JIT access, least privilege, RBAC, and privileged access reduction initiatives.
  • Implement and support Microsoft Entra ID, including Conditional Access, PIM, MFA, Identity Protection, passwordless authentication, and access controls.
  • Support application access, SSO, federation, and authentication integrations using SAML, OAuth 2.0, OIDC, LDAP, Active Directory, and directory services.
  • Secure privileged users, administrative and service accounts, application identities, machine identities, and other non-human identities.
  • Onboard applications, servers, databases, endpoints, and cloud resources into PAM and identity security platforms.
  • Develop privileged access standards, engineering runbooks, operational procedures, and Zero Trust access patterns.
  • Automate identity and privileged access processes using PowerShell, Python, REST APIs, and workflow integrations.
  • Troubleshoot IAM/PAM issues, perform root cause analysis, and remediate identity-related security risks and control gaps.
  • Partner with security, infrastructure, cloud, application, and business teams on identity security initiatives.
Qualifications
  • Bachelor’s degree in Cybersecurity, IT, Computer Science, Engineering, or related field, or equivalent experience.
  • 3+ years of experience designing, implementing, or supporting IAM, PAM, or enterprise identity security solutions.
  • 2+ years of hands-on PAM experience with CyberArk Privilege Cloud, CyberArk PAM, Delinea, BeyondTrust, or a comparable platform highly preferred.
  • Hands-on experience with ZSP, JIT access, least privilege, RBAC, break-glass access, and privileged access reduction.
  • Strong knowledge of Microsoft Entra ID, Conditional Access, PIM, MFA, Identity Protection, Active Directory, and modern authentication.
  • Strong understanding of SSO, federation, SAML, OAuth 2.0, OIDC, and LDAP.
  • Experience with PowerShell, Python, REST APIs, or identity workflow automation preferred.
  • Ability to assess identity security risks, identify control gaps, and communicate practical remediation recommendations.
  • Approximately 5% travel may be required.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity Security Engineer
Identity Security Engineer

Eliassen Group • Cary (NC)

Hybrid
USD 111,000 - 116,000
Identity Security Engineer — IAM/PAM, ZSP & JIT
Identity Security Engineer — IAM/PAM, ZSP & JIT

CDW • Cary (NC)

Hybrid
USD 110,000 - 160,000
Identity and Security Engineer
Identity and Security Engineer

Ledgent Technology • Houston (TX)

On-site
USD 130,000 - 140,000
Information Technology Security Engineer
Information Technology Security Engineer

IZAR Associates, Inc. • United States

On-site
USD 100,000 - 130,000
Senior Identity Security Engineer
Senior Identity Security Engineer

Talent Mappers • Denver (CO)

Hybrid
USD 140,000 - 160,000
Senior Identity Security Engineer
Senior Identity Security Engineer

Talent Mappers • Illinois

Hybrid
USD 140,000 - 160,000
PAM Engineer
PAM Engineer

JCW Group • Charlotte (NC)

On-site
USD 120,000 - 180,000
Privileged Access Management Engineer
Privileged Access Management Engineer

JCW Group • Charlotte (NC)

On-site
USD 180,000 - 240,000
Identity and Access Management Engineer
Identity and Access Management Engineer

Socket.dev • Fairfax (VA)

Hybrid
USD 130,000 - 180,000
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000