We are seeking an Identity Security Engineer for a 6-month contract to hire hybrid role on site in Cary, NC to strengthen identity security, reduce privileged access risk, and enable secure access across enterprise systems, data, and cloud resources.
This role will engineer and support identity and privileged access solutions across cloud, on-premises, and hybrid environments, with a strong focus on Zero Standing Privilege (ZSP), Just-In-Time (JIT) access, least privilege, RBAC, Conditional Access, and modern authentication.
Responsibilities
- Design, implement, and support enterprise IAM and PAM solutions across cloud, on-premises, and hybrid environments.
- Engineer privileged access capabilities including credential vaulting, password rotation, session management, account onboarding, break-glass access, and lifecycle management.
- Advance ZSP, JIT access, least privilege, RBAC, and privileged access reduction initiatives.
- Implement and support Microsoft Entra ID, including Conditional Access, PIM, MFA, Identity Protection, passwordless authentication, and access controls.
- Support application access, SSO, federation, and authentication integrations using SAML, OAuth 2.0, OIDC, LDAP, Active Directory, and directory services.
- Secure privileged users, administrative and service accounts, application identities, machine identities, and other non-human identities.
- Onboard applications, servers, databases, endpoints, and cloud resources into PAM and identity security platforms.
- Develop privileged access standards, engineering runbooks, operational procedures, and Zero Trust access patterns.
- Automate identity and privileged access processes using PowerShell, Python, REST APIs, and workflow integrations.
- Troubleshoot IAM/PAM issues, perform root cause analysis, and remediate identity-related security risks and control gaps.
- Partner with security, infrastructure, cloud, application, and business teams on identity security initiatives.
Qualifications
- Bachelor’s degree in Cybersecurity, IT, Computer Science, Engineering, or related field, or equivalent experience.
- 3+ years of experience designing, implementing, or supporting IAM, PAM, or enterprise identity security solutions.
- 2+ years of hands-on PAM experience with CyberArk Privilege Cloud, CyberArk PAM, Delinea, BeyondTrust, or a comparable platform highly preferred.
- Hands-on experience with ZSP, JIT access, least privilege, RBAC, break-glass access, and privileged access reduction.
- Strong knowledge of Microsoft Entra ID, Conditional Access, PIM, MFA, Identity Protection, Active Directory, and modern authentication.
- Strong understanding of SSO, federation, SAML, OAuth 2.0, OIDC, and LDAP.
- Experience with PowerShell, Python, REST APIs, or identity workflow automation preferred.
- Ability to assess identity security risks, identify control gaps, and communicate practical remediation recommendations.
- Approximately 5% travel may be required.