Security Engineer - Network & Identity (Contractor)

Sungrow

Houston (TX)

Hybrid

USD 140,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health, dental, vision benefits
401(k) retirement plans
Paid time off

Job summary

Sungrow USA is hiring a Security Engineer – Network & Identity to design and own our network security, PKI, and identity infrastructure across on‑prem, cloud, and SaaS. You will focus on Zero Trust, machine identities, and secure access controls, not incident response.

The role requires hands‑on expertise with Entra ID, MFA, and PKI platforms, plus automation to improve security posture across Azure, AWS, and hybrid environments.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent.
  • 5+ years of security engineering, IAM, network security, or cloud security.
  • Hands-on with Microsoft Entra ID including CA, MFA, SSO, and Conditional Access.
  • Experience with Fortinet and Zscaler in Zero Trust architectures.
  • Experience designing and operating enterprise PKI and certificate lifecycle management.

Responsibilities

  • Design, implement, and maintain enterprise network security architectures.
  • Own PKI, cryptography, and certificate lifecycle management across Azure/AWS/hybrid.
  • Implement and enforce identity security controls, MFA, and conditional access.
  • Develop automation for identity provisioning, certificate management, and security validation.
  • Support network access control, SSO integrations, and least-privilege access models.

Skills

Network security
IAM / Identity
PKI / certificate mgmt
Zero Trust
Fortinet
Zscaler
Microsoft Entra ID
MFA / Passwordless
TLS/mTLS
Automation / IaC

Education

Bachelor's degree in CS/IT/Engineering
Security certifications (SC-300, AZ-500, CISSP, CISM)

Tools

Fortinet
Zscaler
Microsoft Entra ID
Keyfactor / PKI tools
DigiCert / PKI platforms

Job description

About the Company: Sungrow North America is a leading provider of renewable energy solutions, specializing in the development and manufacturing of photovoltaic inverters and energy storage systems. The company offers a comprehensive range of products and services designed to optimize the performance and efficiency of solar power installations. Sungrow North America aims to provide sustainable and reliable energy solutions to meet the growing demand for clean power and is known for its commitment to innovation, high-quality standards, and exceptional customer service.

Security Engineer – Network & Identity

The Security Engineer (Network & Identity) is a hands-on engineering role within the IT team responsible for designing, implementing, securing, and automating Sungrow USA's network security, PKI and certificate management, and identity & access infrastructure across on-premises, cloud, and SaaS environments. This role serves as the technical owner for network security architecture, cryptographic services, certificate lifecycle management, authentication, and access controls. The position focuses on Zero Trust security, network segmentation, certificate-based authentication, and identity protection to reduce organizational risk and enable secure business operations and platform ownership rather than SOC operations, threat monitoring, or incident response.

Essential Duties And Responsibilities
Network Security
  • Design, implement, and maintain secure enterprise network architectures across corporate offices, data centers, cloud platforms, and remote workforce environments.
  • Architect network segmentation, Zero Trust access controls, and secure connectivity standards using Fortinet and Zscaler security solutions.
  • Develop and maintain Zero Trust architectures across network, identity, endpoint, application, and cloud environments.
  • Design and administer secure remote access using Zscaler Private Access, VPN technologies, and identity-aware access controls.
  • Manage firewall policies, network security controls, routing security, DNS security, and hybrid-cloud connectivity.
  • Design and support Network Access Control architectures using IEEE 802.1X, RADIUS, and certificate-based authentication.
  • Assess network security posture, develop remediation plans, and drive continuous security improvements.
Cryptography, PKI & Certificate Management
  • Own the enterprise PKI, cryptography, and certificate lifecycle management architecture, standards, and governance program.
  • Design and manage certificate-based authentication and machine identity solutions for users, devices, servers, applications, cloud workloads, and network infrastructure across Azure, AWS, and hybrid environments.
  • Implement and maintain certificate lifecycle automation using Microsoft Cloud PKI, Keyfactor, CyberArk Certificate Manager, EJBCA, DigiCert, AppViewX, or comparable platforms.
  • Manage certificate issuance, enrollment, discovery, deployment, monitoring, renewal, revocation, auditing, and compliance across the enterprise.
  • Design and support cryptographic services and certificate-based security controls, including TLS/mTLS, code signing, PKI trust hierarchies, certificate-based authentication, SCEP, PKCS, and machine identities.
  • Establish PKI and cryptographic standards, key management practices, and security controls to support Zero Trust, regulatory compliance, and enterprise security requirements.
  • Troubleshoot and resolve complex certificate, cryptographic, trust chain, authentication, and secure communications issues across enterprise systems and applications.
Identity & Access
  • Define authentication and authorization standards for workforce, partner, application, service, and machine identities.
  • Design, implement, and maintain Microsoft Entra ID architecture, tenant governance, and identity security controls.
  • Develop, test, and enforce Conditional Access policies and Zero Trust access controls.
  • Implement and maintain MFA, passwordless authentication, phishing-resistant authentication, and Microsoft Entra ID Protection capabilities.
  • Design and support enterprise SSO and federation integrations using SAML, OAuth 2.0, OpenID Connect, and SCIM.
  • Implement least-privilege and risk-based access models across enterprise platforms.
  • Administer RBAC, administrative separation, Microsoft Entra Privileged Identity Management, and least-privilege access controls.
  • Govern application registrations, service principals, enterprise applications, API permissions, and managed identities.
  • Support B2B collaboration, guest-user governance, external workforce access, and third-party identity integrations.
  • Design and implement security controls across Microsoft Azure and AWS environments.
  • Apply least privilege, RBAC, encryption, secrets management, and secure configuration standards to on-prem and cloud resources.
  • Automate identity provisioning and deprovisioning, access governance, certificate management, configuration validation, and security operations.
  • Create reusable secure-by-default templates and reduce manual administration through automation and orchestration.
  • Conduct access reviews, entitlement certifications, and identity governance activities.
Education Or Desired License And Certificates
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent professional experience.
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300) preferred.
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500) preferred.
  • CCNA, Fortinet, Zscaler, AWS Security, CISSP, CISM, Terraform, or relevant PKI certification preferred
Preferred Experience & Qualifications
  • 5+ years of experience in security engineering, identity & access management (IAM), network security, cloud security, or a related enterprise IT discipline.
  • Hands-on experience with Microsoft Entra ID, including Conditional Access, MFA, SSO, Identity Protection, PIM, RBAC, identity governance, and modern authentication protocols (SAML, OAuth, OpenID Connect, SCIM).
  • Experience designing, implementing, and securing enterprise identity, privileged access, and machine identity solutions across hybrid and multi-cloud environments.
  • Hands-on experience with Fortinet, Zscaler (ZIA/ZPA), Zero Trust architectures, least-privilege access models, and network security controls.
  • Experience designing and operating enterprise PKI, certificate lifecycle management, certificate-based authentication, and machine identity platforms such as Keyfactor, DigiCert, EJBCA, AppViewX, CyberArk Certificate Manager, or similar solutions.
  • Experience securing Azure and AWS environments, including identity, networking, encryption, secrets management, logging, and security monitoring.
  • Experience with PAM and IGA platforms such as CyberArk, Delinea, BeyondTrust, SailPoint, Saviynt, or similar technologies.
  • Experience integrating identity, network, cloud, and security telemetry with SIEM and security operations platforms.
  • Strong automation and Infrastructure as Code skills using PowerShell, Python, Microsoft Graph API, REST APIs, Terraform, or similar technologies.
  • Strong troubleshooting skills across authentication, federation, certificates, PKI, network security, cloud access, application integrations, and enterprise identity services.
  • Knowledge of cybersecurity and compliance frameworks including SOC 2, ISO/IEC 27001, NIST CSF, NIST 800-63, CIS Controls, Zero Trust, and NERC CIP.
Competencies
  • Mandarin fluency preferred but not required.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Ability to work independently and collaboratively in a fast-paced environment.
  • Excellent communication, stakeholder management, and technical documentation skills.
  • Strong organization, attention to detail, initiative, and ownership.
  • Ability to balance security, reliability, usability, scalability, and business requirements.
  • Proactive approach to automation, standardization, and continuous improvement.
Travel

5%-20%

Work Location and Status
  • Full time, Hybrid at any Sungrow USA office in Phoenix, Costa Mesa, or Houston
  • No visa sponsorship
Compensation
  • Compensation commensurate with experience
  • Competitive salary and annual bonus eligibility
  • Comprehensive benefits package including health, dental, vision, and retirement plans
  • Strong personal and company growth opportunities

Sungrow is an equal opportunity employer. Due to strong interest in this position, Sungrow will only reach out to those candidates who best meet the requirements. Thank you for your interest in Sungrow.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer - Network & Identity (Contractor)
Security Engineer - Network & Identity (Contractor)

ADP, Inc. • Houston (TX)

Hybrid
USD 90,000 - 130,000
Information Security Compliance Analyst
Information Security Compliance Analyst

Sungrow Na • Northern (KY)

Hybrid
USD 110,000 - 135,000
Security Engineer: Network & Identity, Zero Trust
Security Engineer: Network & Identity, Zero Trust

Sungrow • Houston (TX)

Hybrid
USD 140,000 - 180,000
Health, dental, vision benefits
401(k) retirement plans
Paid time off
Field Service Technician - BESS
Field Service Technician - BESS

Sungrow • Denver (CO)

On-site
USD 50,000 - 55,000
Competitive benefits package
Employee programs
Field Service Technician - PV
Field Service Technician - PV

Sungrow • Phoenix (AZ)

On-site
USD 103,155,000 - 114,616,000
Senior Technical Quality Engineer
Senior Technical Quality Engineer

Sungrow • Houston (TX)

Hybrid
USD 103,000 - 140,000
Remote work options
Comprehensive training programs
Professional development opportunities
Field Service Technician - PV
Field Service Technician - PV

Sungrow • Peoria (IL)

On-site
Competitive benefits package
Opportunities for personal and company growth
Field Service Technician - PV
Field Service Technician - PV

RiseMe • Jacksonville (FL)

Hybrid
USD 50,000 - 55,000
Field Service Technician - PV
Field Service Technician - PV

Sungrow • Bowling Green (KY)

On-site
Field Service Technician - BESS
Field Service Technician - BESS

Sungrow USA Corporation • Fresno (CA)

Hybrid
USD 50,000 - 55,000