The Senior Identity Security Engineer is responsible for designing, implementing, and operating the organization's identity and access security solutions. This role owns authentication, authorization, identity governance, privileged access, and Zero Trust identity controls that protect users, applications, and enterprise data.
Working closely with Security Engineering, Infrastructure, Cloud Engineering, HR Systems, and Application teams, this engineer develops scalable identity solutions that automate access, enforce least privilege, and improve the organization's security posture.
This position is hybrid 4 days a week in office.
Key Responsibilities
Identity Engineering
- Design and implement enterprise Identity and Access Management (IAM) solutions.
- Engineer authentication and authorization architectures using SAML, OAuth, OpenID Connect, SCIM, and modern authentication standards.
- Design and maintain Conditional Access policies and adaptive authentication controls.
- Implement and maintain MFA, passwordless authentication, and phishing-resistant authentication technologies.
- Engineer lifecycle automation for Joiner, Mover, and Leaver processes.
Identity Governance
- Design and implement Identity Governance Administration (IGA) capabilities.
- Develop role-based access control (RBAC) and entitlement models.
- Automate access reviews, certifications, and segregation-of-duty controls.
- Develop integrations between HR systems, directories, SaaS platforms, and business applications.
Zero Trust Identity
- Implement identity-centric Zero Trust controls.
- Integrate identity posture with Zscaler ZPA where appropriate.
- Design least-privilege access models across cloud and on-premises environments.
Automation
- Develop PowerShell, Python, Graph API, REST API, and SCIM automation.
- Build identity provisioning and reporting workflows.
- Develop operational dashboards and compliance reporting.
- Provide identity architecture guidance for new applications.
- Partner with application owners to integrate enterprise identity standards.
Qualifications
- Bachelor's degree in Computer Science, Information Security, or related field.
- 6+ years of Identity Engineering or Security Engineering experience.
- Experience with Entra ID, Active Directory, or similar identity platforms.
- Experience implementing IAM and Identity Governance solutions.
- Experience with Conditional Access, MFA, SAML, OAuth, OpenID Connect, SCIM.
- Experience with PowerShell and Microsoft Graph.
- Experience integrating SaaS applications using enterprise SSO.
- Familiarity with Zero Trust architecture.
- Experience with NIST, CIS Controls, and identity security best practices.
Salary Range: $140,000—$160,000 USD base