Senior Security Engineer

Edward Jones

St. Louis (MO)

On-site

USD 130,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
Dental & Vision
401k with matching
HSA/FSA
Paid holidays
Vacation & sick leave
Bonuses and profit sharing
Employee Assistance Program

Job summary

Edward Jones seeks a highly technical Senior Non-Human Identity Engineer to lead engineering, automation, onboarding, remediation, and operational management of machine identities across cloud, on‑premises, and hybrid environments. You will personally build solutions, automate tasks, and work with DevOps, cybersecurity, and infrastructure teams to secure lifecycles of service accounts and credentials.

The role requires deep IAM expertise, strong scripting (PowerShell, Python), and comfort in a

Qualifications

  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Engineering, or equivalent experience.
  • 7+ years hands-on Identity and Access Management / cybersecurity engineering / cloud security.
  • 5+ years direct experience managing non-human identities, service accounts, workload identities, or machine authentication technologies.
  • Strong hands-on experience with Microsoft Entra ID, Active Directory, or similar identity platforms.
  • Experience implementing and supporting secrets management and privileged access solutions.
  • Strong scripting and automation skills (PowerShell, Python, Bash).
  • Experience with OAuth 2.0, OpenID Connect, SAML, Kerberos, LDAP, PKI.
  • Experience supporting multi-cloud (Azure, AWS, GCP).
  • Ability to analyze logs and troubleshoot identity-related issues.
  • Experience with enterprise change management and incident response processes.
  • Strong communication and collaboration across tech teams.

Responsibilities

  • Engineer, implement, and support enterprise non-human identity solutions across cloud, on-premises, and hybrid environments.
  • Develop and maintain automated provisioning, credential rotation, secret management, certificate lifecycle management, and deprovisioning processes.
  • Onboard and migrate service accounts, managed identities, workload identities, application accounts, and machine credentials.
  • Configure, deploy, and support privileged access controls for non-human identities using PAM and secrets management.
  • Eliminate hardcoded credentials and modernize authentication methods across applications.
  • Design and maintain automation using PowerShell, Python, REST APIs, Terraform, and other tools.
  • Integrate identity controls into CI/CD and DevSecOps workflows.
  • Troubleshoot authentication, authorization, federation, certificates, tokens, and credential issues across apps.
  • Support large-scale remediation for dormant accounts, excessive permissions, and identity security risks.
  • Configure and administer identity platforms including directory services, cloud ID providers, PAM, and PKI.
  • Monitor identity activity and investigate suspicious events or policy violations.
  • Conduct access reviews and entitlement analysis to enforce least-privilege.
  • Create runbooks, guides, engineering standards, and technical docs.
  • Collaborate with Security Operations and Incident Response during investigations.
  • Participate in after-hours support and major incidents when required.

Skills

IAM
Scripting
PowerShell
Python
REST APIs
Terraform
CI/CD
DevSecOps
Troubleshooting
Authentication issues
Cloud platforms

Education

Bachelor's degree in IT / cybersecurity / CS / engineering

Tools

Microsoft Entra ID
Active Directory
Secrets vaults (Delinea, CyberArk, etc.)

Job description

This job posting is anticipated to remain open for 30 days, from 14-Jul-2026. The posting may close early due to the volume of applicants.

Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500¹ company where people come first. With over 9 million clients and 20,000 financial advisors across the U.S. and Canada, we’re proud to be privately-owned, placing the focus on our clients rather than shareholder returns.

Behind everything we do is our purpose: We partner for positive impact to improve the lives of our clients and colleagues, and together, better our communities and society. We are an innovative, flexible, and inclusive organization that attracts, develops, and inspires performance excellence and a sense of belonging.

People are at the center of our partnership. Edward Jones associates are seen, heard, respected, and supported. This is what we believe makes us the best place to start or build your career.

View our Purpose, Inclusion and Citizenship Report.

Team Overview:

We are seeking a highly technical, hands‑on Senior Non-Human Identity Engineer to lead the engineering, automation, onboarding, remediation, and operational management of non-human identities across the enterprise. This role is focused on the implementation and day-to-day engineering of machine identities, service accounts, workload identities, API credentials, certificates, secrets, and privileged application accounts supporting cloud, on‑premises, and hybrid environments.

This is not an architecture-only or governance-only position. The successful candidate will be expected to personally build solutions, write automation, troubleshoot authentication issues, onboard applications, integrate platforms, and drive remediation efforts. The engineer will work closely with application teams, DevOps, cloud engineering, cybersecurity, and infrastructure teams to ensure non-human identities are properly secured, monitored, and managed throughout their lifecycle.

The ideal candidate combines deep IAM expertise with strong scripting, automation, cloud, and troubleshooting skills, and is comfortable operating in a fast-paced enterprise environment where hands‑on execution is critical.

What You'll Do:
  • Engineer, implement, and support enterprise non-human identity solutions across cloud, on-premises, and hybrid environments.
  • Develop and maintain automated provisioning, credential rotation, secret management, certificate lifecycle management, and deprovisioning processes.
  • Perform onboarding and migration of service accounts, managed identities, workload identities, application accounts, and machine credentials into enterprise identity management platforms.
  • Configure, deploy, and support privileged access controls for non-human identities using PAM and secrets management technologies.
  • Work directly with development, application, and infrastructure teams to eliminate hardcoded credentials and replace legacy authentication methods with modern identity solutions.
  • Design, build, and maintain automation using PowerShell, Python, REST APIs, Terraform, and other scripting or orchestration technologies.
  • Integrate identity controls into CI/CD pipelines and DevSecOps workflows.
  • Troubleshoot and resolve authentication, authorization, federation, certificate, token, and credential-related issues across enterprise applications.
  • Support large‑scale remediation initiatives involving dormant service accounts, excessive permissions, unmanaged secrets, and identity-related security vulnerabilities.
  • Configure and administer identity platforms, including directory services, cloud identity providers, PAM solutions, certificate authorities, and secrets vaults.
  • Monitor non-human identity activity and investigate suspicious authentication events, credential misuse, or policy violations.
  • Conduct access reviews and entitlement analysis to ensure least-privilege principles are maintained.
  • Create operational runbooks, implementation guides, engineering standards, and technical documentation.
  • Partner with Security Operations and Incident Response teams during investigations involving machine identities and application credentials.
  • Participate in after-hours support activities, major incident response, and maintenance activities when required.
What Experience You'll Need:
  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Engineering, or equivalent experience.
  • 7+ years of hands‑on experience in Identity and Access Management, Cybersecurity Engineering, Infrastructure Engineering, or Cloud Security.
  • 5+ years of direct experience managing non-human identities, service accounts, application identities, workload identities, or machine authentication technologies.
  • Strong hands‑on experience administering Microsoft Entra ID, Active Directory, or similar identity platforms.
  • Experience implementing and supporting secrets management, credential vaulting, and privileged access solutions.
  • Strong scripting and automation skills using PowerShell, Python, Bash, or similar technologies.
  • Experience working with OAuth 2.0, OpenID Connect, SAML, Kerberos, LDAP, certificates, and PKI technologies.
  • Experience supporting Azure, AWS, Google Cloud, or multi-cloud environments.
  • Ability to analyze logs, troubleshoot authentication failures, and resolve complex identity-related issues.
  • Experience working within enterprise change management, incident management, and operational support processes.
  • Strong verbal and written communication skills with the ability to collaborate across technical teams.
What Could Set You Apart:
  • Hands‑on experience with CyberArk, HashiCorp Vault, Delinea, BeyondTrust, SailPoint, Microsoft Entra Workload Identities, or similar platforms.
  • Experience managing certificate lifecycles and public/private key infrastructure.
  • Experience securing Kubernetes, containers, microservices, and cloud-native applications.
  • Familiarity with Infrastructure as Code technologies such as Terraform, Bicep, ARM, or CloudFormation.
  • Experience with SIEM platforms and identity security monitoring.
  • CISSP, CISM, Security+, Microsoft Identity and Access Administrator, CyberArk Defender/Sentry, or related certifications.
Candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office four days per week effective June 1, 2026. Before June 1, 2026, candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office three days per week, with preference for Tuesday through Thursday.

At Edward Jones, we are building a place where everyone feels like they belong. We're proud of our associates' contributions to the firm and the recognitions we have received.

Check out our U.S. awards and accolades: Insights & Information Blog Postings about Edward Jones

Check out our Canadian awards and accolades: Insights & Information Blog Postings about Edward Jones

Edward Jones does not discriminate on the basis of race, color, gender, religion, national origin, age, disability, sexual orientation, pregnancy, veteran status, genetic information or any other basis prohibited by applicable law.

Edward Jones' compensation and benefits package includes medical and prescription drug, dental, vision, voluntary benefits (such as accident, hospital indemnity, and critical illness), short- and long-term disability, basic life, and basic AD&D coverage. Short- and long-term disability, basic life, and basic AD&D coverage are provided at no cost to associates. Edward Jones offers a 401k retirement plan, and tax-advantaged accounts: health savings account, and flexible spending account. Edward Jones observes ten paid holidays and provides 15 days of vacation for new associates beginning on January 1 of each year, as well as sick time, personal days, and a paid day for volunteerism. Associates may be eligible for bonuses and profit sharing. All associates are eligible for the firm's Employee Assistance Program. For more information on the Benefits available to Edward Jones associates, please visit our benefits page.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer IV
Application Security Engineer IV

Edward Jones • St. Louis (MO)

Hybrid
USD 140,000 - 190,000
401(k) plan
Medical + prescription
Dental & vision
+5
Senior Security Analyst - Identity and Access Governance
Senior Security Analyst - Identity and Access Governance

Edward Jones • Tempe (AZ)

On-site
USD 90,000 - 130,000
Medical benefits
401k plan
Paid holidays
+2
Security Engineer IV
Security Engineer IV

Edward Jones • St. Louis (MO)

Hybrid
USD 120,000 - 150,000
Application Security Architect
Application Security Architect

Edward Jones • St. Louis (MO)

Hybrid
USD 150,000 - 230,000
Medical and prescription drug coverage
Dental coverage
Vision coverage
+2
Application Security Engineer IV - AI Harness
Application Security Engineer IV - AI Harness

Edward Jones • St. Louis (MO)

Hybrid
USD 120,000 - 170,000
Medical benefits
Dental benefits
Vision benefits
+2
Team Leader - Security Engineering
Team Leader - Security Engineering

Edward Jones • St. Louis (MO)

Hybrid
USD 120,000 - 150,000
Medical and prescription drug
Dental
Vision
+5
Senior Technical Product Owner (DevOps)
Senior Technical Product Owner (DevOps)

Edward Jones • St. Louis (MO)

Hybrid
USD 130,000 - 170,000
Security Architect - Vulnerability Exposure Management
Security Architect - Vulnerability Exposure Management

Edward Jones • St. Louis (MO)

Hybrid
USD 140,000 - 190,000
Medical and prescription drug
Dental and vision
401k retirement plan
+2
Security Engineer IV
Security Engineer IV

Edward Jones • Tempe (AZ)

Hybrid
USD 120,000 - 150,000
Security Architect - Vulnerability Exposure Management
Security Architect - Vulnerability Exposure Management

Edward Jones • Tempe (AZ)

On-site
USD 140,000 - 190,000