Sr Principal DT Security Engineer - 90343213 - Remote

Amtrak

United States

Hybrid

USD 149,000 - 194,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health and wellbeing programs
401K with employer match
Paid time off
Rail pass privileges
Dental and Vision

Job summary

Amtrak is seeking a Sr. Principal Systems Engineer to lead IAM strategy and enterprise authentication services across Active Directory, Microsoft Entra ID, PAM and certificate management in a large, complex environment.

You will shape roadmaps, guide architecture, and mentor teams while partnering with technology and business leaders to align security with business needs.

Qualifications

  • Experience focused on Identity and Access Management (IAM), authentication services, directory services, and access security technologies.
  • Extensive hands‑on experience designing, implementing, and supporting enterprise identity platforms, including Microsoft Active Directory and Microsoft Entra ID (Azure AD).
  • Demonstrated experience leading PAM programs and technologies, including privileged account governance and least-privilege security principles.

Responsibilities

  • Serve as SME for IAM services, providing strategic direction and technical leadership.
  • Lead architecture, design, implementation, and continuous improvement of enterprise authentication platforms.
  • Develop and maintain technology roadmaps, ensuring alignment with security requirements and business needs.
  • Lead planning and execution of complex IAM initiatives and programs.
  • Drive PAM strategy and certificate lifecycle management across enterprise identity infrastructures.
  • Provide governance for identity lifecycle management and authentication services.

Skills

IAM
Active Directory
Microsoft Entra ID
PAM
Certificate Lifecycle Management
PKI
Security architecture

Education

Bachelor’s Degree or equivalent
Certifications such as CISSP / IAM related

Tools

Federation services
PKI tooling
Certificate management tools

Job description

Your success is a train ride away! As we move America’s workforce toward the future, Amtrak connects businesses and communities across the country. We employ more than 20,000 diverse, energetic professionals in a variety of career fields throughout the United States. The safety of our passengers, our employees, the public and our operating environment is our priority, and the success of our railroad is due to our employees.

Your success is a train ride away! As we move America’s workforce toward the future, Amtrak connects businesses and communities across the country. We employ more than 20,000 diverse, energetic professionals in a variety of career fields throughout the United States. The safety of our passengers, our employees, the public and our operating environment is our priority, and the success of our railroad is due to our employees.

Are you ready to join our team? Our values of ‘Do the Right Thing, Excel Together and Put Customers First’ are at the heart of what matters most to us, and our Core Capabilities, ‘Building Trust, Accountability, Effective Communication, Customer Focus, and Proactive Safety & Security’ are what every employee needs to know and do to be most impactful at Amtrak. By living the Amtrak values, focusing on our capabilities, and actively embracing and fostering diverse ideas, backgrounds, and perspectives, together we will honor our past and make Amtrak a company of the future.

Job Summary

Leads the development and evolution of enterprise cybersecurity capabilities by shaping security strategy, advancing cyber defense architectures, and addressing emerging threats across the organization. This role requires a highly experienced technical leader who can serve as the organization's subject matter expert on Identity and Access Management (IAM) while driving the strategy, architecture, and delivery of enterprise authentication services. The Sr. Principal Systems Engineer is responsible for providing technical leadership and architectural guidance across Active Directory, Microsoft Entra ID, Privileged Access Management (PAM), Certificate Management and related identity technologies in a large, complex enterprise environment. Acting as a trusted advisor to both technology and business leadership, this individual leads the planning and execution of strategic initiatives, evaluates emerging technologies, develops long-term roadmaps, and influences enterprise architecture decisions both within and beyond the IAM domain.

Essential Functions
  • Serve as the senior technical authority and subject matter expert (SME) for Identity and Access Management (IAM) services, providing strategic direction and technical leadership across the organization.
  • Lead the architecture, design, implementation, and continuous improvement of enterprise authentication and identity platforms, including Active Directory, Microsoft Entra ID, and related identity technologies.
  • Develop and maintain technology roadmaps, ensuring alignment with organizational objectives, security requirements, compliance mandates, and future business needs.
  • Assists and/or may lead in the development and analysis of source selection strategies.
  • Provide architectural guidance and governance for enterprise initiatives, evaluating proposed solutions and ensuring adherence to IAM standards, security principles, and best practices.
  • Lead the planning and execution of complex projects and programs, including resource planning, prioritization, risk management, and stakeholder engagement.
  • Drive the strategy, implementation, and optimization of Privileged Access Management (PAM) solutions to strengthen security, reduce risk, and support regulatory compliance.
  • Serve as the subject matter expert for Certificate Lifecycle Management (CLM), providing technical leadership for enterprise PKI, digital certificates, and certificate automation.
  • Establish and enforce technical standards, policies, and operational procedures for identity lifecycle management, authentication services, privileged access, and directory services.
  • Provide end-to-end operational support for enterprise identity infrastructure, including monitoring, maintenance, incident response, and continuous improvement to ensure reliability, availability, performance, and security.
  • Collaborate with cross-functional teams to evaluate emerging technologies, assess risks, and influence strategic technology decisions across the enterprise.
  • Lead root cause analysis and resolution efforts for complex identity, authentication, authorization, and access-related issues, driving long-term corrective actions.
Minimum Qualifications
  • Bachelor’s Degree or equivalent combination of education, training and/or relevant experience.
  • Plus 9 years of relevant work experience.
  • Experience focused on Identity and Access Management (IAM), authentication services, directory services, and access security technologies.
  • Extensive hands‑on experience designing, implementing, and supporting enterprise identity platforms, including Microsoft Active Directory, Microsoft Entra ID (Azure AD), federation services, authentication protocols, and identity lifecycle management.
  • Demonstrated experience leading Privileged Access Management (PAM) programs and technologies, including privileged account governance, credential management, privileged session controls, and least-privilege security principles.
  • Proven experience serving as a technical lead or principal engineer in large, complex enterprise environments, providing architecture guidance, project leadership, and technical mentorship across multiple teams and disciplines.
  • Strong experience developing technology roadmaps, leading strategic initiatives, and consulting with executive and senior leadership, with the ability to translate business objectives into secure and scalable technical solutions.
Preferred Qualifications
  • Bachelor’s Degree or equivalent combination of education, training and/or relevant experience.
  • Plus 11 years of relevant work experience.
  • Industry certifications such as CISSP, Microsoft Certified: Identity and Access Administrator Associate, Microsoft Certified: Cybersecurity Architect Expert, CyberArk Defender/Sentry, or equivalent.
  • Experience supporting regulatory and compliance frameworks such as PCI DSS, NIST, SOX, ISO 27001, or similar.
  • Experience with hybrid identity architectures, cloud security, Zero Trust initiatives, Conditional Access Policies, MFA, and Identity Governance and Administration (IGA) solutions.
Knowledge, Skills, And Abilities
  • Excellent customer service, communication, and interpersonal skills essential for collaborative teamwork and self‑motivation.
  • Proficiency in identifying and implementing security measures, including understanding adversary tactics and tools.
  • Experience managing a diverse security ecosystem encompassing SIEM/SOAR, EDR/AV, CASB, IDS/IPS, DLP, UEBA, FW, IAM/SSO technologies.
  • Demonstrated ability to influence strategy and solve highly complex, ambiguous security challenges with broad organizational impact.
  • Proven ability to lead large, multi‑disciplinary initiatives and influence stakeholders across the organization without direct authority.

The salary/hourly range is $149,400.00 – $193,644.00. Pay is based on several factors including but not limited to education, work experience, certifications, etc. Depending on an employee’s assigned worksite or location, Amtrak may consider a geo-pay differential to be applied to the employee’s base salary. Amtrak may offer additional incentive and pay programs to recognize and reward our employees, including a short-term incentive bonus based upon factors such as individual and company performance that is commensurate with the level of the position.

Benefits
  • Health and Wellbeing Financial and Retirement Work and Family Life Support
  • Health, Dental, and Vision Insurance 401K with Employer Match Generous Paid Time Off
  • Wellness Programs Railroad Retirement Benefits Paid Caregiving Days and Backup Care
  • Health Savings Account Public Service Student Loan Forgiveness Fertility and Family Building Benefits
  • No-cost Personal Health Advocate Student Loan Assistance Adoption and Surrogacy Assistance
  • Medical Plan Opt-out Credit Tuition and Education Reimbursement Paid Family Leave
  • Life Insurance Rail Pass Privileges
  • Short- and Long-term Disability Insurance Employee Assistance Program
  • No-cost Financial Advisor Sessions Commuter and Flexible Spending Accounts

Requisition ID:167005

Work Arrangement: 02-Remote Optional

Relocation Offered: No

Travel Requirements: Up to 25%

You power our progress through your performance. We want your work at Amtrak to be more than a job. We want your career at Amtrak to be a fulfilling experience where you find challenging work, rewarding opportunities, respect among colleagues, and attractive compensation. Amtrak maintains a culture that values high performance and recognizes individual employee contributions.

Amtrak is committed to a safe workplace free of drugs and alcohol. All Amtrak positions requires a pre-employment background check that includes prior employment verification, a criminal history check and a pre-employment drug screen. Candidates who test positive for marijuana will be disqualified, regardless of any state or local statute, ordinance, regulation, or other law that legalizes or decriminalizes the use or possession of marijuana, whether for medical, recreational, or other use. Amtrak's pre-employment drug testing program is administered in accordance with DOT regulations and applicable law. In accordance with DOT regulations (49 CFR 40.25), Amtrak is required to obtain prior drug and alcohol testing records for applicants/employees intending to perform safety-sensitive duties for covered Department of Transportation positions. If an applicant/employee refuses to provide written consent for Amtrak to obtain these records, the individual will not be permitted to perform safety-sensitive functions. In accordance with federal law governing security checks of covered individuals for providers of public transportation (Title 6 U.S.C. 1143), Amtrak is required to screen applicants for any permanent or interim disqualifying criminal offenses. Note that any education requirement listed above may be deemed satisfied if you have an equivalent combination of education, training and experience. Amtrak is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race/color, to include traits historically associated with race, including but not limited to, hair texture and hairstyles such as braids, locks and twists, religion, sex (including pregnancy, childbirth and related conditions, such as lactation), national origin/ethnicity, disability (intellectual, mental and physical), veteran status, marital status, ancestry, sexual orientation, gender identity and gender expression, genetic information, citizenship or any other personal characteristics protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Cybersecurity Systems Security Officer - 90307947 - null
Principal Cybersecurity Systems Security Officer - 90307947 - null

Amtrak • Northern (KY)

Hybrid
USD 113,000 - 147,000
Health Insurance
Dental Insurance
Vision Insurance
+5
Sr Mgr Digital Technology - Physical Security Systems
Sr Mgr Digital Technology - Physical Security Systems

Amtrak • Wilmington (DE)

On-site
USD 149,000 - 194,000
Health, Dental, Vision
401K with employer match
Rail Pass Privileges
Director, DT Threat Detection & Engineering- 90284261 - null
Director, DT Threat Detection & Engineering- 90284261 - null

Amtrak • Northern (KY)

Hybrid
USD 179,000 - 232,000
Health Insurance
Dental Insurance
Vision Insurance
+3
Sr Mgr. Cyber Threat Intelligence - 90397460
Sr Mgr. Cyber Threat Intelligence - 90397460

Amtrak • Washington

On-site
USD 149,000 - 194,000
Health Insurance
401K with Employer Match
Paid Time Off
+2
Sr Principal Systems Engineer - 90394673 - Philadelphia Job Details | Amtrak
Sr Principal Systems Engineer - 90394673 - Philadelphia Job Details | Amtrak

Amtrak • New York (NY)

On-site
USD 136,000 - 176,000
Health and Wellbeing
Financial and Retirement
Paid Time Off
+1
Lead Network Engineer - Washington DC, Phila, Wilmington, Chicago
Lead Network Engineer - Washington DC, Phila, Wilmington, Chicago

Amtrak • Wilmington (DE)

On-site
USD 104,000 - 134,000
Health and Wellbeing
401K with Employer Match
Paid Time Off
+2
Principal Software Engineer - 90402969
Principal Software Engineer - 90402969

Amtrak • Wilmington (DE)

On-site
USD 124,000 - 162,000
Health, dental, and vision plans
401(k) retirement plan with employer match
Paid time off
+2
Principal Incident Response Analyst - 90397446 - null
Principal Incident Response Analyst - 90397446 - null

Amtrak • United States

Hybrid
USD 125,000 - 161,000
Health and Wellbeing
401K with Employer Match
Paid Time Off
+1
Director of Technology, Customer Engagement Platforms - Washington DC, Philadelphia, Remote Optional
Director of Technology, Customer Engagement Platforms - Washington DC, Philadelphia, Remote Optional

Amtrak • Philadelphia

On-site
USD 179,000 - 233,000
Health, Dental, and Vision Insurance
401K with Employer Match
Generous Paid Time Off
+4
Sr Software Engineer - 90404987 Job Details | Amtrak
Sr Software Engineer - 90404987 Job Details | Amtrak

Amtrak • Washington

On-site
USD 119,162,000 - 154,286,000
Health, dental, vision plans
401K retirement plan with employer-"“맞