×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Identity and Access Security Engineer

Job in Baltimore, Anne Arundel County, Maryland, 21276, USA
Listing for: Brown Advisory Incorporated
Full Time position
Listed on 2026-08-12
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 110000 - 135000 USD Yearly USD 110000.00 135000.00 YEAR
Job Description & How to Apply Below

Company Overview

Company Overview Every firm has a culture – the values, beliefs, methodology, attitudes and standards that reflect an organization’s DNA. But the truly inspiring firms – the game‑changers, the industry leaders and the disruptors – have cultures that propel them to innovate and stand out. At Brown Advisory, we aim to be one of those inspired firms. Over the years, we have purposefully built and nurtured our client‑first culture.

Brown Advisory is an independent investment management and strategic advisory firm committed to delivering a combination of first‑class performance, strategic advice and the highest level of client service. The firm’s clients—including individuals, families, family offices, endowments, foundations, charities, institutions, consultants, and financial intermediaries—are served by over 1,000 colleagues worldwide, all of whom are equity owners of the firm.

Brown Advisory is currently seeking an Identity and Access Security Engineer to lead and mature the firm's identity security controls across Okta, Microsoft Entra , Active Directory, Cyber Ark, Blood Hound Enterprise, multifactor authentication, privileged access, application integrations, and access governance. This blended role is designed for a hands‑on security professional who understands identity as both a business‑enablement workflow and a critical security control plane.

The engineer will be responsible for reducing identity‑related risk across workforce, privileged, service, application, and machine identities. The role combines identity engineering, privileged‑access management, identity threat exposure management, access governance, attack‑path remediation, and operational control assurance. As part of a lean Information Security team within a mid‑sized financial services organization, this individual will partner with Infrastructure, Enterprise Applications, Compliance, Human Resources, Operations, and business system owners.

The role will help ensure that access is appropriately granted, reviewed, monitored, and removed while enabling secure adoption of SaaS, cloud, and on‑premises platforms.

Blended Role Coverage
  • Primary emphasis:
    Identity security engineering and governance across IAM, PAM, identity threat exposure management, MFA, privileged access, access reviews, and identity‑related risk.
  • Blended coverage:
    Okta and Entra n, Cyber Ark platform operations and privileged‑account onboarding, service‑account governance, Blood Hound Enterprise analysis and attack‑path remediation, Active Directory privilege hygiene, SaaS access controls, identity lifecycle automation, and selected security‑engineering support.
Duties and Responsibilities
  • Own the day‑to‑day security governance and engineering of identity controls across Okta, Microsoft Entra , Active Directory, MFA, Conditional Access, privileged access, and identity lifecycle workflows.
  • Design, implement, operate, and continuously improve privileged‑access controls using Cyber Ark, including account discovery, vault onboarding, credential rotation, access workflows, session controls, privileged‑account monitoring, break‑glass access, and evidence collection.
  • Govern the lifecycle of privileged human and non‑human identities, including administrator accounts, service accounts, application credentials, scheduled‑task accounts, emergency accounts, and other machine identities.
  • Identify privileged and service accounts that are unmanaged, improperly configured, inactive, or outside established Cyber Ark controls, and coordinate their onboarding, remediation, or retirement.
  • Develop and maintain Cyber Ark safes, platforms, policies, account ownership models, reconciliation processes, access permissions, operational procedures, and recovery documentation.
  • Operate Blood Hound Enterprise as an identity threat exposure management capability, analyzing attack paths, Tier Zero relationships, excessive privilege, nested group membership, delegated permissions, and other identity‑control weaknesses.
  • Translate Blood Hound findings into prioritized and actionable remediation plans, working with Infrastructure and application owners to remove unnecessary privilege…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary