Security Engineer – Identity, Access Management & Detection
Listed on 2026-08-17
-
IT/Tech
Cybersecurity, Information Security & Data Protection
At Air Life, we are dedicated to improving the quality of every breath. Excellence with Every Breath is not just a tag line, but the way we work and take care of our customers. With a mindset to evolve, innovate, and grow, we are a premier manufacturer of the highest-quality and market-leading breathing consumables. This growth philosophy has positioned us to increase our global footprint and business reach, impacting even more people around the world.
Our expanding family of the most trusted brands offers a product portfolio that spans the continuum of care from first responder to home care, with safety, patient comfort, and clinical performance in mind. Collective expertise allows us to provide quality products and experiences to our patients, customers, and our people. Our values of Customer first, Differentiate with our People, Bias for Action, Continuous Improvement and Accountability define who we are and how we work.
Join us!
The Security Engineer – Identity, Access Management & Detection is responsible for designing, implementing, and operating Air Life's identity and access management infrastructure while also contributing to the detection and response capabilities that protect the enterprise from evolving cyber threats. This role manages user identities, authentication mechanisms, access privileges, and privileged account controls across Air Life's global environment, while partnering with Air Life's managed detection and response provider (Arctic Wolf) to ensure that identity-based and broader cyber threats are effectively detected, investigated, and remediated.
This dual-focus role is central to Air Life's Zero Trust maturity journey and its ability to maintain a secure, compliant, and resilient IT environment.
- Deep understanding of Identity and Access Management architecture, including IAM lifecycle management, Identity Governance and Administration (IGA), and Privileged Access Management (PAM).
- Hands-on experience with Microsoft Entra on-premises Active Directory;
Power Shell scripting experience required. - Experience with Cisco Duo MFA, Microsoft Intune MDM, and the Microsoft Defender security suite.
- Practical knowledge of automated provisioning and deprovisioning, role-based access control (RBAC), Single Sign-On (SSO) configuration, LDAP, and federation standards.
- Working knowledge of security threat detection concepts, SIEM platform interaction, and security alert triage; experience collaborating with MDR/MSSP providers on alert tuning and incident escalation (Arctic Wolf experience preferred).
- Understanding of Zero Trust architecture principles and their application to identity-first security design.
- Experience with vulnerability management, endpoint protection agent management, and data loss prevention tooling.
- Knowledge of security compliance frameworks (NIST, ISO 27001, CIS Controls, GDPR) with practical experience applying them to IAM control design.
- Experience with backup and disaster recovery systems (Rubrik/Azure preferred).
- Strong root cause analysis and technical troubleshooting skills for complex identity and security issues.
- Ability to manage concurrent projects and tasks in a dynamic environment;
Smartsheet experience preferred. - Experience with KnowBe4 security awareness and phishing simulation administration preferred.
- Relevant IAM or cybersecurity certification preferred (Microsoft SC-300, CompTIA Security+, SSCP, or equivalent).
Minimum 4-8 years of IT experience with 3+ years in a cybersecurity or IAM-focused role in an enterprise environment. Experience in a manufacturing, healthcare, or regulated environment preferred.
Level Of EducationBachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent experience. IAM or security certification preferred.
TravelUp to 20% as required by the business.
Essential Duties And Responsibilities- Design, implement, and continuously improve Air Life's Identity and Access Management architecture, including full IAM lifecycle management, automated provisioning and deprovisioning workflows, and role-based access control frameworks aligned to least-privilege principles.
- Administer and optimize Microsoft Entra on-premises Active Directory services, including group policy management, directory synchronization, hybrid identity configuration, and identity governance rule maintenance.
- Manage and continuously improve Air Life's Single Sign-On and Multi-Factor Authentication platforms (Cisco Duo, Entra ), ensuring high availability, consistent user experience, and compliance with Air Life's authentication standards.
- Develop and maintain Privileged Access Management (PAM) and Privileged Identity Management (PIM) controls, enforcing least-privilege principles and time-bound access for administrative and privileged accounts across the environment.
- Conduct and coordinate periodic access reviews and certification campaigns to validate…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).