Senior Identity Protection Specialist
Job in
Morrisville, Wake County, North Carolina, 27560, USA
Listed on 2026-08-16
Listing for:
Jobtailor
Full Time
position Listed on 2026-08-16
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description & How to Apply Below
- Lead identity threat monitoring and triage
- Operate and tune Crowd Strike Identity Protection; monitor SIEM/UEBA and identity telemetry for risks
- Validate true/false positives, prioritize by business impact, and elevate per playbooks/SLAs
- Drive rapid containment and remediation
- Execute containment actions (disable accounts, revoke sessions/tokens, isolate hosts)
- Coordinate remediation with IAM/Endpoint/Infrastructure; verify risk reduction to closure
- Own identity-focused incident response
- Ensure evidence handling, root cause analysis, post-incident reviews, and lessons learned
- Engineer detections and hunt for threats
- Build and refine detections and hunts across SIEM/EDR/identity platforms using KQL/SQL/regex/Sigma aligned to MITRE ATT&CK
- Strengthen privileged access controls
- Detect anomalous privileged behavior via SIEM/UEBA and Netskope telemetry
- Recommend/enforce JIT, break-glass patterns, and mover/leaver privilege hygiene with IAM
- Respond to dark web/credential exposure
- Administer platforms and sustain hygiene
- Maintain coverage/health for identity monitoring; manage upgrades and changes via CAB
- Keep operational runbooks, SOPs, and playbooks current
- Automate and orchestrate at scale
- Shape identity policy and controls
- Report outcomes and support audits
- Bachelor’s degree in Cybersecurity, Computer Science, IT, or related field; or equivalent practical experience
- 8+ years in IT/cybersecurity, including 3+ years focused on identity security/operations
- Hands-on enterprise experience administering/operating Crowd Strike Identity Protection
- Proficiency with SIEM/UEBA (Splunk preferred) and cloud security platforms
- Demonstrated experience in identity-centric IR, threat hunting, and detection engineering
- Scripting/automation with Power Shell and Python; experience with REST/Graph/Crowd Strike APIs and SOAR
- Clear communication and documentation skills; comfortable producing executive-ready reports and audit evidence
- Deep knowledge of identity attack paths and protocols.
- Experience with JIT/JEA, PAM concepts, and global on-call rotations
Demonstrates expertise in identity threat monitoring, incident response, and detection engineering, with a strong focus on utilizing Crowd Strike Identity Protection and SIEM/UEBA tools. Proficient in scripting and automation to enhance identity security operations and ensure compliance with policies and controls.
Highest-signal resume keywords- Crowd Strike Identity Protection
- SIEM/UEBA (Splunk Preferred)
- Identity-Centric Incident Response
- Threat Hunting
- Scripting/Automation with Power Shell and Python
- Identity Threat Monitoring
- Incident Response
- Detection Engineering
- Risk Analysis
- Automation
- KQL
- SQL
- Regex
- MITRE ATT&CK
- Privileged Access Management
- Clear Communication
- Documentation Skills
- Identity Security
- Cybersecurity
- Identity Attack Paths
- JIT/JEA
- Global On-Call Rotations
- Crowd Strike APIs
- SOAR
- Netskope Telemetry
- Cloud Security Platforms
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×