Cybersecurity Engineer
Listed on 2026-09-13
-
IT/Tech
Cybersecurity
Our core values — Stewardship, Character, Collaborate, Learn, Disrupt — are the lens through which we evaluate every business decision. As a dynamic, growing company that offers extremely competitive compensation and benefits, our employees are our most valued assets and the foundation of Expand's performance among our E&P competitors.
We seek applicants from all backgrounds to ensure we get the best, most creative talent on our team. We realize that, historically, underrepresented groups feel the need to be 100% qualified in order to apply. If you meet any combination of our requirements, we encourage you to apply. We strive to hire people from a wide variety of backgrounds, not just because it’s the right thing to do, but because it makes our company stronger.
Job SummaryThis senior-level cybersecurity engineering position is responsible for designing, implementing, administering, and supporting enterprise identity, directory services, privileged access, and access governance solutions. The role serves as a senior technical contributor below the architect level, translating security architecture and standards into reliable operational capabilities across Active Directory, Okta, SailPoint, Cyber Ark, Quest Active Roles Server, TLS certificate management, and Group Policy.
This position leads complex engineering efforts, supports critical cybersecurity services, mentors less experienced team members, and ensures identity and access platforms remain secure, resilient, auditable, and aligned with business and regulatory requirements.
- Design, implement, administer, and support enterprise identity and access management services, including Active Directory, Okta, SailPoint, Cyber Ark, Quest Active Roles Server, and related integrations
- Serve as a senior technical owner for directory services, authentication, authorization, privileged access, identity governance, and access lifecycle processes
- Implement solution architectures, technical standards, and security patterns defined by cybersecurity architects and leadership
- Maintain and improve Active Directory security, including domain administration, OU structure, delegation models, privileged groups, administrative accounts, and GPO policies
- Administer Quest Active Roles Server capabilities, including delegated administration, workflow support, provisioning controls, and operational automation
- Configure, support, and troubleshoot Okta SSO, MFA, federation, application integrations, authentication policies, and related identity controls
- Support SailPoint identity governance processes, including access requests, access certifications, entitlement ownership, provisioning workflows, and integration health
- Administer Cyber Ark privileged access management capabilities, including vaulted credential onboarding, safe permissions, credential rotation, privileged session controls, and operational support
- Manage and improve enterprise TLS certificate lifecycle processes, including certificate inventory, issuance, renewal coordination, expiration tracking, and remediation of certificate-related risks
- Troubleshoot and resolve complex identity, directory, authentication, authorization, certificate, and privileged access incidents; participate in root-cause analysis and corrective action planning
- Identify and implement automation opportunities using tools such as Power Shell, scripting, APIs, and workflow automation to improve repeatability, control effectiveness, and operational efficiency
- Partner with infrastructure, application, cloud, audit, and business teams to implement secure access patterns and resolve identity-related issues
- Develop and maintain technical documentation, standards, runbooks, recovery procedures, diagrams, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).