Identity Security Engineer
Listed on 2026-07-31
-
IT/Tech
Cybersecurity, Information Security & Data Protection
We are seeking an experienced Identity Security Engineer to help design, implement, and mature enterprise identity security capabilities across our organization. This role serves as a technical owner and security steward for key identity functions, including identity governance, provisioning workflows, access control standards, authentication policy, privileged access, and SaaS identity integration patterns.
The ideal candidate is a hands-on technical engineer who can operate at both the architecture and implementation level. This individual should be able to support the implementation and maturity of an Identity Governance and Administration platform, design and validate provisioning workflows, advise on Conditional Access and MFA policies, and help configure or govern privileged access capabilities.
This position requires strong technical judgment, practical implementation skills, and the ability to communicate identity risk, access control requirements, and operational expectations clearly to Security, Helpdesk, Infrastructure, Application Owners, Risk, Compliance, and Audit stakeholders. The successful candidate should be comfortable implementing controls, documenting standards, influencing operational teams, and progressively taking ownership of identity security architecture decisions, design patterns, and roadmap execution.
Key Responsibilities- Support implementation, configuration, and ongoing maturity of Identity Governance and Administration capabilities, including access requests, approvals, birthright access, role-based access, access reviews, certification campaigns, separation of duties, provisioning, deprovisioning, and lifecycle automation.
- Design, review, and validate Conditional Access, sign-in, password, session, and MFA policies across platforms such as Okta, Microsoft Entra , or similar identity providers.
- Support and troubleshoot privileged access management capabilities, including vaulting, credential rotation, privileged account onboarding, session brokering, RDP/SSH access patterns, just-in-time access, and privileged access reviews.
- Partner with Infrastructure and Application teams to onboard applications into provisioning, SSO, MFA, and privileged access processes using approved identity patterns.
- Develop and maintain identity integrations using standards and technologies such as SAML, OIDC/OAuth, SCIM, REST APIs, API authentication methods, webhooks, and automation workflows.
- Review access models, entitlement structures, groups, roles, and permissions to identify excessive access, orphaned access, toxic combinations, and opportunities for simplification.
- Work with Service Now teams to support access request workflows, approval routing, fulfillment tasks, catalog items, and integration between ITSM processes and identity governance capabilities.
- Provide technical oversight and escalation support for identity-related operational processes performed by Helpdesk, Infrastructure, and Application teams, including access fulfillment, application onboarding, MFA, provisioning, and privileged access.
- Collaborate with Risk, Compliance, Audit, and business stakeholders to produce evidence, explain access control designs, remediate findings, and improve control effectiveness.
- Stay current on identity security threats, SaaS identity risks, MFA bypass techniques, privileged access risks, and modern IAM best practices.
- 5+ years of experience in identity and access management, cybersecurity engineering, security operations, infrastructure security, cloud security, or related technical roles.
- Strong understanding of identity security concepts, including authentication, authorization, federation, MFA, access governance, privileged access, least privilege, lifecycle management, and segregation of duties.
- Experience supporting or implementing Identity Governance and Administration capabilities, including access requests, approvals, birthright access, access reviews, certification campaigns, provisioning, deprovisioning, entitlement management, and access reconciliation.
- Experience configuring, reviewing, or monitoring authentication and access enforcement controls, including password policies, sign-in policies, session controls, MFA, Conditional Access, group-based access, and application access controls.
- Familiarity with Privileged Access Management concepts such as credential vaulting, privileged session management, RDP/SSH access, password rotation, service accounts, shared accounts, break-glass access, and just-time access.
- Working knowledge of identity protocols, APIs, and integration patterns, including SAML, OIDC/OAuth, SCIM, LDAP, Kerberos, REST APIs, API authentication, JSON, webhooks, certificates, secrets, tokens, and integration troubleshooting.
- Experience creating or maintaining identity standards, implementation patterns, runbooks, operational procedures, escalation paths, and technical documentation.
- Ability to review identity configurations or access control changes…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).