Eliassen Group

Identity Security Engineer

Cary, NC • Posted 4 days ago
Hybrid Full Time Business Consulting and Services

Hybrid in Cary, NC, Tues-Thursday


Our client seeks an Identity Security Engineer to strengthen identity security and reduce privileged access risk across cloud, on-premises, and hybrid environments. You will engineer and support IAM and PAM solutions, advance Zero Trust through Zero Standing Privilege and Just-In-Time access, and partner with cross-functional teams to enable secure access to enterprise systems, data, and cloud resources.


This is a full-time, permanent opportunity, offering a competitive salary and comprehensive benefits package. Qualified applicants must be willing and able to work on a w2 basis.


Salary: $111,000 - $116,000/ yr. w2 plus 10% bonus


Responsibilities

  • Design, implement, and support enterprise IAM and PAM solutions across cloud, on-premises, and hybrid environments.
  • Engineer privileged access capabilities including credential vaulting, password rotation, session management, privileged account onboarding, break-glass access, and account lifecycle management.
  • Advance ZSP, JIT access, least privilege, privileged access reduction, and RBAC initiatives.
  • Implement and support Microsoft Entra ID capabilities including Conditional Access, PIM, MFA, Identity Protection, passwordless authentication, and access security controls.
  • Design and support application access management, SSO, federation, and modern authentication integrations using SAML, OAuth 2.0, OIDC, LDAP, and directory services.
  • Secure privileged users, administrative accounts, service accounts, application identities, machine identities, agentic identities, and other non-human identities.
  • Partner with infrastructure, cloud, application, and platform teams to onboard systems, applications, servers, databases, endpoints, and cloud resources into PAM and identity security platforms.
  • Develop and maintain privileged access standards, administrative access models, engineering runbooks, operational procedures, and Zero Trust access control patterns.
  • Automate identity and privileged access processes using PowerShell, Python, REST APIs, workflow orchestration, and platform integrations.
  • Troubleshoot IAM and PAM platform issues, perform root cause analysis, and implement corrective actions to improve reliability and operational stability.
  • Collaborate with Security Operations to investigate identity-related incidents, privileged access risks, control gaps, and suspicious activity involving high-risk identities.
  • Communicate identity security risks, technical recommendations, and remediation plans to cross-functional teams, senior management, and business stakeholders.
  • Other duties as assigned.


Experience Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent combination of education and experience.
  • 3+ years of experience designing, implementing, and supporting IAM, PAM, and identity security solutions in large enterprise environments.
  • 2+ years of hands-on administration with CyberArk Privilege Cloud, CyberArk PAM, Delinea, BeyondTrust, or comparable PAM platforms.
  • Demonstrated ability to own and improve ZSP, JIT access, least privilege, RBAC, break-glass access, and privileged access reduction capabilities.
  • Strong working knowledge of Microsoft Entra ID, Conditional Access, PIM, MFA, Identity Protection, directory services, and modern authentication controls.
  • Understanding of SSO, federation, authentication, and authorization technologies such as SAML, OAuth 2.0, OIDC, LDAP, Active Directory, and cloud identity platforms.
  • Capability to deliver automation or integration using PowerShell, Python, REST APIs, or workflow automation is preferred.
  • Proven ability to assess identity security risks, identify control gaps, recommend remediation, and communicate with technical and non-technical stakeholders.
  • Strong judgment, ownership, urgency, customer focus, integrity, and ability to prioritize in a fast-paced environment.
  • Approximately 5% travel may be required.


Education Requirements

Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent experience.

Identity Security Engineer in Cary at Eliassen Group

This position is listed as full time and hybrid. It was posted 4 days ago.

See all Eliassen Group jobs on LocalWork →

Back to Job Search