Senior Identity Security Engineer (Arlington, VA or San Diego, CA)
Core
Harden identity security controls and implement a zero-trust, FIDO2 compliant framework to secure access for 8000 employees across a large technical infrastructure.
Role type
Senior Identity Security Engineer
Builds
Zero-trust authentication frameworks, conditional access policies, and AI-assisted security tooling for internal use.
Domain
Cybersecurity / Identity and Access Management (IAM)
Deliverable
production ML models | product features | infrastructure
Required skills
Identity security engineering, IAM tool administration (Okta, PingID, Microsoft Entra ID, Active Directory), authentication protocols (SAML, OAuth, OIDC, Kerberos), PKI, FIDO2, passkeys, SIEM log analysis, scripting (Python, PowerShell, Bash), adversarial attack mitigation (AitM, Evilgnx), attack path management.
Preferred skills
MDM platform experience (Microsoft Intune, Jamf, JumpCloud), identity security testing tools (Bloodhound, AzureHound, SharpHound, Responder), CI/CD infrastructure, risk-based conditional access, workload identity governance, AI/ML-assisted security tooling.
Technologies
Okta, PingID, Microsoft Entra ID, Active Directory, Microsoft Intune, Jamf, JumpCloud, Bloodhound, AzureHound, SharpHound, Responder, Python, PowerShell, Bash, SIEM, FIDO2, OAuth, OIDC, SAML, Kerberos.
Responsibilities
Design and improve identity security controls; develop conditional access policies; analyze logs to guide security rollouts; support phish-resistant authentication rollout; engineer controls for AI and workload identities; research and operationalize AI-assisted tooling; document standards and runbooks; participate in attack path management.
Seniority
Senior, hands-on IC