freehire launches on Product Hunt on 26 August.

Follow →

Lead Identity Security Engineer

The Senior Identity Security Engineer is responsible for designing, implementing, and governing enterprise identity and access management capabilities aligned with cybersecurity risk management objectives, the Microsoft Cybersecurity Reference Architecture (MCRA), and Zero Trust principles. The role serves as a senior technical authority for identity security across on-premises, cloud, and hybrid environments, with an initial focus on Microsoft Entra ID and Active Directory. It defines how authentication, authorization, privileged access, identity governance, and identity threat detection capabilities are designed and secured. It partners with Identity Administration, Cybersecurity Operations, infrastructure, application, governance, compliance, and business teams to establish scalable identity services that protect S&C and customer information while supporting reliable business operations.

Hours

  • 8:00 am – 5:00 pm- Remote (Chicago, IL)

Compensation

At S&C, we are dedicated to providing competitive and equitable compensation for all our team members, and we are committed to transparency in our pay practices. The estimated annual base salary range for this position is $128,090 - $169,716.60 Individual pay within this salary range is determined by several compensable factors, including performance, knowledge, job-related skills and experience, and relevant education or training. This role is also eligible for S&C’s annual incentive plan (AIP), subject to eligibility criteria.

Join Our Team as a Lead Identity Security Engineer

Essential Functions:

Identity Strategy, Architecture, and Standards:

  • Define and maintain the identity security strategy, reference architectures, technical standards, and roadmap aligned with MCRA, Zero Trust, cybersecurity risk priorities, and business needs.

  • Design secure, scalable identity and access management solutions across on-premises, cloud, and hybrid environments, with clear separation between governance, engineering, administration, and monitoring responsibilities.
  • Govern the identity architecture and control posture for Microsoft Entra ID, Active Directory, cloud synchronization, and related identity services
  • Architect authentication and authorization capabilities, including SSO, federation, MFA, passwordless authentication, Conditional Access, session controls, and risk-based access.
  • Design privileged access controls, including PIM/PAM, just-in-time access, administrative tiering, emergency access, service-account governance, and least-privilege operating models.
  • Develop role-based and attribute-based access models, segregation-of-duties controls, entitlement standards, and secure access patterns for enterprise applications and platforms.
  • Lead identity lifecycle and governance improvements, including joiner-mover-leaver processes, provisioning and deprovisioning automation, SCIM integrations, access reviews, recertification, guest access, and non-human identity governance.
  • Partner with Identity Administration on implementation and operational execution while maintaining architecture, standards, and control design ownership within Identity Engineering.
  • Participate in security architecture, project, and change reviews to ensure identity security requirements are designed into new applications, platforms, and business processes.
  • Engineer identity threat detection and response enablement, including log architecture, telemetry collection, detection content, analytics, dashboards, and integrations across Defender for Identity, Sentinel, SIEM/SOAR, PAM, and related platforms.
  • Build and tune identity detections and response automation with Cybersecurity Operations, which owns continuous monitoring, investigation, escalation, and incident response.
  • Assess identity risk by analyzing authentication patterns, risky identities, privileged-access exposure, stale or orphaned accounts, control exceptions, and detection coverage; translate findings into practical remediation plans.
  • Define identity metrics, reporting, and evidence standards that demonstrate control effectiveness, governance performance, risk reduction, and roadmap execution for audit, compliance, client assurance, and cyber insurance needs.
  • Evaluate identity and ITDR technologies, lead proofs of concept and vendor assessments, and drive initiatives from strategy through implementation and transition to operations.
  • Develop and maintain architecture diagrams, standards, control designs, implementation guidance, operating procedures, and playbooks; provide technical leadership and mentorship across IT.
  • Protect Firm and client information by complying with information security policies, exercising sound judgment, and promptly reporting security events, control failures, or material risks.

Skills, Knowledge & Experience:

  • 6 to 10 years of progressive experience in identity and access management, identity security engineering, security engineering, or a closely related discipline.

  • Demonstrated experience serving as a senior technical lead for enterprise identity initiatives, including hands-on delivery in complex Microsoft identity environments

  • Deep knowledge of identity security architecture and engineering across Microsoft Entra ID, Active Directory, and hybrid identity environments.

  • Advanced experience with MFA, SSO, federation, Conditional Access, PIM/PAM, RBAC/ABAC, identity lifecycle governance, access reviews, and least-privilege design.

  • Demonstrated ability to design enterprise identity controls while preserving clear boundaries between architecture and governance, platform administration, and security monitoring.

  • Experience engineering identity security telemetry and detection capabilities, including Entra ID and Active Directory logging, Microsoft Defender for Identity, Microsoft Sentinel or comparable SIEM, SOAR automation, and identity analytics.

  • Strong understanding of identity attack paths and common threats, including credential theft, token abuse, privilege escalation, lateral movement, legacy authentication, excessive privilege, and persistence through identity systems.

  • Proficiency with automation and integration technologies such as PowerShell, Python, Microsoft Graph and other APIs, infrastructure-as-code, and structured data formats.

  • Ability to translate cybersecurity risk and technical complexity into clear standards, decisions, roadmaps, and executive-ready communications.

  • Proven ability to lead complex cross-functional initiatives, influence without direct authority, manage competing priorities, and drive issues through resolution.

  • High degree of discretion, integrity, attention to detail, and commitment to client service and professional excellence.

Preferred

  • Experience in a global, highly confidential, regulated, manufacturing, or professional-services environment.

  • Working knowledge of cloud security, networking, PKI and certificates, application architecture, and security operations, supported by strong analytical, troubleshooting, documentation, presentation, and stakeholder-management skills.

  • Microsoft Certified: Identity and Access Administrator Associate (SC-300), Azure Security Engineer Associate, or comparable Microsoft identity certification (within 6 mos)
  • CISSP, CISM, CCSP, or a comparable information security certification

Education:

Required

  • Bachelor’s degree in Cyber Security, Information Systems Management, Computer Science, Computer Engineering, Cloud Security or equivalent experience.

Certifications & Licenses:

Preferred

Advanced certification in a relevant PAM, IGA, ITDR, SIEM/SOAR, or cloud platform is a plus

No fixed deadline

#LI-KD1

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available