Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Brown Advisory

Identity and Access Security Engineer

Brown Advisory

Identity and Access Security Engineer strengthening IAM, PAM, and identity threat controls. Supporting secure access governance at independent investment management firm Brown Advisory.

Posted 8/11/2026full-timeBaltimore • Maryland • 🇺🇸 United StatesMid-LevelSenior💰 $110,000 - $135,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in identity and access management, particularly with Microsoft Entra ID, Active Directory, and CyberArk. Proficient in governing privileged access, conducting access reviews, and remediating identity-related security issues.

Highest-signal resume keywords
Identity GovernanceCyberArk Privileged-Access ManagementMicrosoft Entra ID AdministrationBloodHound Enterprise AnalysisAccess Reviews and Remediation

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Identity Controls EngineeringPrivileged Access ManagementActive Directory SecurityMFA ImplementationSSO IntegrationPowerShell ScriptingREST API AutomationCredential RotationIdentity Lifecycle ManagementAccess Workflow Design
Soft Skills
Strong Communication SkillsCollaboration Across Teams
Tools & Technologies
OktaMicrosoft Entra IDActive DirectoryCyberArkBloodHound EnterpriseSIEM IntegrationMicrosoft 365OAuth 2.0SAMLSCIM
Certifications & Qualifications
CISSPMicrosoft Identity/SecurityCyberArk CertificationOkta Certification
Industry Keywords
Identity and Access ManagementInfrastructure SecurityCloud SecurityRegulated EnvironmentPrivileged Accounts GovernanceService Accounts ManagementAccess CertificationSegregation of DutiesEvidence CollectionControl Reporting

Tech Stack

Tools & technologies
CloudCyber SecurityVault

About the role

Key responsibilities & impact
  • Own day-to-day security governance and engineering of identity controls across Okta, Microsoft Entra ID, Active Directory, MFA, Conditional Access, privileged access, and identity lifecycle workflows
  • Design, implement, operate, and improve CyberArk privileged-access controls, including account discovery, vault onboarding, credential rotation, access workflows, session controls, monitoring, break-glass access, and evidence collection
  • Govern privileged human and non-human identity lifecycles, including administrator accounts, service accounts, application credentials, scheduled-task accounts, emergency accounts, and machine identities
  • Identify unmanaged, misconfigured, inactive, or noncompliant privileged and service accounts and coordinate onboarding, remediation, or retirement
  • Develop and maintain CyberArk safes, platforms, policies, account ownership models, reconciliation processes, permissions, procedures, and recovery documentation
  • Operate BloodHound Enterprise to analyze attack paths, Tier Zero relationships, excessive privilege, nested groups, delegated permissions, and identity weaknesses
  • Translate BloodHound findings into prioritized remediation plans and validate remediation through rescanning, attack-path analysis, ticket evidence, exceptions, and exposure metrics
  • Maintain Tier Zero and critical-identity models across Active Directory, Entra ID, privileged platforms, administrative systems, and infrastructure
  • Assess and improve Active Directory security, including privileged groups, delegated rights, nested groups, service accounts, stale privileges, trusts, and administrative-tier separation
  • Partner with Infrastructure to reduce standing privilege and implement secure administrative patterns
  • Integrate applications with Okta and Entra ID using secure authentication, authorization, SSO, provisioning, deprovisioning, and lifecycle-management patterns
  • Lead access reviews for critical systems, privileged roles, SaaS platforms, and regulated processes
  • Partner with HR, Compliance, Operations, and application owners to improve identity lifecycle workflows
  • Integrate identity telemetry into SIEM and investigation workflows and support investigations into suspicious authentication, credential misuse, privileged activity, role changes, OAuth grants, service-account behavior, and identity-based lateral movement
  • Support SaaS identity, authorization, administrative-role, and data-access controls
  • Define and report identity-security metrics and maintain standards, procedures, evidence, risk documentation, metrics, and leadership reporting
  • Drive remediation of audit findings, penetration-test findings, policy exceptions, BloodHound findings, and access-control gaps
  • Provide guidance on secure identity patterns and support continuous improvement and new technology adoption

Requirements

What you’ll need
  • Bachelor's degree in cybersecurity, computer science, information systems, engineering, or a relevant field, or equivalent professional experience
  • 4–8 years of experience in information security, identity and access management, infrastructure security, cloud security, or related technical work
  • Hands-on experience administering or engineering identity controls in Microsoft Entra ID and Active Directory
  • Experience with Okta or another enterprise identity provider strongly preferred
  • Hands-on experience with a privileged-access management platform; CyberArk experience strongly preferred
  • Experience identifying and remediating Active Directory or cloud identity attack paths using BloodHound Enterprise, BloodHound Community Edition, or a comparable platform
  • Experience governing service accounts, application identities, privileged accounts, secrets, and other non-human identities
  • Experience with access reviews, MFA, SSO, provisioning, deprovisioning, Conditional Access, and identity governance in a regulated environment
  • Experience with PowerShell, Microsoft Graph, REST APIs, or other automation methods
  • Experience working with infrastructure teams to remediate complex privilege relationships without disrupting business-critical systems
  • CISSP, Microsoft identity/security, CyberArk, Okta, or other relevant certifications preferred
  • Knowledge of Okta, Microsoft Entra ID, Active Directory, Microsoft 365, MFA, Conditional Access, SSO, SCIM, SAML, OAuth 2.0, OpenID Connect, lifecycle automation, group governance, enterprise applications, managed identities, and application registrations
  • Knowledge of CyberArk vaulting, safes, platforms, credential rotation, reconciliation, privileged session controls, account discovery, onboarding, access workflows, reporting, service accounts, emergency access, and operational recovery
  • Knowledge of BloodHound Enterprise or comparable attack-path management, Tier Zero analysis, transitive privilege, nested groups, delegated permissions, remediation validation, and exposure metrics
  • Knowledge of identity governance, access certification, role and entitlement governance, segregation of duties, exception handling, contractor/vendor access, evidence collection, and control reporting
  • Knowledge of structured data analysis, identity inventory reconciliation, workflow automation, and integrations with ticketing, SIEM, and reporting platforms
  • Strong communication skills and ability to work across technical teams, business owners, Compliance, HR, and Operations
  • Must be authorized to work in the United States without current or future employer-sponsored work authorization

Benefits

Comp & perks
  • Medical
  • Dental
  • Vision
  • Wellness program participation incentive
  • Financial wellness program
  • Fitness event fee reimbursement
  • Gym membership discounts
  • Colleague Assistance Program
  • Telemedicine Program (for those enrolled in Medical)
  • Adoption Benefits
  • Daycare late pick-up fee reimbursement
  • Basic Life & Accidental Death & Dismemberment Insurance
  • Voluntary Life & Accidental Death & Dismemberment Insurance
  • Short Term Disability
  • Paid parental leave
  • Group Long Term Disability
  • Pet Insurance
  • 401(k) (50% employer match up to IRS limit, 4 year vesting)
  • Bonus eligibility, if applicable
  • Long-term incentive eligibility, if applicable