About the Role
We are looking for a versatile and highly skilled Cyber Security Engineer / IAM Specialist to play a pivotal role in securing our business and IT operations. As we are actively building and maturing our cyber security program, this role offers a unique opportunity to make a foundational impact.
You will serve as our subject matter expert for Identity and Access Management (IAM) and application security, ensuring that all third-party business and IT applications are implemented with a security-first mindset. Because our cyber program is evolving, this is a highly dynamic, cross-functional role. You will have your hands in multiple domains, including security governance, vulnerability management, operational technology (OT) security, and overarching cyber architecture.
Key Responsibilities
- Application Security & Risk Management
- Secure Implementation: Oversee the security architecture and implementation of all third-party IT and business applications (SaaS, COTS, etc.), ensuring they meet organizational security standards.
- Threat Modeling: Conduct comprehensive threat modeling to identify potential vulnerabilities, attack vectors, and design flaws in application deployments.
- Risk Mitigation: Assess risks associated with new and existing applications, providing actionable, secure solutions and compensating controls to business stakeholders.
- Identity & Access Management (IAM)
- Lifecycle Management: Design, deploy, and manage our IAM lifecycle processes, ensuring the principles of least privilege and zero trust are applied across the organization.
- Microsoft Ecosystem Management: Leverage the Microsoft environment (e.g., Entra ID / Azure AD) to configure and enforce Conditional Access policies, MFA, SSO, and Role-Based Access Control (RBAC).
- Access Auditing: Regularly audit identities, roles, and permissions to ensure compliance with internal access policies.
- Cyber Program Development & Engineering
- Vulnerability Management: Assist in building, configuring, and maintaining vulnerability scanning workflows and coordinating remediation efforts across endpoints, servers, and applications.
- Operational Technology (OT) Security: Support the secure design and architecture of our OT environments, bridging the gap between standard IT infrastructure and industrial/operational systems.
- Governance & Compliance: Contribute to the development of foundational cyber security policies, standards, and compliance frameworks.
- General Cyber Support: Act as a flexible security engineering resource, guiding the secure design of various IT projects and initiatives as the overarching security program scales.
Required Qualifications
- Experience: Proven experience as a Cyber Security Engineer, Application Security Specialist, or IAM Engineer.
- Microsoft Environment Expertise: Deep technical understanding of the Microsoft security ecosystem, including Azure, Entra ID (Azure AD), and enterprise Windows environments.
- Threat Modeling Skills: Hands-on experience performing threat modeling and risk assessments for third-party software integrations and business apps.
- IAM Proficiency: Strong foundational knowledge of identity protocols (SAML, OAuth, OIDC) and enterprise identity management.
- Broad Security Knowledge: Working understanding of broader security domains, including vulnerability management, OT/ICS security concepts, and governance frameworks.
- Communication: Excellent ability to translate complex cyber risks into clear, actionable business recommendations for non-technical stakeholders.
Why Join Us?
This is a builder’s role. You will not just be turning the crank on existing processes; you will be instrumental in defining how we approach security across the business. If you enjoy a dynamic environment where you can touch multiple architectural aspects of cyber security, from evaluating a new SaaS application to securing OT networks, we want to hear from you.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.