The Senior Identity Security Engineer is responsible for designing, implementing, and governing enterprise identity and access management capabilities aligned with cybersecurity risk management objectives, the Microsoft Cybersecurity Reference Architecture (MCRA), and Zero Trust principles. The role serves as a senior technical authority for identity security across on-premises, cloud, and hybrid environments, with an initial focus on Microsoft Entra ID and Active Directory. It defines how authentication, authorization, privileged access, identity governance, and identity threat detection capabilities are designed and secured. It partners with Identity Administration, Cybersecurity Operations, infrastructure, application, governance, compliance, and business teams to establish scalable identity services that protect S&C and customer information while supporting reliable business operations.
Hours
Compensation
At S&C, we are dedicated to providing competitive and equitable compensation for all our team members, and we are committed to transparency in our pay practices. The estimated annual base salary range for this position is $128,090 - $169,716.60 Individual pay within this salary range is determined by several compensable factors, including performance, knowledge, job-related skills and experience, and relevant education or training. This role is also eligible for S&C’s annual incentive plan (AIP), subject to eligibility criteria.
Join Our Team as a Lead Identity Security Engineer
Essential Functions:
Identity Strategy, Architecture, and Standards:
Define and maintain the identity security strategy, reference architectures, technical standards, and roadmap aligned with MCRA, Zero Trust, cybersecurity risk priorities, and business needs.
Skills, Knowledge & Experience:
6 to 10 years of progressive experience in identity and access management, identity security engineering, security engineering, or a closely related discipline.
Demonstrated experience serving as a senior technical lead for enterprise identity initiatives, including hands-on delivery in complex Microsoft identity environments
Deep knowledge of identity security architecture and engineering across Microsoft Entra ID, Active Directory, and hybrid identity environments.
Advanced experience with MFA, SSO, federation, Conditional Access, PIM/PAM, RBAC/ABAC, identity lifecycle governance, access reviews, and least-privilege design.
Demonstrated ability to design enterprise identity controls while preserving clear boundaries between architecture and governance, platform administration, and security monitoring.
Experience engineering identity security telemetry and detection capabilities, including Entra ID and Active Directory logging, Microsoft Defender for Identity, Microsoft Sentinel or comparable SIEM, SOAR automation, and identity analytics.
Strong understanding of identity attack paths and common threats, including credential theft, token abuse, privilege escalation, lateral movement, legacy authentication, excessive privilege, and persistence through identity systems.
Proficiency with automation and integration technologies such as PowerShell, Python, Microsoft Graph and other APIs, infrastructure-as-code, and structured data formats.
Ability to translate cybersecurity risk and technical complexity into clear standards, decisions, roadmaps, and executive-ready communications.
Proven ability to lead complex cross-functional initiatives, influence without direct authority, manage competing priorities, and drive issues through resolution.
High degree of discretion, integrity, attention to detail, and commitment to client service and professional excellence.
Preferred
Experience in a global, highly confidential, regulated, manufacturing, or professional-services environment.
Working knowledge of cloud security, networking, PKI and certificates, application architecture, and security operations, supported by strong analytical, troubleshooting, documentation, presentation, and stakeholder-management skills.
Education:
Required
Certifications & Licenses:
Preferred
Advanced certification in a relevant PAM, IGA, ITDR, SIEM/SOAR, or cloud platform is a plus
No fixed deadline
#LI-KD1