About the Role
We are looking for a versatile and highly skilled Cyber Security Engineer / IAM Specialist to play a pivotal role in securing our business and IT operations. As we are actively building and maturing our cyber security program, this role offers a unique opportunity to make a foundational impact.
You will serve as our subject matter expert for Identity and Access Management (IAM) and application security, ensuring that all third-party business and IT applications are implemented with a security-first mindset. Because our cyber program is evolving, this is a highly dynamic, cross-functional role. You will have your hands in multiple domains, including security governance, vulnerability management, operational technology (OT) security, and overarching cyber architecture.
Key Responsibilities
- Application Security & Risk Management
- Secure Implementation: Oversee the security architecture and implementation of all third-party IT and business applications (SaaS, COTS, etc.), ensuring they meet organizational security standards.
- Threat Modeling: Conduct comprehensive threat modeling to identify potential vulnerabilities, attack vectors, and design flaws in application deployments.
- Risk Mitigation: Assess risks associated with new and existing applications, providing actionable, secure solutions and compensating controls to business stakeholders.
- Identity & Access Management (IAM)
- Lifecycle Management: Design, deploy, and manage our IAM lifecycle processes, ensuring the principles of least privilege and zero trust are applied across the organization.
- Microsoft Ecosystem Management: Leverage the Microsoft environment (e.g., Entra ID / Azure AD) to configure and enforce Conditional Access policies, MFA, SSO, and Role-Based Access Control (RBAC).
- Access Auditing: Regularly audit identities, roles, and permissions to ensure compliance with internal access policies.
- Cyber Program Development & Engineering
- Vulnerability Management: Assist in building, configuring, and maintaining vulnerability scanning workflows and coordinating remediation efforts across endpoints, servers, and applications.
- Operational Technology (OT) Security: Support the secure design and architecture of our OT environments, bridging the gap between standard IT infrastructure and industrial/operational systems.
- Governance & Compliance: Contribute to the development of foundational cyber security policies, standards, and compliance frameworks.
- General Cyber Support: Act as a flexible security engineering resource, guiding the secure design of various IT projects and initiatives as the overarching security program scales.
Required Qualifications
- Experience: Proven experience as a Cyber Security Engineer, Application Security Specialist, or IAM Engineer.
- Microsoft Environment Expertise: Deep technical understanding of the Microsoft security ecosystem, including Azure, Entra ID (Azure AD), and enterprise Windows environments.
- Threat Modeling Skills: Hands-on experience performing threat modeling and risk assessments for third-party software integrations and business apps.
- IAM Proficiency: Strong foundational knowledge of identity protocols (SAML, OAuth, OIDC) and enterprise identity management.
- Broad Security Knowledge: Working understanding of broader security domains, including vulnerability management, OT/ICS security concepts, and governance frameworks.
- Communication: Excellent ability to translate complex cyber risks into clear, actionable business recommendations for non-technical stakeholders.
Why Join Us?
This is a builder’s role. You will not just be turning the crank on existing processes; you will be instrumental in defining how we approach security across the business. If you enjoy a dynamic environment where you can touch multiple architectural aspects of cyber security, from evaluating a new SaaS application to securing OT networks, we want to hear from you.
