Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Security Engineer, Identity & Cloud Controls

Stratos

Lead Security Engineer, Identity & Cloud Controls Location: Beachwood, OH (Hybrid) Reports To: Director of IT We are seeking a highly experienced Lead Security Engineer to serve as the primary technical authority for security engineering, identity governance, and cloud control enforcement across our organization. This is a high-impact, senior role responsible for designing and implementing modern security controls in a cloud-first environment, while working in close partnership with a managed security provider (SEI Sphere) that oversees monitoring and response operations. Position Summary The Lead Security Engineer, Identity & Cloud Controls serves as the organization’s primary technical security authority, responsible for designing, implementing, and governing security controls across identity platforms, cloud services, and enterprise applications. Operating within a co-managed security model alongside SEI Sphere (MSSP), this role focuses on internal control design, enforcement, and integration—ensuring security policies are effectively translated into technical controls that are operational, measurable, and audit-ready. This position plays a critical role in strengthening identity governance, reducing unauthorized application risk, improving access control consistency, and enabling automation across the security ecosystem. Key Responsibilities Identity & Access Management (Primary Focus) Design and implement identity security controls across: Microsoft Entra ID (Azure AD) Okta CyberArk (Privileged Access Management) Develop and Maintain: Role-based access control (RBAC) models Conditional Access policies and MFA strategies Lead implementation and automation of: User lifecycle management (joiner/mover/leaver) Periodic access reviews and certifications Identify and remediate excessive permissions, orphaned accounts, and privilege escalation risks Cloud & Microsoft Security Platform Ownership Configure and optimize: Microsoft Defender (Endpoint, Office 365, Cloud Apps) Microsoft Purview (DLP, sensitivity labeling, data protection controls) Ensure alignment of identity, endpoint, and data protection policies Translate security policies into enforceable technical configurations Application Governance & Shadow IT Control Implement controls to detect and manage unauthorized applications and SaaS usage Govern third-party app access, including OAuth and API integrations Establish application onboarding and risk review processes Reduce shadow IT exposure while balancing business usability Security Automation & Integration Design and implement automated security processes using: PowerShell, Microsoft Graph API, and other automation tools Automate: Access provisioning and deprovisioning Policy enforcement and reporting Integrate security tools to ensure consistent control application across platforms MSSP (SEI Sphere) Integration & Oversight Serve as the primary internal technical liaison with SEI Sphere Ensure proper integration of identity, application, and cloud telemetry into MSSP monitoring Validate detection coverage, escalation processes, and response coordination Identify and remediate gaps between internal controls and MSSP visibility Compliance, Audit & Governance Translate SEC / FINRA regulatory requirements into technical controls Maintain control mappings and generate audit evidence Support internal and external audits, assessments, and regulatory reviews Contribute to vendor due diligence and technical risk evaluations Actively participate in the organization’s GRC Committee Security Architecture & Strategy Serve as the primary internal SME for security engineering and architecture decisions Contribute to long-term security strategy, including identity-first and Zero Trust initiatives Provide recommendations for platform improvements and future-state capabilities Why This Role Matters This role is critical to advancing our security maturity by focusing on what matters most: Identity and access control Application governance Control enforcement and automation Bridging internal security engineering with external security operations You’ll have the opportunity to shape the security architecture, influence strategy, and build scalable solutions that directly reduce risk across the organization. Work Environment Hybrid work model Direct collaboration with IT leadership and cross-functional teams High visibility role with impact across technology, compliance, and operations Required Qualifications 7–10+ years in cybersecurity engineering or architecture roles Deep hands‑on expertise with: Microsoft Entra ID (Azure AD), Conditional Access, identity governance Okta (SSO, federation, lifecycle management) Microsoft Defender suite and security ecosystem Proven experience implementing or managing: Privileged Access Management (CyberArk strongly preferred) Access control models and governance frameworks Strong scripting and automation skills (PowerShell required) Experience integrating security tools and platforms across cloud environments Familiarity with MSSP/SOC operating models Experience in regulated environments (FINRA, SEC, or equivalent) Ability to translate policy and regulatory requirements into technical control implementations Preferred Qualifications Experience with Microsoft Purview (DLP, labeling, insider risk) Experience with Defender for Cloud Apps or CASB technologies Familiarity with API‑based integrations and automation Background in financial services or highly regulated industries #J-18808-Ljbffr Stratos

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Lead Security Engineer, Identity & Cloud Controls in Beachwood, OH vacancy
  • Stratos is seeking a Lead Security Engineer for Identity & Cloud Controls in Beachwood, OH. This senior position involves designing security controls, implementing identity governance, and managing cloud services with a strong focus on automation. The ideal candidate will... 
    Suggested

    Stratos

    Beachwood, OH
    3 days ago
  • $91k - $185.9k

     ...the company’s success. As a Security Specialist within PNC's...  ...Phoenix, AZ. As a Security Engineer on PNC's Cloud Security team, you will build...  ...deploy innovative security controls that protect public cloud...  ...sexual orientation, gender identity, disability, veteran status... 
    Suggested
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office
    Shift work

    PNC

    Cleveland, OH
    3 days ago
  •  ...position for a Platform Engineer, mix between infra and...  ...are working efficiently, securely, and resiliently, supporting both cloud and on-premises systems...  ..., including ingress controllers (e.g., NGINX), TLS certificate...  ...orientation, gender identity, national origin,... 
    Suggested
    Permanent employment
    Relocation

    Apex Systems

    Cleveland, OH
    2 days ago
  •  ...Lead Platform Engineer The Lead Platform Engineer role is responsible...  ...working efficiently, securely, and resiliently. The...  ..., including both cloud and on-premises...  ...runtimes, including ingress controllers (e.g., NGINX), TLS...  ...orientation, gender identity, national origin, protected... 
    Suggested
    Full time
    Contract work
    For contractors
    H1b
    Work at office
    Local area
    Relocation package

    Sherwin-Williams

    Cleveland, OH
    2 days ago
  •  ...Insight Global is seeking a Web Application Security Engineer to support our client’s web application...  ...and optimize web application security controls, including WAF policies and protections...  ...pregnancy), sexual orientation, gender identity and expression, marital status,... 
    Suggested

    Insight Global

    Pepper Pike, OH
    11 hours ago
  • $57.1k - $154.3k

     ...Senior Security Engineer Category: Cyber Security Main location: United States, Pennsylvania, Various Alternate...  ...within the assigned execution crew - reviewing access control, privilege escalation, identity, and container security findings in the vulnerability... 
    Permanent employment
    Full time
    Local area
    Immediate start

    CGI Technologies and Solutions, Inc.

    Cleveland, OH
    5 days ago
  • $96k - $181k

     ...Senior Offensive Security Engineer Location: 4910 Tiedeman...  ...Responsibilities Lead and execute adversary...  ...security assessments across cloud platforms (Google...  ...and network security controls. Employ these tools...  ...sexual orientation, gender identity, national origin, age,... 
    Work experience placement
    Work at office
    Flexible hours

    KeyCorp

    Cleveland, OH
    2 days ago
  • $77.5k - $140.9k

    Ernst & Young Oman is looking for an Application Security Engineer to manage development platforms and enhance application security. You will...  .... Extensive experience in application security tools and cloud infrastructure, especially AWS, is required. The position offers... 

    Ernst & Young Oman

    Cleveland, OH
    4 days ago
  • $100k - $120k

    Tata Consultancy Services Limited is seeking an Application Security Engineer to assist with design, implementation, and support related to application security workflows. This role requires a Bachelor’s degree and 8 to 10 years of relevant experience. The position offers... 

    Tata Consultancy Services

    Cleveland, OH
    3 days ago
  •  ...Our mission is to securely connect the world:...  ...government agencies take control of the cryptographic identities that safeguard...  ...Information Security Engineer Location:...  ...strengtheningsecurity controls, leading incident response...  ...~ Familiarity with cloud security principles... 
    Full time
    Remote work

    Keyfactor

    Independence, OH
    1 day ago
  • $57.1k - $154.3k

     ...Lead Database Engineer Category: Software Development/ Engineering Main location...  ...for information security sign‑off. • Coordinate with...  ...remediation cycle. Access Control and Credential Management •...  ...orientation, gender, gender identity, and gender expression, familial... 
    Permanent employment
    Full time
    Local area

    CGI Technologies and Solutions, Inc.

    Cleveland, OH
    1 day ago
  • The Lead Platform Engineer role is responsible for setting strategic priorities...  ...are working efficiently, securely, and resiliently. The Lead...  ...infrastructure, including both cloud and on-premises systems, in...  ...orientation, gender identity, national origin, protected... 
    Full time
    Contract work
    For contractors
    Local area

    Sherwin-Williams

    Cleveland, OH
    1 day ago
  •  ...Intelligence and Machine Learning. The role demands strong programming skills in Python, experience with ML frameworks, and the ability to lead AI model integrations into production systems. Candidates should possess excellent communication skills to interact with both... 

    Intellisoft Technologies

    Cleveland, OH
    4 days ago
  •  ...DevOps Engineers to support Azure cloud infrastructure, CI/CD pipelines, and a major...  ...and workflows Lead or assist with Bitbucket...  ...and scripting Ensure security, access control, and secrets management...  ...sexual orientation, gender identity and expression, marital... 

    Insight Global

    Beachwood, OH
    5 days ago
  •  ...implement, and maintain network security solutions across enterprise...  ...services. Provide engineering support for Cisco, Arista, Fortinet...  ...platforms. Support cloud security initiatives in Azure...  ...and maintain network security controls. Support incident response... 
    Weekend work

    Neshent Tech

    Cleveland, OH
    2 days ago
  • $92.3k - $166.85k

     ...Description We are seeking a Lead Transmission Line Engineer who will manage a...  ...goals. Drive the quality control process for the execution...  ...details are available at . Securing Your Data Beware of...  ...orientation, gender identity or expression, veteran or... 
    Work at office
    Local area
    Immediate start
    Remote work
    Relocation package
    Flexible hours

    Leidos

    Cleveland, OH
    1 day ago
  •  ...We’re seeking a Lead Cost Engineer to support a major capital power project , owning the full...  ...impact, senior role responsible for cost control, forecasting, and earned value...  ...disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran... 
    For subcontractor
    Work at office
    Local area

    Nexus Engineering Group

    Cleveland, OH
    10 hours ago
  • $92.3k - $166.85k

    Overview Lead Transmission Line Engineer role involves managing a collaborative team within a fast‑paced...  ...to meet growth goals. Drive quality control processes to ensure highest delivery...  ...status, sexual orientation, gender identity or expression, veteran or military status... 
    Remote work
    Relocation package

    Construction Association of Michigan

    Cleveland, OH
    10 hours ago
  • ## Job Description# Lead Platform Engineer· The Senior Platform Engineer role is responsible for designing...  ...the platform are working efficiently, securely, and resiliently. The Senior Platform...  ...'s infrastructure, including both cloud and on-premises systems, in support of... 

    Apex Systems

    Cleveland, OH
    5 days ago
  • The Lead Cost Engineer role is a senior position within the Project Services organization supporting...  ...engineering activities including cost control, forecasting, earned value management,...  ..., sex, sexual orientation, gender identity or expression, age, national origin, veteran... 
    For contractors
    For subcontractor
    Work at office
    Local area

    Nexus Engineering Group Inc

    Cleveland, OH
    3 days ago
  • $57.1k - $154.3k

     ...- Permanent Full Time Title : Lead DevSecOps Engineer Category : Analytics and Emerging...  ...DevSecOps Engineer to champion secure‑by‑design engineering across our cloud and application platforms. You...  ...orientation, gender, gender identity, and gender expression, familial... 
    Permanent employment
    Full time
    Local area
    Shift work

    CGI Njoyn

    Cleveland, OH
    4 days ago
  •  ...WFH. OverDrive is hiring a Security Engineer to help build, tune, and respond...  ...as an incident response lead during security incidents,...  ...the effectiveness of controls within your focus area. Participate...  ...-relevant data sources (cloud, identity, network/security tooling).... 
    Work from home

    OverDrive - Rakuten Group

    Cleveland, OH
    3 days ago
  •  ...services firm is seeking a Senior Manager, Platform Operations Lead Engineer to oversee daily technology platform operations. You will...  ...integration between infrastructure and applications, manage security testing, and coordinate with internal teams and vendors. Candidates... 
    Remote work

    EY

    Cleveland, OH
    4 days ago
  • $140k - $154k

     ...Insight Global is seeking a Lead Performance Reliability Engineer to join their Production Support organization...  ...), sexual orientation, gender identity and expression, marital status, national...  ...environments, especially: Oracle Fusion Cloud (Finance, Supply Chain) Oracle... 

    Insight Global

    Cleveland, OH
    3 days ago
  • $99k - $232k

     ...journey enabled by Oracle Cloud ERP and EPM. You will...  ...packaged solutions leading significant tracks on...  ...importance of a structured, controlled production systems...  ..., and gender identity); age; disability; genetic...  ...thoughtfully to establish a secure and trusted workplace... 
    Full time
    H1b

    PwC

    Cleveland, OH
    1 day ago
  • $170.6k - $390k

     ...career in information security! The...  ...network security controls align with business...  ...across on‑premises, cloud, and hybrid environments...  ...in Cybersecurity Engineering, where you will...  ...of threats while leading cross-departmental...  ...orientation, gender identity/expression, pregnancy... 
    Summer holiday
    Remote work
    Flexible hours

    EY

    Cleveland, OH
    3 days ago
  • Liberty Personnel Services, Inc. is seeking a DevSecOps Engineer in Cleveland to drive a high-priority transformation of their software delivery ecosystem. The role focuses on integrating automated security protocols into development and managing a diverse engineering... 

    Liberty Personnel Services, Inc.

    Cleveland, OH
    10 hours ago
  •  ...mission‑critical programs across national security, defense, and public service delivery....  ...security concepts, including firewalls, access control, and traffic monitoring - Experience or...  ...environments including on-premises and cloud networking - Strong troubleshooting,... 
    Minimum wage
    Full time
    Contract work
    Temporary work
    Work experience placement
    Remote work

    Maximus

    Cleveland, OH
    10 hours ago
  • $67k - $136.8k

     ...As an FSO DevOps Engineer Senior Analyst, you’ll...  ...reliability, observability, and secure deployment patterns....  ...documentation Aligns risk and control processes into day-to-...  ...Strong knowledge of cloud platforms such as Azure...  ...orientation, gender identity/expression, pregnancy,... 
    Summer holiday
    Flexible hours

    EY

    Cleveland, OH
    4 days ago
  • $100k - $172.5k

     ...Technology Enterprise Strategy & Security Job Sub Function:...  ...Principal Product Security Engineer to be located in Danvers, MA...  ...Partner with engineering teams (cloud, console, pump, etc.) to drive...  ..., sexual orientation, gender identity, age, national origin, disability... 
    Full time
    Temporary work
    Work at office
    Local area
    Immediate start
    Remote work
    3 days per week

    Johnson & Johnson

    Cleveland, OH
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Security Engineer, Identity & Cloud Controls. Be the first to apply!