Lead Security Engineer, Identity & Cloud Controls
Stratos
Lead Security Engineer, Identity & Cloud Controls Location: Beachwood, OH (Hybrid) Reports To: Director of IT We are seeking a highly experienced Lead Security Engineer to serve as the primary technical authority for security engineering, identity governance, and cloud control enforcement across our organization. This is a high-impact, senior role responsible for designing and implementing modern security controls in a cloud-first environment, while working in close partnership with a managed security provider (SEI Sphere) that oversees monitoring and response operations. Position Summary The Lead Security Engineer, Identity & Cloud Controls serves as the organization’s primary technical security authority, responsible for designing, implementing, and governing security controls across identity platforms, cloud services, and enterprise applications. Operating within a co-managed security model alongside SEI Sphere (MSSP), this role focuses on internal control design, enforcement, and integration—ensuring security policies are effectively translated into technical controls that are operational, measurable, and audit-ready. This position plays a critical role in strengthening identity governance, reducing unauthorized application risk, improving access control consistency, and enabling automation across the security ecosystem. Key Responsibilities Identity & Access Management (Primary Focus) Design and implement identity security controls across: Microsoft Entra ID (Azure AD) Okta CyberArk (Privileged Access Management) Develop and Maintain: Role-based access control (RBAC) models Conditional Access policies and MFA strategies Lead implementation and automation of: User lifecycle management (joiner/mover/leaver) Periodic access reviews and certifications Identify and remediate excessive permissions, orphaned accounts, and privilege escalation risks Cloud & Microsoft Security Platform Ownership Configure and optimize: Microsoft Defender (Endpoint, Office 365, Cloud Apps) Microsoft Purview (DLP, sensitivity labeling, data protection controls) Ensure alignment of identity, endpoint, and data protection policies Translate security policies into enforceable technical configurations Application Governance & Shadow IT Control Implement controls to detect and manage unauthorized applications and SaaS usage Govern third-party app access, including OAuth and API integrations Establish application onboarding and risk review processes Reduce shadow IT exposure while balancing business usability Security Automation & Integration Design and implement automated security processes using: PowerShell, Microsoft Graph API, and other automation tools Automate: Access provisioning and deprovisioning Policy enforcement and reporting Integrate security tools to ensure consistent control application across platforms MSSP (SEI Sphere) Integration & Oversight Serve as the primary internal technical liaison with SEI Sphere Ensure proper integration of identity, application, and cloud telemetry into MSSP monitoring Validate detection coverage, escalation processes, and response coordination Identify and remediate gaps between internal controls and MSSP visibility Compliance, Audit & Governance Translate SEC / FINRA regulatory requirements into technical controls Maintain control mappings and generate audit evidence Support internal and external audits, assessments, and regulatory reviews Contribute to vendor due diligence and technical risk evaluations Actively participate in the organization’s GRC Committee Security Architecture & Strategy Serve as the primary internal SME for security engineering and architecture decisions Contribute to long-term security strategy, including identity-first and Zero Trust initiatives Provide recommendations for platform improvements and future-state capabilities Why This Role Matters This role is critical to advancing our security maturity by focusing on what matters most: Identity and access control Application governance Control enforcement and automation Bridging internal security engineering with external security operations You’ll have the opportunity to shape the security architecture, influence strategy, and build scalable solutions that directly reduce risk across the organization. Work Environment Hybrid work model Direct collaboration with IT leadership and cross-functional teams High visibility role with impact across technology, compliance, and operations Required Qualifications 7–10+ years in cybersecurity engineering or architecture roles Deep hands‑on expertise with: Microsoft Entra ID (Azure AD), Conditional Access, identity governance Okta (SSO, federation, lifecycle management) Microsoft Defender suite and security ecosystem Proven experience implementing or managing: Privileged Access Management (CyberArk strongly preferred) Access control models and governance frameworks Strong scripting and automation skills (PowerShell required) Experience integrating security tools and platforms across cloud environments Familiarity with MSSP/SOC operating models Experience in regulated environments (FINRA, SEC, or equivalent) Ability to translate policy and regulatory requirements into technical control implementations Preferred Qualifications Experience with Microsoft Purview (DLP, labeling, insider risk) Experience with Defender for Cloud Apps or CASB technologies Familiarity with API‑based integrations and automation Background in financial services or highly regulated industries #J-18808-Ljbffr Stratos
- Stratos is seeking a Lead Security Engineer for Identity & Cloud Controls in Beachwood, OH. This senior position involves designing security controls, implementing identity governance, and managing cloud services with a strong focus on automation. The ideal candidate will...Suggested
$91k - $185.9k
...the company’s success. As a Security Specialist within PNC's... ...Phoenix, AZ. As a Security Engineer on PNC's Cloud Security team, you will build... ...deploy innovative security controls that protect public cloud... ...sexual orientation, gender identity, disability, veteran status...SuggestedFull timeTemporary workPart timeWork experience placementWork at officeShift work- ...position for a Platform Engineer, mix between infra and... ...are working efficiently, securely, and resiliently, supporting both cloud and on-premises systems... ..., including ingress controllers (e.g., NGINX), TLS certificate... ...orientation, gender identity, national origin,...SuggestedPermanent employmentRelocation
- ...Lead Platform Engineer The Lead Platform Engineer role is responsible... ...working efficiently, securely, and resiliently. The... ..., including both cloud and on-premises... ...runtimes, including ingress controllers (e.g., NGINX), TLS... ...orientation, gender identity, national origin, protected...SuggestedFull timeContract workFor contractorsH1bWork at officeLocal areaRelocation package
- ...Insight Global is seeking a Web Application Security Engineer to support our client’s web application... ...and optimize web application security controls, including WAF policies and protections... ...pregnancy), sexual orientation, gender identity and expression, marital status,...Suggested
$57.1k - $154.3k
...Senior Security Engineer Category: Cyber Security Main location: United States, Pennsylvania, Various Alternate... ...within the assigned execution crew - reviewing access control, privilege escalation, identity, and container security findings in the vulnerability...Permanent employmentFull timeLocal areaImmediate start$96k - $181k
...Senior Offensive Security Engineer Location: 4910 Tiedeman... ...Responsibilities Lead and execute adversary... ...security assessments across cloud platforms (Google... ...and network security controls. Employ these tools... ...sexual orientation, gender identity, national origin, age,...Work experience placementWork at officeFlexible hours$77.5k - $140.9k
Ernst & Young Oman is looking for an Application Security Engineer to manage development platforms and enhance application security. You will... .... Extensive experience in application security tools and cloud infrastructure, especially AWS, is required. The position offers...$100k - $120k
Tata Consultancy Services Limited is seeking an Application Security Engineer to assist with design, implementation, and support related to application security workflows. This role requires a Bachelor’s degree and 8 to 10 years of relevant experience. The position offers...- ...Our mission is to securely connect the world:... ...government agencies take control of the cryptographic identities that safeguard... ...Information Security Engineer Location:... ...strengtheningsecurity controls, leading incident response... ...~ Familiarity with cloud security principles...Full timeRemote work
$57.1k - $154.3k
...Lead Database Engineer Category: Software Development/ Engineering Main location... ...for information security sign‑off. • Coordinate with... ...remediation cycle. Access Control and Credential Management •... ...orientation, gender, gender identity, and gender expression, familial...Permanent employmentFull timeLocal area- The Lead Platform Engineer role is responsible for setting strategic priorities... ...are working efficiently, securely, and resiliently. The Lead... ...infrastructure, including both cloud and on-premises systems, in... ...orientation, gender identity, national origin, protected...Full timeContract workFor contractorsLocal area
- ...Intelligence and Machine Learning. The role demands strong programming skills in Python, experience with ML frameworks, and the ability to lead AI model integrations into production systems. Candidates should possess excellent communication skills to interact with both...
- ...DevOps Engineers to support Azure cloud infrastructure, CI/CD pipelines, and a major... ...and workflows Lead or assist with Bitbucket... ...and scripting Ensure security, access control, and secrets management... ...sexual orientation, gender identity and expression, marital...
- ...implement, and maintain network security solutions across enterprise... ...services. Provide engineering support for Cisco, Arista, Fortinet... ...platforms. Support cloud security initiatives in Azure... ...and maintain network security controls. Support incident response...Weekend work
$92.3k - $166.85k
...Description We are seeking a Lead Transmission Line Engineer who will manage a... ...goals. Drive the quality control process for the execution... ...details are available at . Securing Your Data Beware of... ...orientation, gender identity or expression, veteran or...Work at officeLocal areaImmediate startRemote workRelocation packageFlexible hours- ...We’re seeking a Lead Cost Engineer to support a major capital power project , owning the full... ...impact, senior role responsible for cost control, forecasting, and earned value... ...disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran...For subcontractorWork at officeLocal area
$92.3k - $166.85k
Overview Lead Transmission Line Engineer role involves managing a collaborative team within a fast‑paced... ...to meet growth goals. Drive quality control processes to ensure highest delivery... ...status, sexual orientation, gender identity or expression, veteran or military status...Remote workRelocation package- ## Job Description# Lead Platform Engineer· The Senior Platform Engineer role is responsible for designing... ...the platform are working efficiently, securely, and resiliently. The Senior Platform... ...'s infrastructure, including both cloud and on-premises systems, in support of...
- The Lead Cost Engineer role is a senior position within the Project Services organization supporting... ...engineering activities including cost control, forecasting, earned value management,... ..., sex, sexual orientation, gender identity or expression, age, national origin, veteran...For contractorsFor subcontractorWork at officeLocal area
$57.1k - $154.3k
...- Permanent Full Time Title : Lead DevSecOps Engineer Category : Analytics and Emerging... ...DevSecOps Engineer to champion secure‑by‑design engineering across our cloud and application platforms. You... ...orientation, gender, gender identity, and gender expression, familial...Permanent employmentFull timeLocal areaShift work- ...WFH. OverDrive is hiring a Security Engineer to help build, tune, and respond... ...as an incident response lead during security incidents,... ...the effectiveness of controls within your focus area. Participate... ...-relevant data sources (cloud, identity, network/security tooling)....Work from home
- ...services firm is seeking a Senior Manager, Platform Operations Lead Engineer to oversee daily technology platform operations. You will... ...integration between infrastructure and applications, manage security testing, and coordinate with internal teams and vendors. Candidates...Remote work
$140k - $154k
...Insight Global is seeking a Lead Performance Reliability Engineer to join their Production Support organization... ...), sexual orientation, gender identity and expression, marital status, national... ...environments, especially: Oracle Fusion Cloud (Finance, Supply Chain) Oracle...$99k - $232k
...journey enabled by Oracle Cloud ERP and EPM. You will... ...packaged solutions leading significant tracks on... ...importance of a structured, controlled production systems... ..., and gender identity); age; disability; genetic... ...thoughtfully to establish a secure and trusted workplace...Full timeH1b$170.6k - $390k
...career in information security! The... ...network security controls align with business... ...across on‑premises, cloud, and hybrid environments... ...in Cybersecurity Engineering, where you will... ...of threats while leading cross-departmental... ...orientation, gender identity/expression, pregnancy...Summer holidayRemote workFlexible hours- Liberty Personnel Services, Inc. is seeking a DevSecOps Engineer in Cleveland to drive a high-priority transformation of their software delivery ecosystem. The role focuses on integrating automated security protocols into development and managing a diverse engineering...
- ...mission‑critical programs across national security, defense, and public service delivery.... ...security concepts, including firewalls, access control, and traffic monitoring - Experience or... ...environments including on-premises and cloud networking - Strong troubleshooting,...Minimum wageFull timeContract workTemporary workWork experience placementRemote work
$67k - $136.8k
...As an FSO DevOps Engineer Senior Analyst, you’ll... ...reliability, observability, and secure deployment patterns.... ...documentation Aligns risk and control processes into day-to-... ...Strong knowledge of cloud platforms such as Azure... ...orientation, gender identity/expression, pregnancy,...Summer holidayFlexible hours$100k - $172.5k
...Technology Enterprise Strategy & Security Job Sub Function:... ...Principal Product Security Engineer to be located in Danvers, MA... ...Partner with engineering teams (cloud, console, pump, etc.) to drive... ..., sexual orientation, gender identity, age, national origin, disability...Full timeTemporary workWork at officeLocal areaImmediate startRemote work3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Security Engineer, Identity & Cloud Controls. Be the first to apply!



