Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Identity and Access Security Engineer

$110k - $135k

Brown Advisory

Company OverviewEvery firm has a culture – the values, beliefs, methodology, attitudes and standards that reflect an organization’s DNA. But the truly inspiring firms – the game-changers, the industry leaders and the disruptors – have cultures that propel them to innovate and stand out. At Brown Advisory, we aim to be one of those inspired firms. Over the years, we have purposefully built and nurtured our client-first culture.Brown Advisory is an independent investment management and strategic advisory firm committed to delivering a combination of first-class performance, strategic advice and the highest level of client service. The firm’s clients—including individuals, families, family offices, endowments, foundations, charities, institutions, consultants, and financial intermediaries—are served by over 1,000 colleagues worldwide, all of whom are equity owners of the firm.Brown Advisory is currently seeking an Identity and Access Security Engineer to lead and mature the firm's identity security controls across Okta, Microsoft Entra ID, Active Directory, CyberArk, BloodHound Enterprise, multifactor authentication, privileged access, application integrations, and access governance. This blended role is designed for a hands-on security professional who understands identity as both a business-enablement workflow and a critical security control plane.The engineer will be responsible for reducing identity-related risk across workforce, privileged, service, application, and machine identities. The role combines identity engineering, privileged-access management, identity threat exposure management, access governance, attack-path remediation, and operational control assurance.As part of a lean Information Security team within a mid-sized financial services organization, this individual will partner with Infrastructure, Enterprise Applications, Compliance, Human Resources, Operations, and business system owners. The role will help ensure that access is appropriately granted, reviewed, monitored, and removed while enabling secure adoption of SaaS, cloud, and on-premises platforms.Blended Role CoveragePrimary emphasis: Identity security engineering and governance across IAM, PAM, identity threat exposure management, MFA, privileged access, access reviews, and identity-related risk.Blended coverage: Okta and Entra ID integration, CyberArk platform operations and privileged-account onboarding, service-account governance, BloodHound Enterprise analysis and attack-path remediation, Active Directory privilege hygiene, SaaS access controls, identity lifecycle automation, and selected security-engineering support.Duties and ResponsibilitiesOwn the day-to-day security governance and engineering of identity controls across Okta, Microsoft Entra ID, Active Directory, MFA, Conditional Access, privileged access, and identity lifecycle workflows.Design, implement, operate, and continuously improve privileged-access controls using CyberArk, including account discovery, vault onboarding, credential rotation, access workflows, session controls, privileged-account monitoring, break-glass access, and evidence collection.Govern the lifecycle of privileged human and non-human identities, including administrator accounts, service accounts, application credentials, scheduled-task accounts, emergency accounts, and other machine identities.Identify privileged and service accounts that are unmanaged, improperly configured, inactive, or outside established CyberArk controls, and coordinate their onboarding, remediation, or retirement.Develop and maintain CyberArk safes, platforms, policies, account ownership models, reconciliation processes, access permissions, operational procedures, and recovery documentation.Operate BloodHound Enterprise as an identity threat exposure management capability, analyzing attack paths, Tier Zero relationships, excessive privilege, nested group membership, delegated permissions, and other identity-control weaknesses.Translate BloodHound findings into prioritized and actionable remediation plans, working with Infrastructure and application owners to remove unnecessary privilege while preserving required business and system functionality.Validate identity-risk remediation through rescanning, attack-path analysis, ticket evidence, exception documentation, and measurable reduction in identity exposure.Maintain a defined Tier Zero and critical-identity model across Active Directory, Entra ID, privileged platforms, administrative systems, and supporting infrastructure.Assess and improve Active Directory security, including privileged groups, delegated administrative rights, nested group relationships, service accounts, stale privileges, domain and forest trust exposure, and administrative-tier separation.Partner with Infrastructure to reduce standing privilege and implement secure administrative patterns for domain, server, workstation, application, and help-desk administration.Integrate applications with Okta and Entra ID using secure authentication, authorization, SSO, provisioning, deprovisioning, and lifecycle-management patterns.Lead access review routines for critical systems, privileged roles, SaaS platforms, and regulated business processes, ensuring exceptions are documented and remediated.Partner with HR, Compliance, Operations, and application owners to improve joiner, mover, leaver, contractor, vendor, service-account, and application-identity workflows.Strengthen identity detection and response by integrating telemetry from Okta, Entra ID, Active Directory, CyberArk, BloodHound Enterprise, and other identity systems into SIEM and investigation workflows.Support investigations involving suspicious authentication, credential misuse, privileged-account activity, unauthorized role changes, risky OAuth grants, anomalous service-account behavior, and potential identity-based lateral movement.Support security configuration for SaaS applications where identity, authorization, administrative roles, and data-access controls are central to risk management.Define and report identity-security metrics, including privileged-account coverage, service-account onboarding, password-rotation compliance, standing privileged access, attack-path exposure, Tier Zero findings, stale access, review completion, and remediation aging.Maintain identity standards, procedures, control evidence, risk documentation, metrics, and leadership reporting in partnership with GRC.Drive remediation of identity-related audit findings, penetration-test findings, policy exceptions, BloodHound findings, and access-control gaps.Provide practical guidance to application, infrastructure, and business teams on secure identity patterns that meet control requirements without slowing delivery unnecessarily.Preferred QualificationsBachelor's degree in cyber security, computer science, information systems, engineering, or a relevant field, or equivalent professional experience.4-8 years of experience in information security, identity and access management, infrastructure security, cloud security, or related technical work.Hands-on experience administering or engineering identity controls in Microsoft Entra ID and Active Directory; experience with Okta or another enterprise identity provider strongly preferred.Hands-on experience with a privileged-access management platform; CyberArk administration or engineering experience strongly preferred.Experience identifying and remediating Active Directory or cloud identity attack paths using BloodHound Enterprise, BloodHound Community Edition, or a comparable identity threat exposure management platform.Demonstrated experience governing service accounts, application identities, privileged accounts, secrets, and other non-human identities.Experience with access reviews, MFA, SSO, provisioning, deprovisioning, Conditional Access, and identity governance in a regulated environment.Experience with PowerShell, Microsoft Graph, REST APIs, or other automation methods used to analyze identity data and automate control workflows.Experience working with infrastructure teams to remediate complex privilege relationships without disrupting business-critical systems.CISSP, Microsoft identity/security certifications, CyberArk certifications, Okta certifications, or other relevant professional designations preferred.Technical SkillsIdentity platforms and protocols: Okta, Microsoft Entra ID, Active Directory, Microsoft 365, MFA, Conditional Access, SSO, SCIM, SAML, OAuth 2.0, OpenID Connect, lifecycle automation, group governance, enterprise applications, managed identities, and application registrations.Privileged-access management: CyberArk administration and engineering, including vaulting, safes, platforms, credential rotation, reconciliation, privileged session controls, account discovery, onboarding, access workflows, reporting, service accounts, emergency access, and operational recovery.Identity threat exposure management: BloodHound Enterprise or comparable attack-path management platforms; Tier Zero analysis; transitive privilege; nested group analysis; delegated permissions; attack-path prioritization; Active Directory privilege hygiene; remediation validation; and exposure metrics.Identity governance: Joiner, mover, leaver workflows; access certification; role and entitlement governance; segregation of duties; exception handling; contractor and vendor access; evidence collection; and control reporting.Automation and analysis: PowerShell, Microsoft Graph, REST APIs, structured data analysis, identity inventory reconciliation, workflow automation, and integration with ticketing, SIEM, and reporting platforms.Identity detection and response: Analysis of authentication, privilege, administrative, and access telemetry from Okta, Entra ID, Active Directory, CyberArk, SaaS platforms, and related identity systems.SaaS access-control models for platforms such as Microsoft 365, Salesforce, Box, and other business-critical applications.Strong communication skills and comfort working across technical teams, business owners, Compliance, HR, and Operations.Demonstrates curiosity and a continuous improvement mindset by identifying opportunities to enhance processes, improve efficiency, and thoughtfully leverage new technologies and tools, including AI-enabled productivity solutionsPersonal AttributesTake ownership and move initiatives forward without constant oversight.Balance technical depth, process discipline, and sound business judgment.Approach risk management pragmatically rather than theoretically.Demonstrate sufficient technical judgment to distinguish an exploitable identity path from a theoretical configuration concern.Work carefully through complex privilege remediation where seemingly minor changes may affect applications, service accounts, administrative workflows, or production systems.Thrive in collaborative, high-accountability environments.Communicate clearly with technical and non-technical colleagues.Bring an entrepreneurial mindset to building and improving security capabilities.Applicants must be authorized to work in the United States without the need for current or future employer-sponsored work authorization (e.g., H-1B , O-1, F-1 (OPT), TN, or any other non-immigrant visa classifications that require employer support or sponsorship).MD Salary: $110-$135k. Commensurate with experience and location. Does not include bonus or long term incentive eligibility (if applicable).DC Salary: $121K–$148.5K. Commensurate with experience and location. Does not include bonus or long-term incentive eligibility (if applicable).BenefitsAt Brown Advisory we offer a competitive compensation package, including full benefits.• Medical• Dental• Vision• Wellness program participation incentive• Financial wellness program• Fitness event fee reimbursement• Gym membership discounts• Colleague Assistance Program• Telemedicine Program (for those enrolled in Medical)• Adoption Benefits• Daycare late pick-up fee reimbursement• Basic Life & Accidental Death & Dismemberment Insurance• Voluntary Life & Accidental Death & Dismemberment Insurance• Short Term Disability• Paid parental leave• Group Long Term Disability• Pet Insurance• 401(k) (50% employer match up to IRS limit, 4 year vesting)Brown Advisory is an Equal Employment Opportunity Employer.SummaryLocation: Baltimore, MD; Washington D.C.Type: Full time

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Identity and Access Security Engineer in Washington DC vacancy
  • $63.91 - $108.82 per hour

    Senior Security Engineer IS - Identity & Access ManagementWe are seeking a highly motivated Senior Security Engineer with a strong passion for Identity and Access Management (IAM) to join our Enterprise Security & Infrastructure (ESI) organization.The ideal candidate brings... 
    Suggested
    Minimum wage
    Local area
    Remote work
    Shift work
    Weekend work

    Providence Health & Services

    Washington DC
    14 days ago
  • $191k - $297k

     ...to be considered for this position.We are seeking an accomplished Principal Security Engineer to serve within Nordstrom's Cybersecurity & Privacy Organization (CPO), focused on Identity & Access Management (IAM). This role will drive the architecture, strategy, and... 
    Suggested
    Full time
    Work at office

    Nordstrom

    Washington DC
    5 days ago
  • $120k - $130k

    Job DescriptionEverforth ECS is seeking an Identity Security Engineer to work in our Washington, DC office / remote. The role is contingent upon...  ...RequirementsIdentity SecurityDeep understanding of enterprise identity and access management (IAM) architecture, governance, and security... 
    Suggested
    Work at office
    Remote work

    ECS Federal

    Washington DC
    a month ago
  •  ...development, infrastructure, Cyber security, and enterprise content/data...  ...3"Job DescriptionJob Title: Identity and Authentication Security...  ...and Authentication Security Engineer/Admin will be responsible for...  .../patterns that allow secure access across district programs and... 
    Suggested
    Remote work

    Comtech

    Washington DC
    a month ago
  •  ...and have the flexibility and access to constantly find new areas...  ...deployment, and management of Identity, Credentialing, and Access Management...  ...e.g. NIST, FICAM, HSPD-12) Engineer and manage the full lifecycle...  ...(PAM) initiatives, securing and monitoring access for high... 
    Suggested
    Full time
    Local area

    KPMG

    Washington DC
    a month ago
  • GEICO seeks a Staff Engineer to innovate and build security systems focusing on identity and access management. You will lead the technical roadmap for secure authentication across the organization, collaborating with peers and stakeholders to deliver robust IAM solutions... 

    GEICO

    Bethesda, MD
    6 days ago
  • ICAM Engineer Identity, Credential, and Access Management This position is 100% Onsite. This position is in Arlington, VA, with occasional/situational travel...  ...Top Secret Engineering & Deployment: Engineer, deploy, secure, and maintain complex, mission-critical identity... 

    RMantra Solutions

    Alexandria, VA
    2 days ago
  • $82.6k - $162.8k

     ...confidence, and proactively manage to secure success.Recruiting for this role ends on...  ...12/31/2026.Work you'll doAs a Security Engineer on the Deloitte Cyber team, you will be...  ...design and implementation of Customer Identity and Access Management (CIAM) solutions aligned to... 
    Local area
    Visa sponsorship

    Deloitte

    Washington DC
    a month ago
  • A leading cybersecurity firm is seeking an Identity, Credential and Access Management Systems Engineer in Arlington, VA. The ideal candidate will have a TS/SCI clearance, a background in information technology, and experience with ForgeRock. Responsibilities include deploying... 
    Full time

    TDI (Tetrad Digital Integrity)

    Arlington, VA
    3 days ago
  • Lead Identity and Access Management (IAM) Engineer Job ID 25287 Location Toll Brothers - Fort Washington, Pennsylvania 19034 United States Category Information...  ...assists with identity architecture, automation, and security operations initiatives to ensure secure, scalable... 
    Full time
    Work at office
    Local area

    Toll Brothers

    Fort Washington, MD
    2 days ago
  • $98.4k - $160k

     ...impact. Join us!Job Description:The Network Security Engineer is responsible for supporting multiple...  ...Strategy DevelopmentAccess and Identity ManagementCritical ThinkingCyber SecurityInformation...  ...We provide industry-leading benefits, access to paid time off, resources and support... 
    Full time
    Work at office
    Flexible hours
    Shift work
    Day shift

    Bank of America

    Washington DC
    1 day ago
  • $77.6k - $176k

     ...experience with enterprise remote access, VPN, or Zero Trust...  ...SASE platforms and cloud-based security services ~ Proficiency in networking...  ..., firewall policies, and identity-based access controls ~...  ...under the guidance of senior engineers Resolve technical issues while... 
    Full time
    Remote work

    Booz Allen Hamilton

    McLean, VA
    3 days ago
  • $135k - $200k

    Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir...  ..., and more.The Role As a Senior Identity Security Engineer on Palantir's Identity Security team,...  ...security at Palantir, reduce standing access, lead identity threat modeling, and contribute... 
    Full time
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package
    Shift work

    Palantir Technologies

    Washington DC
    7 hours ago
  • $165k - $215k

     ...Siemens, and Verizon to name a few. The RoleJoin a small, high impact engineering team building the core Identity and Access Management platform that powers authentication, authorization, and security across our entire product surface. We design and operate the services... 
    Full time
    Work at office
    Flexible hours
    Night shift

    Outreach

    Washington DC
    a month ago
  • $175.1k - $236.9k

     ...cooling equipment that ensure our customers have continual access to the innovation they rely on. We work on the most...  ...a diverse team of software, hardware, and network engineers, supply chain specialists, security experts, operations managers, and other vital roles. You... 
    Remote work
    Flexible hours

    Amazon

    Washington DC
    a month ago
  • $100k - $120k

     ...Description Reporting to the Director, IT Operations, the Security & Identity Engineer is the senior IT Operations staff member responsible for...  ...ensures the protection of organizational assets through secure access controls, proactive threat detection, and adherence to... 
    Temporary work
    Remote work
    Flexible hours

    Washington Nationals Baseball Club

    Washington DC
    26 days ago
  • $178.4k - $226.7k

    The Ads Security organization at Amazon is dedicated to creating innovative technical...  ...are seeking a talented Senior Security Engineer to join our team, where you will have...  ...following: application security frameworks, identity and access controls, incident response, mobile... 
    Flexible hours

    Amazon

    Washington DC
    a month ago
  • $159.3k - $202.4k

     ...passionate about delivering innovative security solutions and protecting millions of...  ...talented and results-driven Security Engineer to help shape how Amazon protects customer...  ...: application security frameworks, identity and access controls, incident response, mobile security... 
    Flexible hours

    Amazon

    Washington DC
    a month ago
  • $180k - $230k

     ...As a Information System Security Engineer (ISSE)  you will play a critical role in ensuring the...  ...engineering of systems operating within Special Access Programs (SAPs) and other highly...  ...solutions, encryption technologies, identity and access management, and secure configuration... 
    Full time
    Contract work
    Work experience placement

    Modern Technology Solutions Inc

    Washington DC
    1 day ago
  • $110k - $230k

     ...Position Description Our Staff Engineer works with our Distinguished...  ...technical expertise ensuring secure authentication and...  ...technical IAM strategies across all Identity-related security services and...  ...OIDC. Deep skills in privileged access management tools and services... 
    Hourly pay
    Work experience placement
    Local area

    GEICO

    Bethesda, MD
    6 days ago
  • $168k - $210k

     ...everyone deserves the freedom to access, move, and manage their money...  ...money globally, providing secure, simple, and reliable ways to...  ...the Senior Manager, Security Engineering, the Security Engineer will...  ...authentication and SSO through an identity provider;1 year of experience... 
    Full time
    Local area
    Remote work
    Worldwide
    Flexible hours
    3 days per week

    Remitly

    Washington DC
    7 days ago
  •  ...Description VIATEQ is looking for a Security Engineer  to support enterprise cybersecurity operations...  ...investigation and all requisite IT access authorizations prior to performing work...  ..., vulnerability management, identity and access management, network security... 
    Remote work

    VIATEQ Corporation

    Washington DC
    4 days ago
  • $145k - $200k

    Washington, D.C.Information Security /Full-time /HybridA World-Changing...  .... As an Offensive Security Engineer, you will test internal...  ...containerized infrastructure, including identity, network, and workload...  ...establishing a foothold and expanding access once inside.Hands-on... 
    Full time
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package

    Palantir Technologies

    Washington DC
    22 days ago
  •  ...Cybersecurity and Infrastructure Security (CISA) mission is to lead the...  ...is to provide Enterprise Engineering and Operations Support Services...  ...internet (TIC) and private access (VPN replacement) solution.Support...  ...with Cloud Identity and Access ManagementExperience... 
    Full time
    Night shift

    Sev1Tech

    Arlington, VA
    a month ago
  •  ...Intelligence/Machine Learning, Cyber Security and Cutting-Edge Technology...  ...Endpoint Security Engineer is responsible for the administration...  ..., supporting conditional access, and monitoring systems to...  ..., sexual orientation, gender identity, national origin, disability... 
    Monday to Friday
    Flexible hours

    Halvik

    Alexandria, VA
    5 days ago
  •  ...our clients.   Position Title: Security Engineer Location: U.S. Department of Agriculture...  ...implements security controls, identity management, and threat detection. Ensures...  ...security controls, identity and access management, and threat detection in... 
    Local area

    CMT Services Inc

    Washington DC
    3 days ago
  • $122.9k - $216.3k

    About the Team & MissionThe team focus is Identity Architecture & Solutions, where we craft...  ...scalable identity and SaaS security capabilities across the enterprise. This...  ...ChallengeEngineer and deploy Zero‑Trust access controls across workforce and service identities... 
    Full time
    Temporary work
    Local area
    Worldwide

    Adobe Systems

    Washington DC
    a month ago
  • $168k - $210k

     ...everyone deserves the freedom to access, move, and manage their money...  ...money globally, providing secure, simple, and reliable ways to...  ...About the Role As a Security Engineer on Remitly's Corporate...  ...focused in a relevant sub-domain (identity, endpoint, SaaS security, cloud... 
    Full time
    Work at office
    Worldwide

    Remitly

    Washington DC
    a month ago
  •  ...across the globe to create, secure, and run applications that enhance...  ...environment. The Security Engineer position will execute...  ....Implement and manage robust access provisioning schemes, role-based...  ...access controls (RBAC), and Identity Management integrations to secure... 
    Full time
    Local area

    F5 Networks

    Washington DC
    a month ago
  • $178.4k - $226.7k

    AWS Network Security is looking for Sr. Security Engineers who can drive and improve Identity outcomes across the network for the largest cloud provider in the world. AWS is...  ...systems, specifically with Identity and Access Management (IAM). We value broad and deep technical... 
    Temporary work
    Internship
    Flexible hours

    Amazon

    Washington DC
    14 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Identity and Access Security Engineer. Be the first to apply!