Identity and Access Security Engineer
$58.17 per hourBrown Advisory
Company OverviewEvery firm has a culture – the values, beliefs, methodology, attitudes and standards that reflect an organization’s DNA. But the truly inspiring firms – the game-changers, the industry leaders and the disruptors – have cultures that propel them to innovate and stand out. At Brown Advisory, we aim to be one of those inspired firms. Over the years, we have purposefully built and nurtured our client-first culture.Brown Advisory is an independent investment management and strategic advisory firm committed to delivering a combination of first-class performance, strategic advice and the highest level of client service. The firm’s clients—including individuals, families, family offices, endowments, foundations, charities, institutions, consultants, and financial intermediaries—are served by over 1,000 colleagues worldwide, all of whom are equity owners of the firm.Brown Advisory is currently seeking an Identity and Access Security Engineer to lead and mature the firm's identity security controls across Okta, Microsoft Entra ID, Active Directory, CyberArk, BloodHound Enterprise, multifactor authentication, privileged access, application integrations, and access governance. This blended role is designed for a hands-on security professional who understands identity as both a business-enablement workflow and a critical security control plane.The engineer will be responsible for reducing identity-related risk across workforce, privileged, service, application, and machine identities. The role combines identity engineering, privileged-access management, identity threat exposure management, access governance, attack-path remediation, and operational control assurance.As part of a lean Information Security team within a mid-sized financial services organization, this individual will partner with Infrastructure, Enterprise Applications, Compliance, Human Resources, Operations, and business system owners. The role will help ensure that access is appropriately granted, reviewed, monitored, and removed while enabling secure adoption of SaaS, cloud, and on-premises platforms.Blended Role CoveragePrimary emphasis: Identity security engineering and governance across IAM, PAM, identity threat exposure management, MFA, privileged access, access reviews, and identity-related risk.Blended coverage: Okta and Entra ID integration, CyberArk platform operations and privileged-account onboarding, service-account governance, BloodHound Enterprise analysis and attack-path remediation, Active Directory privilege hygiene, SaaS access controls, identity lifecycle automation, and selected security-engineering support.Duties and ResponsibilitiesOwn the day-to-day security governance and engineering of identity controls across Okta, Microsoft Entra ID, Active Directory, MFA, Conditional Access, privileged access, and identity lifecycle workflows.Design, implement, operate, and continuously improve privileged-access controls using CyberArk, including account discovery, vault onboarding, credential rotation, access workflows, session controls, privileged-account monitoring, break-glass access, and evidence collection.Govern the lifecycle of privileged human and non-human identities, including administrator accounts, service accounts, application credentials, scheduled-task accounts, emergency accounts, and other machine identities.Identify privileged and service accounts that are unmanaged, improperly configured, inactive, or outside established CyberArk controls, and coordinate their onboarding, remediation, or retirement.Develop and maintain CyberArk safes, platforms, policies, account ownership models, reconciliation processes, access permissions, operational procedures, and recovery documentation.Operate BloodHound Enterprise as an identity threat exposure management capability, analyzing attack paths, Tier Zero relationships, excessive privilege, nested group membership, delegated permissions, and other identity-control weaknesses.Translate BloodHound findings into prioritized and actionable remediation plans, working with Infrastructure and application owners to remove unnecessary privilege while preserving required business and system functionality.Validate identity-risk remediation through rescanning, attack-path analysis, ticket evidence, exception documentation, and measurable reduction in identity exposure.Maintain a defined Tier Zero and critical-identity model across Active Directory, Entra ID, privileged platforms, administrative systems, and supporting infrastructure.Assess and improve Active Directory security, including privileged groups, delegated administrative rights, nested group relationships, service accounts, stale privileges, domain and forest trust exposure, and administrative-tier separation.Partner with Infrastructure to reduce standing privilege and implement secure administrative patterns for domain, server, workstation, application, and help-desk administration.Integrate applications with Okta and Entra ID using secure authentication, authorization, SSO, provisioning, deprovisioning, and lifecycle-management patterns.Lead access review routines for critical systems, privileged roles, SaaS platforms, and regulated business processes, ensuring exceptions are documented and remediated.Partner with HR, Compliance, Operations, and application owners to improve joiner, mover, leaver, contractor, vendor, service-account, and application-identity workflows.Strengthen identity detection and response by integrating telemetry from Okta, Entra ID, Active Directory, CyberArk, BloodHound Enterprise, and other identity systems into SIEM and investigation workflows.Support investigations involving suspicious authentication, credential misuse, privileged-account activity, unauthorized role changes, risky OAuth grants, anomalous service-account behavior, and potential identity-based lateral movement.Support security configuration for SaaS applications where identity, authorization, administrative roles, and data-access controls are central to risk management.Define and report identity-security metrics, including privileged-account coverage, service-account onboarding, password-rotation compliance, standing privileged access, attack-path exposure, Tier Zero findings, stale access, review completion, and remediation aging.Maintain identity standards, procedures, control evidence, risk documentation, metrics, and leadership reporting in partnership with GRC.Drive remediation of identity-related audit findings, penetration-test findings, policy exceptions, BloodHound findings, and access-control gaps.Provide practical guidance to application, infrastructure, and business teams on secure identity patterns that meet control requirements without slowing delivery unnecessarily.Preferred QualificationsBachelor's degree in cyber security, computer science, information systems, engineering, or a relevant field, or equivalent professional experience.4-8 years of experience in information security, identity and access management, infrastructure security, cloud security, or related technical work.Hands-on experience administering or engineering identity controls in Microsoft Entra ID and Active Directory; experience with Okta or another enterprise identity provider strongly preferred.Hands-on experience with a privileged-access management platform; CyberArk administration or engineering experience strongly preferred.Experience identifying and remediating Active Directory or cloud identity attack paths using BloodHound Enterprise, BloodHound Community Edition, or a comparable identity threat exposure management platform.Demonstrated experience governing service accounts, application identities, privileged accounts, secrets, and other non-human identities.Experience with access reviews, MFA, SSO, provisioning, deprovisioning, Conditional Access, and identity governance in a regulated environment.Experience with PowerShell, Microsoft Graph, REST APIs, or other automation methods used to analyze identity data and automate control workflows.Experience working with infrastructure teams to remediate complex privilege relationships without disrupting business-critical systems.CISSP, Microsoft identity/security certifications, CyberArk certifications, Okta certifications, or other relevant professional designations preferred.Technical SkillsIdentity platforms and protocols: Okta, Microsoft Entra ID, Active Directory, Microsoft 365, MFA, Conditional Access, SSO, SCIM, SAML, OAuth 2.0, OpenID Connect, lifecycle automation, group governance, enterprise applications, managed identities, and application registrations.Privileged-access management: CyberArk administration and engineering, including vaulting, safes, platforms, credential rotation, reconciliation, privileged session controls, account discovery, onboarding, access workflows, reporting, service accounts, emergency access, and operational recovery.Identity threat exposure management: BloodHound Enterprise or comparable attack-path management platforms; Tier Zero analysis; transitive privilege; nested group analysis; delegated permissions; attack-path prioritization; Active Directory privilege hygiene; remediation validation; and exposure metrics.Identity governance: Joiner, mover, leaver workflows; access certification; role and entitlement governance; segregation of duties; exception handling; contractor and vendor access; evidence collection; and control reporting.Automation and analysis: PowerShell, Microsoft Graph, REST APIs, structured data analysis, identity inventory reconciliation, workflow automation, and integration with ticketing, SIEM, and reporting platforms.Identity detection and response: Analysis of authentication, privilege, administrative, and access telemetry from Okta, Entra ID, Active Directory, CyberArk, SaaS platforms, and related identity systems.SaaS access-control models for platforms such as Microsoft 365, Salesforce, Box, and other business-critical applications.Strong communication skills and comfort working across technical teams, business owners, Compliance, HR, and Operations.Demonstrates curiosity and a continuous improvement mindset by identifying opportunities to enhance processes, improve efficiency, and thoughtfully leverage new technologies and tools, including AI-enabled productivity solutionsPersonal AttributesTake ownership and move initiatives forward without constant oversight.Balance technical depth, process discipline, and sound business judgment.Approach risk management pragmatically rather than theoretically.Demonstrate sufficient technical judgment to distinguish an exploitable identity path from a theoretical configuration concern.Work carefully through complex privilege remediation where seemingly minor changes may affect applications, service accounts, administrative workflows, or production systems.Thrive in collaborative, high-accountability environments.Communicate clearly with technical and non-technical colleagues.Bring an entrepreneurial mindset to building and improving security capabilities.Applicants must be authorized to work in the United States without the need for current or future employer-sponsored work authorization (e.g., H-1B , O-1, F-1 (OPT), TN, or any other non-immigrant visa classifications that require employer support or sponsorship).MD Salary: $110-$135k. Commensurate with experience and location. Does not include bonus or long term incentive eligibility (if applicable).DC Salary: $121K–$148.5K. Commensurate with experience and location. Does not include bonus or long-term incentive eligibility (if applicable).BenefitsAt Brown Advisory we offer a competitive compensation package, including full benefits.• Medical• Dental• Vision• Wellness program participation incentive• Financial wellness program• Fitness event fee reimbursement• Gym membership discounts• Colleague Assistance Program• Telemedicine Program (for those enrolled in Medical)• Adoption Benefits• Daycare late pick-up fee reimbursement• Basic Life & Accidental Death & Dismemberment Insurance• Voluntary Life & Accidental Death & Dismemberment Insurance• Short Term Disability• Paid parental leave• Group Long Term Disability• Pet Insurance• 401(k) (50% employer match up to IRS limit, 4 year vesting)Brown Advisory is an Equal Employment Opportunity Employer.SummaryLocation: Baltimore, MD; Washington D.C.Type: Full time
$110k - $135k
...by over 1,000 colleagues worldwide, all of whom are equity owners of the firm.Brown Advisory is currently seeking an Identity and Access Security Engineer to lead and mature the firm's identity security controls across Okta, Microsoft Entra ID, Active Directory, CyberArk...SuggestedFull timeTemporary workFor contractorsH1bWorldwide$82.6k - $162.8k
...confidence, and proactively manage to secure success.Recruiting for this role ends on... ...12/31/2026.Work you'll doAs a Security Engineer on the Deloitte Cyber team, you will be... ...design and implementation of Customer Identity and Access Management (CIAM) solutions aligned to...SuggestedLocal areaVisa sponsorship$134.5k - $265.1k
...confidence, and proactively manage to secure success.Recruiting for this... ...technical ownership with engineering expertise, governance, and... ...fine-grained, attribute-based access policies (PBAC/ABAC) that... ...Integrate PlainID with client identity providers (Okta, Microsoft Entra...SuggestedLocal areaVisa sponsorship$134.5k - $265.1k
...resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026Work you’ll doAs Identity and Access Management (IAM) solutions team Saviynt Engineering Manager, you will:Demonstrate advanced understanding of business...SuggestedLocal areaVisa sponsorship$155.6k - $306.8k
Position Summary As an Engineering Manager in Deloitte Cyber’s Digital Trust & Privacy practice, you will help clients solve complex identity, access, and data protection challenges through AI-enabled engineering solutions. This role sits at the intersection of...SuggestedLocal areaVisa sponsorship$135k - $216k
ResponsibilitiesPeraton is seeking a Information Systems Security Engineer (ISSE) in our Linthicum, MD office in support of our Department... ...transitioning from RMF v4 to v5.Basic understanding of identity and access management system capabilities and configuration....Contract workWork at officeShift work- ...Career Portal (Jobs Hub). Click here to access. Time Type:Full timeRemote Type:Job... ...TechnologyJob Description Summary: The Senior IT Security Engineer is responsible for planning, deploying,... ..., sex, sexual orientation, gender identity, national origin, disability, veteran...Full time
$105.4k - $207.8k
...with confidence, and proactively manage to secure success. Identity security market is undergoing a... ...ends on 12/31/2026.Work you'll doAs a Senior Engineering Management Specialist on the Deloitte Cyber Identity & Access Management team, you will be responsible for...Local areaVisa sponsorship$105.4k - $207.8k
Position Summary Cisco Network Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte... ...and supporting Cisco Identity Services Engine (ISE) capabilities, including 802.1X network access control, device profiling, guest lifecycle...Work experience placementLocal areaVisa sponsorship$119.6k - $179.4k
.... In rapidly changing global security environments, Northrop Grumman... ...Embedded Systems Security Engineer to join our team in Baltimore... ...ability to obtain Special Program Access. This position can be filled... ..., sexual orientation, gender identity, marital status, national...Full timeContract workRelocation packageShift work- ...website: Title : Information Systems Security Engineer (ISSE), Level IILocation: USCG Surface... ...required. This position does not involve access to classified information or classified... ...religion, sex, sexual orientation, gender identity, national origin, age, pregnancy,...Full timeContract workFor contractorsWork at officeLocal areaRemote work
$107.93k - $188k
...transform how organizations operate, and securing those environments requires... ...complex platforms. As a Cloud Security Engineer, you will help assess and enhance security... ...improve cloud security controls, including identity and access management, network security,...Local area$107.93k - $188k
...transform how organizations operate, and securing those environments requires... ...complex platforms. As a Cloud Security Engineer, you will help assess and enhance security... ...improve cloud security controls, including identity and access management, network security,...Local area$144.3k - $240.5k
...across complex environments. As a Lead Integration Engineer II, you will help deliver scalable, secure, and reliable integration capabilities that support... ...race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected...Contract work$102.5k - $188.9k
...confidence, and proactively manage to secure success.Splunk plays a... ...environments. As a Splunk Engineer/Architect, you will design, implement... ...data models, and role-based access controlsMust have one or more... ...Splunk with endpoint, identity, firewall, or cloud security...$105.4k - $207.8k
...Summary Cyber Palo Alto Networks Security Engineer/ Senior Consultant, Strategy, Growth,... ...GCP)Implementing and optimizing Prisma Access capabilities, including GlobalProtect,... ...automation, and response (SIEM/SOAR) and identity provider tools, and supporting...Work experience placementLocal areaRemote work- About the Role GSC is a leading cyber security and information technology company based... ...and experienced Senior Cloud Security Engineer to join our team. In this role, you... ...infrastructure, including network architecture, identity and access management, and data protection...Remote workFlexible hours
$134.5k - $265.1k
Position Summary As a Cyber Forward Deployed Engineer (FDE), you will work at the intersection of client engagement... ...with cybersecurity concepts (e.g., application security, cloud security, identity, detection engineering).Experience with DevSecOps practices...Local areaVisa sponsorship$121k - $206k
...safeguarding our business and clients. We are looking for a Senior Security Engineer with a strong development background and a passion for... ....Mentor engineers across teams on IaC best practices, cloud identity management, and principles of least privilege, including...Full timeLocal areaRemote workWork from home3 days per week$100k - $200k
...team provides expertise in network, system engineering and both offensive and defensive... ...to plan, analyze, design, develop, test, secure, integrate, implement, operate, and maintain... ..., pregnancy, sexual orientation, gender identity, national origin, age or protected veteran...Temporary workLocal areaFlexible hours- ...tightly integrating MDR with offensive security, threat hunting, security research, and... ...CyberMaxx is seeking an Associate Security Engineer to join our Security Control Management... ..., pregnancy, sexual orientation, gender identity, national origin, disability, veteran or...Temporary workLocal areaRemote workFlexible hours
- ...Security Systems Engineer Owings Mills, MD 21117 6 + Months Onsite Day 1: Hybrid Model: 3 Days Onsite Per Week! Enterprise Level Access Control System Administration Setup, configure, update, and troubleshoot. Focus on Lenel S2 Enterprise Level Video Management System...3 days per week1 day per week
$107.9k - $195.05k
...Description Leidos is currently seeking an Information Systems Security Engineer to support our customer onsite. The ISSE shall perform,... ..., domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis...Local areaImmediate start$130k - $270k
...Information Systems Security Engineer (ISSE) Linthicum Heights, MD •Government/Military Clearance Required: TS/SCI with Polygraph... ...race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation...Full timeFlexible hours- ...guidance. - Perform basic containment activities, including access changes, application removal, configuration updates, and allow/... ...preparation of recurring cybersecurity scorecard data. - Monitor security tools and alerts, performing initial triage and escalating...Minimum wageContract workTemporary workWork experience placementRemote work
$175k - $200k
...Career Portal (Jobs Hub). Click here to access. Time Type:Full timeRemote Type:Job... ...an experienced Director, Cloud Security Architecture and Engineering to serve as a hands-on leader, providing... ...security architectures including identity, encryption, network segmentation, logging...Full timeWork experience placementNight shiftWeekend work$134.5k - $265.1k
...Join Deloitte’s Cloud Cyber Security practice as a GCP Forward Deployed Engineer, Senior Consultant and help organizations... ..., network policies, Workload Identity Federation (WIF), runtime protection... ...Policies, Identity and Access Management (IAM) Policy Analyzer,...Local areaVisa sponsorship$118.7k - $243.7k
Position Summary As a Manager in AI Security Engineering, you will play a critical role in... ...security, including data protection, access control, model validation, and monitoring... ...of data protection, identity/access management, and secure architecture...- Professional Services Network Security Engineer Entelligence is seeking a Network Security Engineer to support our Customer’s clients. The successful... ...In‑depth knowledge and deployment experience of Remote Access technologies. Network Security experience (IPS/IDS, ZBFW,...Contract workRemote work
$79.52k - $143.13k
...Under limited supervision, the Cyber Security Engineer is primarily responsible for the enterprise... ...response activities Systems Access ~ Responsible for access control... ...religion, sex, sexual orientation, gender identity and expression, age, national origin,...Work at officeLocal areaImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Identity and Access Security Engineer. Be the first to apply!
- entry level security engineer Baltimore, MD
- network security engineer Baltimore, MD
- sr information security engineer Baltimore, MD
- IT security engineer Baltimore, MD
- aws cloud security engineer Baltimore, MD
- security engineer Baltimore, MD
- senior cloud security engineer Baltimore, MD
- information technology security engineer Baltimore, MD
- senior application security engineer Baltimore, MD
- security engineering manager


