Identity Security Engineer at ECS Tech Inc
United States
$120k - $130k
<p><u>Everforth ECS is seeking an <strong><em>Identity Security Engineer </em></strong>to work in our <strong><em>Washington, DC </em></strong>office / <strong><em>remote</em></strong>. <strong>The role is contingent upon additional funding.</strong></u></p> <p> </p> <p>We are seeking a technically experienced <strong>Identity Security Engineer</strong> to join our security operations division — a full-spectrum cybersecurity organization covering endpoint security, event monitoring, threat intelligence, and advanced incident response. This is a security engineering role, meaning you are not simply administering identity systems but are designing, hardening, and evolving them.</p> <p> </p> <p>Your work sits at the intersection of two critical disciplines: identity security and Windows server infrastructure. You will assess the organization's identity architecture against modern security frameworks, lead initiatives to reduce identity-based risk, and ensure that the Windows server environment supporting those identity systems is configured, documented, and defended to the highest standard.</p> <p> </p> <p>This role requires someone who understands identity not just as an IT function but as a primary security control and who can operate with engineering depth and strategic thinking.</p> <p> </p> <p><em>Salary Range: $120,000 - $130,000</em><br /><em><a href="https://ecstech.com/careers/benefits">General Description of Benefits</a></em></p><div>Qualifications</div><p>Identity Security</p> <ul> <li>Deep understanding of enterprise identity and access management (IAM) architecture, governance, and security operations</li> <li>Experience integrating identity signals into security operations, including identity protection, threat detection, and centralized logging</li> <li>Ability to monitor identity health, detect suspicious activity, and investigate identity-based threats using security analytics and operational playbooks</li> <li>Hands-on experience with Microsoft Entra ID (Azure Active Directory), Privileged Identity Management (PIM), and just-in-time access controls</li> <li>Experience enforcing least privilege, role-based access control (RBAC), and automating access provisioning and deprovisioning workflows</li> <li>Familiarity with Zero Trust identity principles — verify explicitly, enforce least privilege, and assume breach — and the ability to assess and mature an organization's identity posture against those principles</li> <li>Experience securing workload identities, service principals, and high-risk administrative accounts</li> <li>Ability to decommission legacy federation infrastructure and migrate applications to modern, standards-based authentication</li> </ul> <p>Windows Server</p> <ul> <li>Strong experience administering and hardening Windows Server environments in an enterprise setting</li> <li>Proficiency with Microsoft Active Directory, Active Directory Federation Services, and Group Policy Objects (GPOs) from a security engineering perspective</li> <li>Ability to monitor and analyze Windows-based architecture, communication, policies, and protocols from a cybersecurity lens</li> <li>Experience performing system monitoring, reviewing logs, and taking corrective action to maintain server integrity and availability</li> <li>Ability to create and maintain thorough system documentation covering installation, configuration, and troubleshooting procedures</li> <li>Experience supporting security continuous monitoring efforts including risk assessments and system patching within Windows server environments</li> </ul> <p>Security Engineering & Collaboration</p> <ul> <li>Ability to identify gaps in current identity and server security capabilities and recommend both technical and process-level improvements</li> <li>Experience developing and contributing to technical security standards, monitoring standards, and security architecture documentation</li> <li>Comfortable working across teams including cybersecurity, networking, systems administration, and technology support partners</li> <li>Ability to communicate findings and risks clearly to both technical peers and senior leadership</li> </ul> <p>A minimum of 5+ years of progressive experience in identity security and Windows server administration is required, with demonstrated experience operating at an engineering level rather than a purely operational or support capacity. Candidates with hands-on Zero Trust identity implementation experience will be strongly preferred.</p>
Apply Now