> Markdown version of [/jobs/ext/2013641-sr-security-engineer](https://www.wearedevelopers.com/jobs/ext/2013641-sr-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr Security Engineer - **Company:** Hays Specialist Recruitment LLC - **Location:** Raleigh, NC, United States - **Experience:** Expert - **Salary:** $121,992.0 - $135,200.0 - **Contract:** Temporary contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Bash Shell, Cloud Computing Security, Cyber Security, System Configuration, XacML, Identity and Access Management, Information Technology Operations, Python (Programming Language), Kerberos (Protocol), Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Windows PowerShell, Role-Based Access Control, Openid Connect, Security Assertion Markup Language (SAML), Single Sign-On, User Provisioning Software, Web Services, Scripting, Cloud Platform System, Cyber Threat Analysis, SailPoint, Restful APIs, Splunk, User Accounts - **Published:** August 10, 2026 - **Apply:** https://www.hays.com/job-detail/sr-security-engineer--raleigh_1185794 ## About the Role * SailPoint IdentityNow (IDN) Expertise * SailPoint IDN Architecture: Hands-on experience configuring, administering, and extending SailPoint IdentityNow (IDN), including source configuration, identity profiles, access profiles, and roles. * Target Connector Setup: Direct experience configuring and troubleshooting SailPoint IDN AWS connectors (e.g., AWS Identity Center/SSO connector or AWS IAM connector) using REST APIs, Web Services, or Virtual Appliances (VA). * Automated Provisioning & Lifecycle Management: Proven track record of configuring Joiner-Mover-Leaver (JML) workflows, automated access provisioning, deprovisioning, and access certification campaigns for cloud environments. * Must have experience with AWS Tenant & Identity Architecture * AWS Identity Foundation: Demonstrated experience standing up and configuring AWS landing zones, AWS Organizations, multi-account structures, and Service Control Policies (SCPs). * AWS Identity Center (AWS SSO) & IAM: Deep expertise setting up AWS IAM Identity Center (formerly AWS Single Sign-On), configuring permission sets, assigning inline/managed policies, and structuring IAM roles/policies for least-privilege access. * Cloud Security & Federation: Strong knowledge of SAML 2.0, OpenID Connect (OIDC), and SCIM protocol integration between enterprise Identity Providers (IdPs) and AWS. * Must have knowledge of hybrid IAM environments and cloud-and-cloud identity integration * Must have understanding of API's how they are used to integrate IAM systems with other applications * Must have authentication and Authorization Protocols a)They should possess a deep understanding of authentication and authorization protocols such as OAuth2.0, OIDC (OpenID Connect), SAML (Security Assertion Markup Language), LDAP (Lightweight Directory Access Protocol), Kerberos, and XACML (eXtensible Access Control Markup Language) * Must have IAM Governance and Compliance a) They should be familiar with IAM governance frameworks and standards such as NIST, ISO 27001, SOX, and GDPR * Must have User Lifecycle Management: must have provisioning and de-provisioning user accounts, including Joiner-Mover-Leaver (JML) processes. * Must have experience with automation of user lifecycle management using tools such as PowerShell, Python, or IAM orchestration tools. * Must have experience in implementation or support of Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC). * Must have Security and Risk Management expertise: an understanding of IAM's role in broader security frameworks and risk management along with an understanding of threat modeling and risk assessment related to identity and access. * Must have experience in Incident Response and Forensics Should have the ability to support IAM-related incident response efforts, including identifying and mitigating identity-based security incidents * Should have ability to perform Splunk queries for log diving; as well as some time of scripting exp = like in PowerShell Understanding of forensic analysis related to identity breaches. * Automation and Scripting Ability to leverage and understand scripting languages such as Python, PowerShell, or Bash for automating tasks. Experience in participating in cross-functional teams in IAM initiatives. Ability to collaborate with security, IT operations, developers, and business stakeholders to align IAM solutions with organizational goals. ## Description * This role will be instrumental in designing and optimizing IAM frameworks, automating identity processes, and ensuring compliance with security policies and regulatory requirements. The engineer will collaborate with cybersecurity, IT, and business stakeholders to enhance security posture, mitigate identity-related risks, and drive IAM adoption. * Assist with implementation and maintenance of technical security solutions including planning, deployment coordination, change management, documentation, and training to enhance SECU's security posture. * Configure and tune security tools, integrate them with enterprise controls, and evaluate vendor offerings and new tools to improve security responsiveness. * Identify and recommend opportunities for documentation enhancements, cost savings, service quality improvements, and operational efficiency. * Support governance and compliance efforts by participating in assessments and remediation activities to ensure adherence to security standards and regulations. * Participate in on-call rotation and serve as a resource for technical support of information security technologies and mentor junior engineers. * Pursue and maintain skills and certifications to stay current with advancing cybersecurity trends and best practices. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Decoupled Authorization using Policy as Code](https://www.wearedevelopers.com/videos/35-decoupled-authorization-using-policy-as-code) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)