> Markdown version of [/jobs/ext/2217556-identity-security-engineer](https://www.wearedevelopers.com/jobs/ext/2217556-identity-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity Security Engineer - **Company:** CoStar Group - **Location:** San Diego, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $133,000.0 - $203,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Artificial Intelligence, Automation of Tests, Bash Shell, Continuous Integration, Identity and Access Management, Python (Programming Language), Kerberos (Protocol), Log Analysis, OAuth, Open Source Technology, OpenID, Public Key Infrastructure, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Security Assertion Markup Language (SAML), Security Information and Event Management, Okta, Large Language Models, Microsoft InTune, Data Analytics, Casper Suite, Multiplatform - **Published:** August 25, 2026 - **Apply:** https://www.dice.com/job-detail/a89f0cea-d838-42b8-83af-16cf3ab8d8ef ## About the Role * Bachelor's Degree required from an accredited, not for profit, in person, university or college. * A track record of commitment to prior employers * Thorough understanding of AitM attacks, Evilgnx and understanding on how to neutralize them through strong identity security hygiene * 4+ years of hands-on security engineering experience, including implementation of new controls to address threats * Strong analytical and problem-solving skills with a data-driven approach to decision-making * Hands-on experience administrating industry-standard IDPs (Okta, PingID, Microsoft Entra ID, Active Directory) * Knowledge of authentication and authorization protocols such as SAML, OAuth, OIDC, Kerberos * Firm understanding of PKI, the FIDO2 framework, passkeys, Windows Hello for Business, and Platform SSO, Okta FastPass, Okta Device Trust * Solid understanding of role-based access control, least privilege, just-in-time access, and other identity security paradigms * Experience analyzing SIEM logs and creating related dashboards * Ability to read and author basic scripts in at least one common language (Python, PowerShell, Bash) Preferred Qualifications and Skills * Hands-on experience with Microsoft Intune, Jamf, JumpCloud, or other MDM platforms * Experience with identity security testing tools such as Bloodhound, AzureHound, SharpHound, Responder, etc. * Record of automating operational tasks * Familiarity with CI/CD infrastructure * Experience configuring risk-based conditional access or authentication policies * Experience with workload identity governance * Strong written and verbal communications skills, with a demonstrated ability to communicate complex topics with both engineering peers and non-technical audiences * Experience with AI/ML-assisted security tooling, including building or deploying LLM-based agents ## Description * Design, implement, and continuously improve identity security controls across various platforms * Develop and maintain conditional access policies that enforce appropriate authentication strength, device compliance, etc including for privileged roles, sensitive applications, and workload identities * Analyze logs to scope and guide rollouts of new security initiatives * Support an org-wide, multi-platform phish-resistant authentication rollout * Engineer controls around AI and workload identities (service principals, managed identities, OAuth app registrations) * Research, prototype, and operationalize AI-assisted tooling and agentic workflows to improve team efficiency, including automating repetitive analysis and building internal tools that surface identity risk * Document projects, standards, and runbooks * Communicate frequently and effectively with both technical and non-technical stakeholders * Participate in attack path management efforts via commercial and open-source tools * Stay current with the greater identity threat landscape as well as the identity defense offerings from major IDP vendors ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)