Identity Security Engineer

American Tower
Boston, MA, United States
1 day ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Active Directory User Authentication Cloud Computing Cyber Security Databases Multi-Factor Authentication Identity and Access Management Python (Programming Language) Lightweight Directory Access Protocols (LDAP) OAuth OpenID
+14 more
Windows PowerShell Role-Based Access Control Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Session Management Single Sign-On Software Engineering Workflow Management Systems Cyberark Information Technology Enterprise Integration Restful APIs Network Server

Job description

We are seeking an Identity Security Engineer to join American Tower’s Information Security organization. This role strengthens identity security, reduces privileged access risk, and enables secure access to enterprise systems, data, and cloud resources. As an Identity Security Engineer, you will engineer and support identity and privileged access solutions across cloud, on-premises, and hybrid environments. You will help advance Zero Trust through Zero Standing Privilege (ZSP), Just-In-Time (JIT) access, least privilege, Role Based Access Controls (RBAC), Conditional Access, and modern authentication technologies. This role works closely with Security Operations, Governance Risk & Compliance, Infrastructure, Cloud, Application Development, Service Desk, and enterprise identity architecture teams., * Design, implement, and support enterprise Identity Access Management (IAM) and Privileged Access Management (PAM) solutions across cloud, on-premises, and hybrid environments.

  • Engineer privileged access capabilities including credential vaulting, password rotation, session management, privileged account onboarding, break-glass access, and account lifecycle management.
  • Advance ZSP, JIT access, least privilege, privileged access reduction, and RBAC initiatives.
  • Implement and support Microsoft Entra ID capabilities including Conditional Access, Privileged Identity Management (PIM), multi-factor authentication (MFA), Identity Protection, password less authentication, and access security controls.
  • Design and support application access management, single sign-on (SSO), federation, and modern authentication integrations using Security Assertion Markup Language (SAML), Open Authorization version 2.0 (OAuth 2.0), Open ID Connect (OIDC), Lightweight Directory Access Protocol (LDAP), and directory services.
  • Secure privileged users, administrative accounts, service accounts, application identities, machine identities, agentic identities, and other non-human identities.
  • Partner with infrastructure, cloud, application, and platform teams to onboard systems, applications, servers, databases, endpoints, and cloud resources into PAM and identity security platforms.
  • Develop and maintain privileged access standards, administrative access models, engineering runbooks, operational procedures, and Zero Trust access control patterns.
  • Automate identity and privileged access processes using PowerShell, Python, REST APIs, workflow orchestration, and platform integrations.
  • Troubleshoot IAM and PAM platform issues, perform root cause analysis, and implement corrective actions to improve reliability and operational stability.
  • Collaborate with Security Operations to investigate identity-related incidents, privileged access risks, control gaps, and suspicious activity involving high-risk identities.
  • Communicate identity security risks, technical recommendations, and remediation plans to cross-functional teams, senior management, and business stakeholders.
  • Other duties as assigned.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent combination of education and experience is required.
  • 3+ years of experience designing, implementing, and supporting IAM, PAM, and/or identity security solutions in large enterprise environments required.
  • 2+ years of confident hands-on experience administering CyberArk Privilege Cloud, CyberArk PAM, Delinea, BeyondTrust, and/or comparable PAM platforms highly preferred.
  • Demonstrated ability to own and improve ZSP, JIT access, least privilege, RBAC, break-glass access, and privileged access reduction capabilities.
  • Strong working knowledge of Microsoft Entra ID, Conditional Access, PIM, MFA, Identity Protection, directory services, and modern authentication controls.
  • Confident understanding of SSO, federation, authentication, and authorization technologies such as SAML, OAuth 2.0, OIDC, LDAP, Active Directory, and cloud identity platforms.
  • Capable of owning automation or integration work using PowerShell, Python, REST APIs, workflow automation, or similar scripting technologies is preferred.
  • Proven ability to assess identity security risks, identify control gaps, recommend practical remediation, and communicate clearly with technical and non-technical stakeholders.
  • Strong judgment, ownership mindset, sense of urgency, customer focus, business integrity, and ability to prioritize work in a fast-paced environment.
  • Approximately 5% travel may be required in support of the position’s responsibilities.

Benefits & conditions

American Tower also offers a comprehensive benefits package, which includes healthcare coverage, a 401(k) savings plan, paid time off, company holidays, sick leave, parental leave, and access to an Employee Assistance Program focused on mental and financial wellness, please click here (https://www.americantower.com/us/careers/benefits) to learn more.

About the company

American Tower is a global digital infrastructure company serving customers through tower sites and other real estate solutions that support connectivity and opportunity, focused on achieving our vision of Building a More Connected World. Our success is rooted in the potential of our people and the power of local teams at our offices and sites across 25 countries.

We are one of the largest global Real Estate Investment Trusts (REITs) and a publicly traded (NYSE:AMT), Fortune 500 Company headquartered in Boston, Massachusetts. The next decade will be an exciting time as we evolve our infrastructure to meet tomorrow’s needs and position our people to elevate their impact, their potential, and our shared success. Come grow your career with us!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

Videos

See all

Related articles

See all