> Markdown version of [/jobs/ext/2292717-information-security-engineer-iii](https://www.wearedevelopers.com/jobs/ext/2292717-information-security-engineer-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer III - **Company:** Capital Group - **Location:** Irvine, CA, United States - **Experience:** Expert - **Salary:** $141,648.0 - $226,637.0 - **Contract:** Temporary contract - **Skills:** Microsoft Windows, Active Directory, Artificial Intelligence, Amazon Web Services, User Authentication, Microsoft Azure, Command-Line Interface, Cyber Security, Databases, Linux, Identity and Access Management, Python (Programming Language), Kerberos (Protocol), Microsoft Software, OAuth, OpenID, Windows PowerShell, Role-Based Access Control, Ansible, Security Assertion Markup Language (SAML), Single Sign-On, Software Vulnerability Management, Cloud Platform System, Cyberark, Technical Debt, Kubernetes, Terraform, Servicenow - **Published:** August 29, 2026 - **Apply:** https://www.wayup.com/i-Investment-Management-j-Information-Security-Engineer-III-Capital-Group-310935691596508/ ## About the Role You are more than a job title. We want you to feel comfortable doing great work and bringing your best, authentic self to everything you do. We value your talents, traditions, and uniqueness-and we're committed to fostering a strong sense of belonging in a respectful workplace., + You have 5+ years of experience in Information Security, Identity and Access Management (IAM), Privileged Access Management (PAM), or a related field. + You have firsthand experience with PAM technologies such as CyberArk, StrongDM or comparable platforms. + You possess a strong understanding of privileged access controls, identity management, authentication, authorization, and security best practices. + You have experience engineering privileged access across on-premises and cloud environments, including AWS, Azure, Kubernetes/EKS, Windows and Linux hosts, databases, command-line access, policy-driven authorization, and monitored sessions. + You have experience with Active Directory, enterprise identity services, and authentication and authorization technologies such as SSO, SAML, OIDC, OAuth 2.0, SCIM 2.0, RBAC, ABAC, certificate-based authentication, Kerberos, and just-in-time provisioning. + You can troubleshoot complex access and authentication issues and provide Tier 3 support, monitoring, incident response, root-cause analysis, vulnerability remediation, and resilient production operations for critical PAM services. + You communicate effectively across teams, translate complex technical concepts for varied audiences, take ownership of outcomes, and continually improve security and operational efficiency. + You can define and operationalize PAM standards, architecture patterns, controls, exception processes, lifecycle governance, metrics, and audit-ready reporting. Preferred Skills & Experience + Experience securing non-human and machine identities, including service accounts, workload identities, certificates, secrets, and AI agents, with lifecycle governance and least-privilege controls. + Experience designing ServiceNow-integrated just-in-time or on-demand privileged-access workflows, including approvals, policy validation, provisioning, revocation, and audit evidence. + Experience automating PAM administration, onboarding, provisioning, credential rotation, monitoring, and policy enforcement using PowerShell, Python, Terraform, Ansible, or comparable infrastructure-as-code tooling. + Experience modernizing legacy PAM infrastructure, designing resilient cloud or colocation architectures, executing migrations and decommissioning, conducting recovery testing, and reducing technical debt. + Relevant security certifications such as CISSP, CyberArk, Microsoft, or AWS certifications. ## Description "I can be myself at work.", As an Information Security Engineer III, you will help secure and modernize Capital Group's Privileged Access Management (PAM) capabilities within our Identity and Access Management (IAM) organization. You will design, implement, and support solutions that protect privileged access across on-premises and cloud environments while helping advance our security modernization strategy. You will play a key role in several high-priority initiatives, including PAM platform modernization, StrongDM adoption, Privileged Access Workstation (PAW) enhancements, ServiceNow integration, Azure support. Your work will improve operational resiliency, reduce risk, and strengthen the security of critical systems across the enterprise. You thrive in a direct engineering environment and enjoy solving complex security challenges, partnering with cross-functional teams, and delivering scalable solutions that balance security, efficiency, and user experience. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)