Cybersecurity Engineer

Expand Energy Corporation
Oklahoma City, OK, United States
3 days ago
Apply on www.oklahomacityjobsite.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Application Programming Interfaces (APIs) Application Integration Architecture Microsoft Azure Software as a Service Cloud Computing Control Objectives for Information and Related Technology (COBIT) CompTIA Security+ Cyber Security Identity and Access Management Microsoft Software
+14 more
Windows PowerShell Role-Based Access Control Cloud Services Zero Trust Network Access Session Management Systems Integration SSL Certificate Management Scripting Transport Layer Security Okta Cyberark Software Troubleshooting Information Technology SailPoint

Job description

This senior-level cybersecurity engineering position is responsible for designing, implementing, administering, and supporting enterprise identity, directory services, privileged access, and access governance solutions. The role serves as a senior technical contributor below the architect level, translating security architecture and standards into reliable operational capabilities across Active Directory, Okta, SailPoint, CyberArk, Quest Active Roles Server, TLS certificate management, and Group Policy. This position leads complex engineering efforts, supports critical cybersecurity services, mentors less experienced team members, and ensures identity and access platforms remain secure, resilient, auditable, and aligned with business and regulatory requirements., * Design, implement, administer, and support enterprise identity and access management services, including Active Directory, Okta, SailPoint, CyberArk, Quest Active Roles Server, and related integrations

  • Serve as a senior technical owner for directory services, authentication, authorization, privileged access, identity governance, and access lifecycle processes
  • Implement solution architectures, technical standards, and security patterns defined by cybersecurity architects and leadership
  • Maintain and improve Active Directory security, including domain administration, OU structure, delegation models, privileged groups, administrative accounts, and GPO policies
  • Administer Quest Active Roles Server capabilities, including delegated administration, workflow support, provisioning controls, and operational automation
  • Configure, support, and troubleshoot Okta SSO, MFA, federation, application integrations, authentication policies, and related identity controls
  • Support SailPoint identity governance processes, including access requests, access certifications, entitlement ownership, provisioning workflows, and integration health
  • Administer CyberArk privileged access management capabilities, including vaulted credential onboarding, safe permissions, credential rotation, privileged session controls, and operational support
  • Manage and improve enterprise TLS certificate lifecycle processes, including certificate inventory, issuance, renewal coordination, expiration tracking, and remediation of certificate-related risks
  • Troubleshoot and resolve complex identity, directory, authentication, authorization, certificate, and privileged access incidents; participate in root-cause analysis and corrective action planning
  • Identify and implement automation opportunities using tools such as PowerShell, scripting, APIs, and workflow automation to improve repeatability, control effectiveness, and operational efficiency
  • Partner with infrastructure, application, cloud, audit, and business teams to implement secure access patterns and resolve identity-related issues
  • Develop and maintain technical documentation, standards, runbooks, recovery procedures, diagrams, and operational evidence supporting audit and compliance requirements
  • Lead significant technical work efforts or smaller projects related to identity modernization, privileged access, access governance, directory hardening, and certificate management
  • Provide technical guidance and mentoring to cybersecurity analysts, administrators, and engineers while escalating architectural decisions when appropriate
  • Participate in cybersecurity operational support and on-call responsibilities as required for critical identity and access services
  • Perform other duties as assigned, * Becomes a trusted senior engineer for Active Directory, Quest Active Roles Server, Okta, SailPoint, CyberArk, TLS certificate management, and GPO-related support
  • Stabilizes and improves identity and access operations while reducing dependence on any single individual for critical platform knowledge
  • Improves documentation, recovery readiness, audit evidence, and operational procedures for key identity and privileged access services
  • Identifies automation opportunities that reduce manual effort and improve the reliability of access, certificate, and directory management processes
  • Contributes to senior engineering and architecture discussions while remaining focused on hands-on execution, platform ownership, and operational excellence

Requirements

  • Advanced knowledge of enterprise identity and access management principles, including SSO, MFA, federation, identity governance, privileged access management, RBAC, least privilege, and Zero Trust concepts
  • Strong hands-on experience administering Microsoft Active Directory in a complex enterprise environment, including domain services, GPOs, administrative delegation, privileged access, and directory hardening
  • Experience with Quest Active Roles Server or similar delegated administration and identity automation tools
  • Experience administering Okta, including application integrations, authentication policies, MFA, SSO, federation, delegated authentication, and troubleshooting
  • Experience supporting SailPoint IdentityNow or similar identity governance platforms, including access requests, certifications, entitlement ownership, provisioning, and workflow support
  • Experience administering CyberArk or similar privileged access management platforms, including credential vaulting, safe permissions, credential rotation, session management, and privileged account controls
  • Strong understanding of TLS certificate management, certificate authorities, certificate lifecycle processes, and operational risks associated with expired or misconfigured certificates
  • Proficiency with PowerShell and scripting or automation tools used to manage identity, directory, certificate, and access-related processes at scale
  • Strong troubleshooting and problem-solving skills across hybrid identity, SaaS applications, Windows infrastructure, cloud services, and enterprise security platforms
  • Good understanding of audit, compliance, SOX control expectations, access review evidence, and documentation practices related to identity and privileged access management
  • Ability to translate cybersecurity architecture, standards, and control objectives into practical engineering tasks and operational processes
  • Effective written and verbal communication skills; able to work with technical teams, application owners, vendors, auditors, and business stakeholders
  • Demonstrated ability to lead complex technical work, manage competing priorities, mentor others, and drive assigned initiatives to completion with limited supervision, * Minimum: Bachelor’s degree from an accredited university in Cybersecurity, Information Security, Information Technology, MIS, Computer Science, or a related field; equivalent experience and cybersecurity training may be considered
  • Preferred: Bachelor’s degree from an accredited university in Cybersecurity, Information Security, Information Technology, MIS, Computer Science, or a related technical field, Minimum: 8 years related work experience in cybersecurity engineering, identity and access management, directory services, privileged access management, infrastructure security, or related enterprise technology functions, * CISSP, CISM, or similar cybersecurity certification
  • Microsoft identity, security, or Azure certifications such as SC-300, AZ-500, or equivalent
  • Okta, SailPoint, CyberArk, Microsoft, or directory services certifications relevant to identity, access governance, or privileged access management
  • CompTIA Security+ or other foundational cybersecurity certification

Benefits & conditions

Our core values - Stewardship, Character, Collaborate, Learn, Disrupt - are the lens through which we evaluate every business decision. As a dynamic, growing company that offers extremely competitive compensation and benefits, our employees are our most valued assets and the foundation of Expand’s performance among our E&P competitors.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.oklahomacityjobsite.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

2:20 min

Addressing security risks with central single sign-on setups

Gift Egwuenu · World Congress 2023

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all