> Markdown version of [/jobs/ext/3034858-identity-security-engineer](https://www.wearedevelopers.com/jobs/ext/3034858-identity-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity Security Engineer - **Company:** My Eye Dr. Optometrists, LLC - **Location:** Raleigh, NC, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Amazon Web Services, Application Integration Architecture, Computing Platforms, Microsoft Azure, Business Software, Cloud Computing, Cloud Computing Security, Cyber Security, Linux, Multi-Factor Authentication, Identity and Access Management, Information Technology Operations, Internet Protocol Security (IP SEC), Virtual Private Networks (VPN), Python (Programming Language), Lightweight Directory Access Protocols (LDAP), OAuth, Public Key Infrastructure, Windows PowerShell, Role-Based Access Control, Openid Connect, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Information and Event Management, Single Sign-On, Software Vulnerability Management, Data Logging, Transport Layer Security, Google Cloud, Enterprise Software Applications, Cyber Threat Analysis, HybridCloud, Firewalls (Computer Science), Infrastructure as Code (IaC), Information Technology - **Published:** September 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3b70f38dd00e5c1d ## About the Role * Bachelor's degree in computer science, information assurance, cybersecurity or related field, or equivalent industry experience. * 5+ years of cybersecurity experience, including at least 3+ years of hands-on identity security, IAM, or cloud security experience. * Experience administering Microsoft Entra ID (Azure AD), SSO, MFA, Conditional Access, RBAC, Privileged Identity Management (PIM), and identity governance controls. * Experience with identity protocols and standards including SAML, OAuth 2.0, OpenID Connect, SCIM, LDAP, and modern authentication technologies. * Previous experience working with Microsoft Azure, AWS, GCP, cloud networking architecture, and hybrid-cloud operations. * Network and encryption experience, including VPNs, IPsec, SSL/TLS, LDAP, and Public Key Infrastructure (PKI). * Working knowledge of Identity Governance & Administration (IGA), Privileged Access Management (PAM), and access certification processes. * Experience with automation and scripting technologies such as PowerShell, Python, APIs, and Infrastructure as Code (IaC). * Familiarity with tools such as IAM, SIEM, EDR, Vulnerability Management, CSPM/CNAPP, Firewalls, Enterprise Logging, and Threat Intelligence platforms. * Strong Linux and Windows support skills. * Experience and understanding of regulatory requirements including HIPAA, PCI, SOX, and GDPR, as well as frameworks such as NIST, ISO 27001, and ITIL. * Self-motivated and self-directed, with excellent critical thinking, communication, and problem-solving skills. ## Description MyEyeDr. is seeking a dynamic and detail-oriented Identity Security Engineer to join our IT Cyber Security team. The Identity Security Engineer helps architect, deploy, and operate secure identity and cloud infrastructure that aligns with business needs. This position is responsible for supporting operational innovation while providing security direction to the business to elevate the company's security posture across identity systems, cloud platforms, and enterprise applications. Reporting to the VP, Cyber Security & IT Operations, this is a hybrid-remote role offering a flexible work arrangement out of our Raleigh, NC office with an onsite requirement of two days per week. You Will * Design, implement, and maintain enterprise identity and access management (IAM) controls across cloud and hybrid environments, ensuring secure access to systems, applications, and data. * Manage the complete identity lifecycle for workforce, contractor, service, and privileged accounts, including provisioning, role changes, access requests, and deprovisioning activities. * Engineer and support Single Sign-On (SSO), Multifactor Authentication (MFA), Conditional Access, federation services, and Zero Trust access controls utilizing Microsoft Entra ID and related identity platforms. * Govern role-based access control (RBAC), entitlement management, privileged access, and periodic access reviews to ensure least-privilege principles are consistently enforced across the enterprise. * Develop and automate identity governance processes, application integrations, and access workflows using standards such as SAML, OAuth, OpenID Connect, SCIM, APIs, PowerShell, and Python. * Develop and maintain secure, resilient enterprise-grade cloud processes in tandem with architects and system engineers. * Secure business applications and computing environments across public, private or hybrid cloud infrastructures. * Protect patient data and business applications in compliance with privacy, security, business resiliency and compliance frameworks as defined in corporate policies. * Conduct rigorous oversight of security systems and security configuration administration to reduce risk to enterprise systems and accounts. * Document, formulate and enforce areas of security improvement that balance risk with business operations and do not diminish efficiencies or innovation. * Act as a key figure in incident response to track occurrence and resolution, with strict documentation and reporting as well as engagement with security operations and incident response teams. * Attend regular technical project and implementation meetings and serve as the security consultant to help guide secure application and infrastructure configurations. * Actively monitor, assess and recommend tactical and strategic initiatives based on new and emerging threats posing risk to cloud computing environments. * Manage remediation efforts after security assessment findings outline weaknesses requiring attention. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)