> Markdown version of [/jobs/ext/3566341-advanced-security-engineer](https://www.wearedevelopers.com/jobs/ext/3566341-advanced-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Advanced Security Engineer - **Company:** Relativity - **Location:** Cleveland, OH, United States (Remote available) - **Experience:** Expert - **Salary:** $216,320.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, User Authentication, Microsoft Azure, Bash Shell, Software as a Service, Cloud Computing, Cyber Security, Information Systems, Databases, Continuous Delivery, Continuous Integration, Data Security, Human Resources Information System (HRIS), Federated Identity Management, Identity and Access Management, Internet Security, Information Systems Security Architecture Professional, Python (Programming Language), Kerberos (Protocol), Key Management, Network Security, Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Ping (Networking Utility), Windows PowerShell, Systems Development Life Cycle, Role-Based Access Control, Azure Active Directory, Anti-Phishing, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Information and Event Management, Single Sign-On, Software Engineering, Systems Integration, Software Vulnerability Management, Policy as Code, Computer Aided Engineering (CAE), Cloud Platform System, Okta, Cyberark, Multi-Cloud, Cyber Threat Analysis, HR Software, Information Technology, Data Management, CIS Benchmarks, Drift Detection, Api Design, SailPoint, Security Orchestration, Automation & Response - **Published:** October 3, 2026 - **Apply:** https://www.careerbuilder.com/job-details/advanced-security-engineer-iam-cleveland-oh--f6bcd9bf-1475-4abc-8d7d-b4774cc0658d ## About the Role * Bachelor's in Computer Science, Information Security, or equivalent experience. * 5+ years of hands-on experience in enterprise IAM or security engineering, with a focus on identity, authentication, and access domains, or a Master's degree in Cybersecurity or a relevant field. * Hands-on experience with common identity tools such as IdP/SSO (Okta, Entra ID/Azure AD, Ping), IGA (SailPoint, Saviynt), PAM (CyberArk, BeyondTrust), and directory services, plus intermediate knowledge of authentication and federation protocols (SAML, OIDC, OAuth 2.0, SCIM, LDAP, Kerberos). * Basic knowledge of industry-standard security benchmarks and frameworks (MITRE, NIST 800-63, Zero Trust). * Proficiency in at least one scripting/automation language (Python, Bash, or PowerShell) applied to modern containerized services, CLI-based commands, and/or identity-specific use cases (API-driven provisioning, policy-as-code). * Ability to communicate technical findings clearly to both engineering peers and non-technical stakeholders. Preferred qualifications: * Familiarity with AI-enabled identity operations (UEBA, ML-based access-risk scoring, or AI-assisted access-review and threat-hunting workflows). * Basic knowledge of common cloud environments (AWS, Azure, or GCP) and their native identity services (IAM, RBAC, workload identity). * Working knowledge of the software development lifecycle, software engineering practices, or infrastructure-as-code environments: contributing identity and access controls (secrets management, workload identity, policy-as-code) to CI/CD pipelines. * Experience with non-human, workload, and AI-agent identity, secrets management, and machine-to-machine authentication. * Experience supporting compliance and audit requirements (SOC 2, ISO 27001, FedRAMP, HIPAA) from an identity and access control perspective. * Relevant certifications such as SC-300 (Microsoft Identity and Access Administrator), AZ-500 (Azure Security Engineer), Okta Certified Professional/Administrator, SailPoint IdentityIQ, SEC+, CISSP, CISA, or equivalent., Endpoint Security, Network Security, Penetration Testing, Security Architecture Design, Security Automation, Security Information, Security Information and Event Management (SIEM), Security Operations, Threat Modeling, Vulnerability Management, Access Control, Amazon Web Services (AWS), Analysis Skills, Artificial Intelligence (AI), Audit Metrics, Authentication, Automation, Benchmarking, CISA - Certified Information Systems Auditor, CISSP - Certified Information Systems Security Professional, Campaigns, Cloud Computing, Communication Skills, Computer Aided Engineering (CAE), Computer Science, Computer Security, Continuous Deployment/Delivery, Continuous Integration, Cross-Functional, Defense Information Systems Agency (DISA), Defense in Depth, Endpoint Security, Enterprise Protection, GCP (Good Clinical Practices), HIPAA (Health Insurance Portability and Accountability Act), HRIS/HRMS, Hunting, IR (Infrared), ISO (International Organization for Standardization), Identity Data Management, Identity Federation, Industry Standards, Information/Data Security (InfoSec), Internet Security, Kerberos, LDAP (Lightweight Directory Access Protocol), Microsoft Access Database, Microsoft Windows Azure, Network Security, OAuth, Penetration Testing, Public/Media/Press/Analyst Relations, Regulatory Compliance, Relativity, Risk, Securities and Exchange Commission (SEC), Security Architecture, Security Assertion Markup Language (SAML), Security Attacks, Security Design, Security Information and Event Management (SIEM), Security Monitoring, Single Sign-On (SSO), Software Development Lifecycle (SDLC), Software Engineering, Software as a Service (SaaS), System Integration (SI), Technical/Engineering Design, Telemetry, Test Design, Threat Modeling, U.S. National Institute of Standards and Technology (NIST) ## Description * Implement and operate identity controls spanning workforce, machine, and workload identity as part of a layered defense-in-depth model. * Operate continuous adaptive trust mechanisms, including continuous access evaluation (CAE), risk-based step-up authentication, and session revocation, that re-verify identity against real-time posture and behavioral signals rather than at the access gate alone. * Configure ZTNA, least-privilege access, phishing-resistant MFA/FIDO2, and JIT access across access paths. * Implement SSO, federation, and authentication standards (SAML, OAuth 2.0, OIDC, SCIM, Kerberos, LDAP) across SaaS and multi-cloud environments. * Apply hardening standards to identity infrastructure using CIS Benchmarks/DISA STIGs with automated compliance validation. Identity Lifecycle, Governance & PAM * Build and maintain identity lifecycle automation (joiner/mover/leaver) integrating HR systems, directories, and downstream applications. * Operate identity governance and administration (IGA) workflows: access reviews, certification campaigns, and segregation-of-duties checks. * Administer privileged access management (PAM) including credential vaulting, JIT elevation, and session monitoring. * Maintain governance of non-human identities (service accounts, workloads, secrets) using drift detection and policy-as-code. Detection, Response & Collaboration * Feed identity telemetry into the detection stack (SIEM/SOAR, UEBA) to support detection of credential abuse, privilege escalation, and lateral movement. * Execute identity-focused IR playbook steps for account takeover, credential compromise, and session hijacking. * Implement identity checks in CI/CD pipelines (secret scanning, IaC identity analysis), acting on AI-generated fix recommendations in PR workflows. * Track identity hygiene metrics and support audits, certifications, and e-discovery requirements alongside GRC.