Everforth ECS is seeking an Identity Security Engineer to work in our Washington, DC office / remote.  The role is contingent upon additional funding.
Â
We are seeking a technically experienced Identity Security Engineer to join our security operations division — a full-spectrum cybersecurity organization covering endpoint security, event monitoring, threat intelligence, and advanced incident response. This is a security engineering role, meaning you are not simply administering identity systems but are designing, hardening, and evolving them.
Â
Your work sits at the intersection of two critical disciplines: identity security and Windows server infrastructure. You will assess the organization's identity architecture against modern security frameworks, lead initiatives to reduce identity-based risk, and ensure that the Windows server environment supporting those identity systems is configured, documented, and defended to the highest standard.
Â
This role requires someone who understands identity not just as an IT function but as a primary security control and who can operate with engineering depth and strategic thinking.
Â
Salary Range: $120,000 - $130,000
General Description of Benefits
Identity Security
- Deep understanding of enterprise identity and access management (IAM) architecture, governance, and security operations
- Experience integrating identity signals into security operations, including identity protection, threat detection, and centralized logging
- Ability to monitor identity health, detect suspicious activity, and investigate identity-based threats using security analytics and operational playbooks
- Hands-on experience with Microsoft Entra ID (Azure Active Directory), Privileged Identity Management (PIM), and just-in-time access controls
- Experience enforcing least privilege, role-based access control (RBAC), and automating access provisioning and deprovisioning workflows
- Familiarity with Zero Trust identity principles — verify explicitly, enforce least privilege, and assume breach — and the ability to assess and mature an organization's identity posture against those principles
- Experience securing workload identities, service principals, and high-risk administrative accounts
- Ability to decommission legacy federation infrastructure and migrate applications to modern, standards-based authentication
Windows Server
- Strong experience administering and hardening Windows Server environments in an enterprise setting
- Proficiency with Microsoft Active Directory, Active Directory Federation Services, and Group Policy Objects (GPOs) from a security engineering perspective
- Ability to monitor and analyze Windows-based architecture, communication, policies, and protocols from a cybersecurity lens
- Experience performing system monitoring, reviewing logs, and taking corrective action to maintain server integrity and availability
- Ability to create and maintain thorough system documentation covering installation, configuration, and troubleshooting procedures
- Experience supporting security continuous monitoring efforts including risk assessments and system patching within Windows server environments
Security Engineering & Collaboration
- Ability to identify gaps in current identity and server security capabilities and recommend both technical and process-level improvements
- Experience developing and contributing to technical security standards, monitoring standards, and security architecture documentation
- Comfortable working across teams including cybersecurity, networking, systems administration, and technology support partners
- Ability to communicate findings and risks clearly to both technical peers and senior leadership
A minimum of 5+ years of progressive experience in identity security and Windows server administration is required, with demonstrated experience operating at an engineering level rather than a purely operational or support capacity. Candidates with hands-on Zero Trust identity implementation experience will be strongly preferred.
Learn more about this Employer on their Career Site
