CybersecurityJobs.io
← Back to all jobs

Job Description

Millennium Management is seeking an Identity Security Engineer to lead security consulting and engineering efforts for Microsoft identity platforms. The role focuses on authentication and access control design across on-premises and cloud environments, with active support during security incidents and ongoing improvements to the identity security roadmap.

Role Summary

The Identity Security Engineer will define authentication platform direction, evaluate identity risks, and drive identity workstreams during information security incidents. Responsibilities include establishing architecture and implementation for identity capabilities, serving as a technical authority on modern authentication protocols, and partnering with senior stakeholders to govern identity and access security policies.

Key Responsibilities

  • Lead security consulting and engineering for Windows, Active Directory, Entra ID, and related identity security solutions, including setting technical direction for new capabilities.
  • Define and execute the vision, strategy, architecture, and implementation of authentication platforms across on-premises and cloud environments.
  • Act as a technical authority on SAML, OpenID Connect, OAuth 2.0, and Kerberos, including single sign-on and PKI, as well as associated identity controls.
  • Assess identity management risks and threats, and communicate remediation plans to senior technical and business stakeholders.
  • Develop the identity security roadmap by evaluating emerging security and privacy technologies, trends, and threats aligned to business initiatives.
  • Lead identity-related workstreams during information security incidents, including containment, root-cause analysis, and post-incident hardening.
  • Partner with senior stakeholders across Technology, Trading, Legal, Internal Audit, and Compliance to define, govern, and enforce identity and access security policies.
  • Establish production readiness, documentation, and operational standards for identity security solutions, while mentoring junior and mid-level security engineers.

Required Qualifications

  • 10+ years of experience in a technical role, including 5+ years focused on information security; financial services experience is preferred.
  • Bachelor’s degree in Computer Science, Engineering, or a related field.
  • Strong experience engineering Microsoft security solutions across desktop and server operating systems, including Entra ID, Active Directory, Group Policy, Desired State Configuration, DNS, and collaboration platforms.
  • Experience managing IaaS and SaaS solutions through CI/CD pipelines.
  • Strong understanding of modern authentication protocols and associated identity security controls.
  • Experience with Microsoft 365 security controls, including Entra ID, Conditional Access, and Foundry.
  • Experience implementing data loss prevention and Azure Information Protection, including data classification, labeling, encryption, and regulatory compliance.
  • Familiarity with EDR, SIEM, vulnerability management, and relevant security certifications is a plus.

Technologies

  • Windows, Active Directory, Entra ID
  • SAML, OpenID Connect, OAuth 2.0, Kerberos, single sign-on, PKI
  • IaaS, SaaS, CI/CD
  • Microsoft 365, Conditional Access, Foundry
  • Data loss prevention, Azure Information Protection, data classification, labeling, encryption
  • EDR, SIEM, vulnerability management
  • Group Policy, Desired State Configuration, DNS, collaboration platforms

Compensation and Location

Location: New York, NY (onsite).

Estimated Salary Range: USD 175,000 to 250,000 per year. Specific to New York City and may change in the future.

Benefits

  • Base salary
  • Discretionary performance bonus
  • Comprehensive benefits

Similar Jobs