Lead Identity Security Engineer
Manager
Senior
Cloud Identity Security
Cybersecurity Leadership
Data Security
Engineer
Enterprise Identity
Facilities Management
Iam Identity Automation
Identity and Access Management
Identity Security
Identity Threat Detection And Response
Incident Response
Information Security
InfoSec
Privileged Access Management
Project Management
Risk Management
Security
Security And Identity
Security Automation
Security Compliance
Security Engineering
Security Operations
Security Standards
Solution Architecture
Job Description
In this Lead Identity Security Architect role, you will direct enterprise Identity Security efforts across IGA, ITDR, PAM, and Policy-Based Access Control (PBAC). The position emphasizes architecture, integration, and operationalization of identity risk detection and response capabilities using leading identity security platforms.
Location
New York, NY (onsite)
Responsibilities
- Lead enterprise Identity Security initiatives spanning IGA, ITDR, PAM, and PBAC capabilities.
- Define and execute the Identity Security strategy, roadmap, architecture, and implementation approach in alignment with business and security objectives.
- Provide architectural oversight and technical leadership for SailPoint Identity Security Cloud (ISC), CrowdStrike Identity Protection, and related Identity Security platforms.
- Design and implement identity risk signal integrations across SailPoint ISC, CrowdStrike Identity Protection, Active Directory, Microsoft Entra ID, PAM solutions, and existing security platforms.
- Develop and operationalize identity threat detection and response to surface account compromise, privilege escalation, lateral movement, insider threats, and credential abuse.
- Lead detection engineering, including use case design, correlation logic, monitoring content development, alert tuning, and optimization.
- Drive SIEM integrations to improve identity-centric threat analytics, monitoring, dashboards, and threat-hunting capabilities.
- Establish workflow automation, orchestration, and response mechanisms to accelerate identity-related incident remediation.
- Support PBAC model implementation, including access governance frameworks, entitlement management, and risk-based access controls.
- Lead PAM onboarding, integration, governance, monitoring, and operational processes for enterprise privileged accounts.
- Partner with executive stakeholders and governance forums to deliver program updates, risk visibility, and strategic guidance.
- Create and maintain operational runbooks, playbooks, architecture documentation, testing plans, and transition-to-support deliverables.
Requirements
- 8+ years of experience in Identity & Access Management (IAM), Identity Governance, Cybersecurity Architecture, or Identity Security Engineering.
- Deep expertise in SailPoint Identity Security Cloud (ISC) implementation, integration, governance, and access lifecycle management.
- Hands-on experience with CrowdStrike Identity Protection and ITDR capabilities, including identity risk monitoring.
- Strong understanding of Privileged Access Management solutions such as CyberArk, BeyondTrust, Delinea, or equivalent.
- Experience implementing identity security controls using SAML, OAuth 2.0, OpenID Connect (OIDC), SCIM, and modern federation protocols.
- Expertise in identity threat detection, incident response, threat hunting, and security monitoring use case development.
- Experience integrating IAM, IGA, PAM, Active Directory, Entra ID, and SIEM platforms in enterprise environments.
- Strong knowledge of policy-based access control, role management, identity governance, and compliance requirements.
- Experience delivering in Agile environments and leading cross-functional security transformation initiatives.
- Excellent stakeholder management, executive communication, technical leadership, and governance experience.
- Relevant certifications in SailPoint, CyberArk, SC-300, CISSP, CISM, or equivalent identity and security technologies are highly desirable.
Technologies
- SailPoint Identity Security Cloud (ISC)
- CrowdStrike Identity Protection
- Privileged Access Management (CyberArk)
- BeyondTrust
- Delinea
- SAML
- OAuth 2.0
- OpenID Connect (OIDC)
- SCIM
- Active Directory
- Microsoft Entra ID
- SIEM
- CyberArk
- SC-300
- CISSP
- CISM
Compensation
The annual salary for this position is USD 114,500 - 134,000, depending on experience and other qualifications. This position is also eligible for Cognizant’s discretionary annual incentive program, based on performance and subject to the terms of Cognizant’s applicable plans.
Benefits
- Medical/Dental/Vision/Life Insurance
- Paid holidays plus Paid Time Off
- 401(k) plan and contributions
- Long-term/Short-term Disability
- Paid Parental Leave
- Employee Stock Purchase Plan
Application Deadline
Applications will be accepted until 30 Sep 2026.