Senior Identity Engineer
Group 1001About the role
Group 1001 is a consumer-centric, technology-driven family of insurance companies on a mission to deliver outstanding value and operational performance by combining financial strength and stability with deep insurance expertise and a can-do culture. Group1001’s culture emphasizes the importance of collaboration, communication, core business focus, risk management, and striving for outcomes. This goal extends to how we hire and onboard our most valuable assets – our employees.
Why This Role Matters:
We are seeking a highly skilled and motivated Senior Identity Engineer to join our Information Security team. The ideal candidate will have deep expertise in enterprise Identity technologies, in a hands-on engineering capacity. This role is critical to ensuring secure identity management processes, compliance with regulatory guidelines, and enhancement of the defense posture of the Group1001.
How You'll Contribute:
- Design, implement, and maintain enterprise-wide identity solutions with a focus on IGA, Cloud and endpoint security.
- Collaborate with cross-functional teams to integrate identity and access management (IAM) solutions into business processes.
- Manage and optimize PAM platforms, such as Delinea Secret Server, Delinea PCS.
- Implement role-based access controls (RBAC) and least privilege principles for privileged accounts.
- Ensure secure storage (Delinea SS) and rotation of privileged credentials and monitor privileged access activities.
- Experience with creating HashiCorp Vault policies, managing leases, and configuring secrets engines
- Maintain compliance with regulatory requirements through automated workflows and reporting.
- Work closely with audit and compliance teams to remediate identity-related risks.
- In depth expertise in complex Active Directory environments, including multi-forest and multi-domain architectures.
- Advanced understanding of FSMO roles, AD replication topology, Global Catalog, and sites/subnets configuration for Active Directory
- Proficiency in managing advanced security features of AD Certificate Services and Managed Service Accounts (MSA)
- Architect and support hybrid identity environments integrating Entra ID with on-premises directories and SaaS applications.
- Configure advanced features such as Conditional Access, Identity Protection, and Self-Service Password Reset.
- Proficient in implementing enterprise-level PKI environments, including root CA and subordinate CA hierarchies.
- Expertise in setting up and managing Certificate Authorities using MS AD Certificate Services and HashiCorp Vault.
- Ensure seamless Single Sign-On (SSO), external identity federation and external B2B trusts.
- Monitor and respond to identity-related security incidents and vulnerabilities.
- Collaborate with the Security Operations Center (SOC) to address IAM-related alerts and threats.
- Conduct root cause analysis and implement preventive measures.
- Evaluate and implement emerging IAM technologies and practices to enhance security and operational efficiency.
- Stay updated with industry trends, regulations, and best practices in identity management and information security.
What We're Looking For:
Education and Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Relevant certifications such as CISSP, CISM, Microsoft Certified: Cybersecurity Architect, or equivalent are preferred.
Experience:
- Minimum of 6-8 years of experience in identity and access management, with expertise in PAM, IGA, and Microsoft Entra ID.
- Hands-on experience with tools like Delinea Secret Server/PCS, SailPoint, Okta, HashiCorp Vault, CyberArk, or similar platforms.
- Strong knowledge of Active Directory, Azure AD LDAP, Kerberos, SAML/OAuth and OpenID Connect protocols.
Skills:
- Expertise in designing and deploying secure identity solutions for complex environments.
- Strong scripting or coding skills (PowerShell, Python, Java, C# etc.) for automation.
- Experience with CI/CD build automation and deployment pipelines (Jenkins, Azure DevOps, CodeShip, PagerDuty)
- Excellent communication and collaboration skills to work effectively with technical and non-technical stakeholders.
- Solid understanding of regulatory frameworks (e.g., GDPR, SOX, HIPAA) and their impact on IAM.
Compensation:
Our compensation reflects the cost of labor across several U.S. geographic markets. The base pay for this position ranges from $200,000/year in our lowest geographic market up to $250,000/year in our highest geographic market. Pay is based o
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s