This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Sr. Cyber Security Engineer II – Identity Governance is a pivotal role responsible for designing, implementing, and operating secure identity and access management solutions. With a focus on Active Directory, access governance, and modern authentication controls, you will support enterprise identity services including hybrid AD, SSO, user lifecycle provisioning, RBAC, and conditional access. This role offers the opportunity to integrate internal applications with modern IGA platforms, ensuring secure, automated, and auditable access processes.
Job Responsibility:
Engineer, maintain, and secure Active Directory components including domains, OUs, group structures, service accounts, and delegated administration models
Support hybrid identity patterns integrating on‑premises Active Directory with cloud identity platforms
Partner with infrastructure and cloud teams to ensure directory services are resilient, monitored, and aligned to security best practices
Apply Zero Trust security concepts to identity systems, recognizing Active Directory and identity connectors as high‑risk control plane assets
Support privileged access separation, administrative role scoping, and least‑privilege enforcement across identity platforms
Participate in hardening initiatives to reduce privilege escalation paths and credential exposure within identity services
Implement and support SSO and federation integrations using industry‑standard protocols (SAML, OIDC, OAuth)
Assist in designing and maintaining conditional access policies based on user risk, role, device posture, and authentication context
Troubleshoot authentication and authorization issues across directories, identity providers, and integrated applications
Support joiner / mover / leaver lifecycle processes across Active Directory and downstream applications
Implement group‑ and role‑based provisioning models aligned to RBAC principles
Ensure timely provisioning and deprovisioning of user and service accounts to reduce access risk
Build, configure, and support connectors between internal applications and modern IGA platforms
Collaborate with IAM and application teams to define provisioning requirements and entitlement models
Assist with connector testing, monitoring, and operational stability to support access request and certification processes
Participate in identity‑related incident response, troubleshooting access issues, privilege misuse, or provisioning failures
Support audits, access reviews, and compliance activities by ensuring identity data is accurate and traceable
Contribute to documentation, SOPs, and runbooks for identity services and integrations
Requirements:
Bachelor’s degree in Cybersecurity, Computer Science, or a related field or equivalent work experience
10 or more years of progressively complex experience in cybersecurity
Proven experience with cybersecurity frameworks (e.g., NIST, ISO 27001)
Hands-on experience with security systems, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, and content filtering
Knowledge of network protocols and data encryption methods
Hands-on experience supporting Active Directory in an enterprise environment
Practical experience with identity and access management concepts including: user lifecycle provisioning, entitlement management, role-based access control (RBAC)
Experience building or supporting application integrations with an IGA platform
Experience supporting SSO and authentication integrations
Working knowledge of conditional access and modern authentication controls
Strong troubleshooting skills across identity, access, and authentication workflows
Experience operating or supporting identity systems classified as Tier Zero
Exposure to hybrid identity architectures (on-premises and cloud)
Familiarity with access certifications, audits, or identity governance processes
Experience collaborating with application, infrastructure, and cloud engineering teams on identity integrations
Certifications such as CISSP, CISM, or SANS GIAC
Nice to have:
Strong leadership and team-building abilities, mentoring junior cybersecurity professionals and leading by example
Effective communication and negotiation skills
able to articulate complex concepts to non-technical stakeholders
Poise under pressure
capable of making high-stakes decisions regarding threat mitigation and incident response
What we offer:
Competitive base salary + bonus on eligible positions
22 days plus 7 major holidays and 1 floating holiday
Company match 401(k) plan
Online and retail discounts
Physical and mental health wellness programs
Daycare, cafeteria, fitness center, and coffee shop at our HQ
Inclusive culture with associate-led Business Resource Groups