Identity Security Engineer

Janus Henderson

$90K — $100K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in Identity Security or related field.
  • Strong understanding of Privileged Access Management (PAM) principles.
  • Experience with enterprise PAM platforms like Britive or CyberArk.
  • Background in designing and operating access controls in cloud environments.
  • Familiarity with Active Directory, Entra ID, and identity governance concepts.

Responsibilities

  • Design and implement Privileged Access Management controls.
  • Investigate and resolve identity-related security incidents.
  • Manage privileged users and service accounts throughout their lifecycle.
  • Develop security metrics and dashboards to measure effectiveness.
  • Support identity threat detection and response capabilities.

Benefits

  • Hybrid working and reasonable accommodations.
  • Generous holiday policies.
  • Excellent health and wellbeing benefits including corporate memberships.
  • Paid volunteer time to engage with the community.
  • Professional development support including tuition reimbursement.
Full Job Description
Your opportunity

The Identity Security Engineer is a hands-on security engineering role focused on securing privileged access and identities across JHI. The role is primarily responsible for designing, implementing, and operating Privileged Access Management (PAM) controls, ensuring privileged users, service accounts, machine identities, APIs, and emerging AI agents are securely managed throughout their lifecycle. In addition, the engineer will support identity threat detection and response capabilities, investigate identity-related security events, maintain data access governance tooling, and develop security metrics and automation that strengthen JHI's overall identity security posture and reduce operational risk.

What to expect when you join our firm

  • Hybrid working and reasonable accommodations
  • Generous Holiday policies
  • Excellent Health and Wellbeing benefits including corporate membership to Wellhub
  • Paid volunteer time to step away from your desk and into the community
  • Support to grow through professional development courses, tuition/qualification reimbursement and more
  • Maternal/paternal leave benefits and family services
  • Unique employee events and programs including a 14er challenge
  • Complimentary beverages, snacks and all employee Happy Hours


Must have skills

  • Strong understanding of Privileged Access Management (PAM) principles, including least privilege, just-in-time access, ephemeral access, privileged session management, secrets management, and credential vaulting.
  • Ability to investigate, triage, and resolve PAM and identity-related incidents, requests, and operational issues while driving root-cause remediation.
  • Experience administering and engineering enterprise PAM platforms such as Britive, CyberArk, Delinea, or equivalent.
  • Experience designing, implementing, and operating privileged access controls across on-premise and cloud environments.
  • Experience onboarding and governing privileged users, service accounts, machine identities, APIs, workload identities, and other non-human identities throughout their lifecycle.
  • Experience securing and managing privileged access for automation platforms, cloud workloads, DevOps tooling, and emerging AI/agentic systems.
  • Experience configuring and maintaining identity security and data access governance platforms, including Active Directory/Entra ID auditing, permissions analysis, access monitoring, and security reporting.
  • Strong understanding of Identity Access Governance (IAG) concepts and integrations between PAM, IAG, and ITSM platforms, such as SailPoint Identity Security Cloud (ISC) and ServiceNow, with experience supporting identity lifecycle management, provisioning workflows, and troubleshooting workflow issues.
  • Experience working with Active Directory, Entra ID, federation, authentication, access control, and modern identity security architectures.
  • Experience developing security metrics, KPIs, dashboards, and reporting that measure control effectiveness, operational performance, adoption, and risk reduction in an automated manner.


Nice to have skills
  • Experience with Identity Threat Detection & Response (ITDR) and identity-centric threat monitoring.
  • Experience with User and Entity Behaviour Analytics (UEBA) platforms.
  • Experience creating, tuning, or maintaining identity-focused detections, analytics, and use cases within a SIEM platform.
  • Understanding of identity-focused attack techniques including account compromise, privilege escalation, credential theft, lateral movement, and insider threats.
  • PowerShell and/or Python scripting experience for automation and operational efficiency.
  • Experience integrating identity platforms with SIEM, SOAR, and security operations tooling.
  • Experience monitoring and securing non-human identities, machine identities, and AI agents.
  • Knowledge of AI agent security, non-human identity governance, MCP security, delegated permissions, workload identities, and AI-related identity threats.


Supervisory responsibilities
  • No


Potential for growth

  • Mentoring
  • Leadership development programs
  • Regular training
  • Career development services
  • Continuing education courses


Compensation information

The base salary range for this position is $90,000 to $100,000. This range is estimated for this role. Actual pay may be different. This position will be open through October 2026.

Colorado law requires an estimated closing date for job postings. Please don't be discouraged from applying if you see this date has passed.

#LI-LN2

Annual Bonus Opportunity: Position may be eligible to receive an annual discretionary bonus award from the profit pool. The profit pool is funded based on Company profits. Individual bonuses are determined based on Company, department, team and individual performance.

Benefits: Janus Henderson is committed to offering a comprehensive total rewards package to eligible employees that includes; competitive compensation, pension/retirement plans, and various health, wellbeing and lifestyle benefits. To learn more about our offerings please visit the Why Join Us section on the career page here.

Similar Jobs

More Jobs at Janus Henderson

More Information Technology Jobs

Find similar Identity Security Engineer jobs: