Identity Security Engineer
What You'll Do- Lead security consulting and engineering for Windows, Active Directory, Entra ID, and related identity security solutions, setting technical direction for the design and development of new capabilities
- Define and execute the vision, strategy, architecture, and implementation of authentication platforms across on-premises and cloud environments
- Serve as a technical authority on SAML, OpenID Connect, OAuth 2.0, and Kerberos authentication, including single sign-on, PKI, and associated identity controls
- Assess identity management risks and threats, and communicate remediation plans to senior technical and business stakeholders
- Shape the identity security roadmap by evaluating emerging security and privacy technologies, trends, and threats against key business initiatives
- Lead identity-related workstreams during information security incidents, including containment, root-cause analysis, and post-incident hardening
- Partner with senior stakeholders across Technology, Trading, Legal, Internal Audit, and Compliance to define, govern, and enforce identity and access security policies
- Establish production-readiness, documentation, and operational standards for identity security solutions, while mentoring junior and mid-level security engineers
What You Bring- 10+ years of experience in a technical role, including 5+ years focused on information security; financial services experience is preferred
- Bachelor's degree in Computer Science, Engineering, or a related field
- Strong experience engineering Microsoft security solutions across desktop and server operating systems, Entra ID, Active Directory, Group Policy, Desired State Configuration, DNS, and collaboration platforms
- Experience managing IaaS and SaaS solutions and services through CI/CD pipelines
- Strong understanding of modern authentication protocols and associated identity security controls
- Experience with Microsoft 365 security controls, including Entra ID, Conditional Access, and Foundry
- Experience implementing data loss prevention and Azure Information Protection solutions, including data classification, labeling, encryption, and regulatory compliance
- Familiarity with EDR, SIEM, vulnerability management, and relevant security certifications is a plus
Salary RangeMillennium offers a total compensation package which includes a base salary, discretionary performance bonus, and comprehensive benefits. The estimated base salary range for this position is $175,000 to $250,000, which is specific to New York City and may change in the future. When finalizing an offer, we take into consideration an individual's experience level and the qualifications they bring to the role to formulate a competitive total compensation package.