Amentum

Senior Cybersecurity Engineer (IAM)

Amentum$120K — $149K *
US-AnywhereRemote in Richmond, VA
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of hands-on IAM security engineering experience with a Bachelor's degree in a relevant field; 4+ years with a Master's.
  • Extensive experience securing Entra ID, Okta, and Active Directory in hybrid environments.
  • Strong expertise in Privileged Access Management (PAM), Self-Service Password Management, and Just-In-Time (JIT) access.
  • Current CISSP, CISM, or equivalent certification required.
  • Proven implementation experience with multi-factor authentication (MFA) and access protection policies.

Responsibilities

  • Implement enterprise IAM security controls in a multi-tenant hybrid environment.
  • Execute IAM designs by translating security architecture into operational security configurations.
  • Maintain and enforce IAM security policies and standards in compliance with regulations.
  • Configure and tune identity security controls to protect users and data.
  • Serve as a 2nd-level SOC escalation point for identity-related security incidents.
  • Investigate identity-related security anomalies using various data sources.
  • Support audit activities by ensuring IAM compliance and maintaining documentation.

Benefits

  • Health, dental, and vision insurance
  • Paid time off and holidays
  • Retirement benefits including 401(k) matching
  • Educational reimbursement
  • Parental leave
  • Employee stock purchase plan
  • Tax-saving options
  • Disability and life insurance
  • Pet insurance
Full Job Description

Amentum is seeking a Senior Cybersecurity Engineer with deep Identity and Access Management (IAM) expertise to protect enterprise assets across a multi-tenant, hybrid (cloud/on-premises) environment. This is a fully remote, hands-on role spanning identity security, multi-cloud security, and endpoint protection. This position is US Remote telework and US Citizenship is required.



Responsibilities:

  • Implement and operate enterprise IAM security controls across a multi-tenant/multi-domain hybrid environment spanning Entra ID, Okta, and Active Directory — including PAM, JIT access, conditional access, and MFA policy enforcement (not day-to-day user/group provisioning or account administration)
  • Execute IAM designs defined by security architecture, translating architectural standards into working security configurations, policies, and integrations
  • Maintain and enforce IAM-related security policies, standards, and best practices in alignment with regulatory and compliance requirements (CMMC, NIST 800-171/800-172, and other applicable frameworks)
  • Configure and tune identity security controls — access policies, privileged access workflows, authentication requirements — protecting users, systems, applications, and data across Entra ID, Okta, and AD environments
  • Serve as 2nd-level SOC escalation point for critical identity-related security incidents
  • Investigate identity-related security anomalies using platform reporting, network traffic, log files, and automated alerts
  • Support audit and assessment activities by maintaining compliant configurations and evidence for IAM controls
  • Automate recurring IAM security operations tasks
  • Maintain system and process documentation, including compliance-relevant control documentation
  • Provide off-hours support as needed (infrequent)
  • Cover other assignments as needed

Knowledge, Skills, & Abilities (KSAs):

  • Working knowledge of Zero Trust, RBAC, and ABAC
  • Working knowledge of regulatory/compliance frameworks relevant to IAM (CMMC, NIST 800-171/800-172, or similar)
  • Understanding of network security fundamentals: boundary protection, segmentation, firewalls, endpoint security, threat hunting, data protection
  • Self-starter, strong written/verbal communication, comfortable with minimal supervision and shifting priorities
  • Ability to travel up to 10%

 

Qualifications:

  • Typically, 8 years of hands-on IAM security engineering experience with a Bachelor’s degree in Computer Science, Information Systems or related field plus; 4 with Master's.  IAM security engineering experiences includes implementing access controls, privileged access management, and authentication policy, rather than general user/account administration.
  • Hands-on experience securing and administering Entra ID, Okta, and Active Directory identity infrastructure in a hybrid environment
  • Solid experience in Privileged Access Management (PAM), Self-Service Password Management, and Just-In-Time (JIT) access
  • Current CISSP, CISM, or equivalent certification
  • Solid MFA and access-protection implementation experience
  • Solid Microsoft Azure/M365 experience
  • U.S. Citizen (required)

 

Preferred qualifications, KSAs, and experience:

  • Experience implementing an IAM governance platform such as Saviynt, SailPoint, or similar
  • Experience supporting CMMC assessments or audits
  • Familiarity with GDPR, SOX, ISO 27001
  • Entra/Azure GCC High exposure

       

Compensation Details:

$120k-$149k

       

The compensation range or hourly rate listed for this position is provided as a good-faith estimate of what the company intends to offer for this role at the time this posting was issued. Actual compensation may vary based on factors such as job responsibilities, education, experience, skills, internal equity, market data, applicable collective bargaining agreements, and relevant laws.

 

Benefits Overview:

Our health and welfare benefits are designed to support you and your priorities. Offerings include:

  • Health, dental, and vision insurance

  • Paid time off and holidays

  • Retirement benefits (including 401(k) matching)

  • Educational reimbursement

  • Parental leave

  • Employee stock purchase plan

  • Tax-saving options

  • Disability and life insurance

  • Pet insurance

 

Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O'Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.

       

Original Posting:

08/03/2026 - Until Filled

Amentum anticipates this job requisition will remain open for at least three days, with a closing date no earlier than three days after the original posting. This timeline may change based on business needs.

       

About Amentum

Amentum is a leading provider of engineering and technical services to the U.S. government and commercial customers worldwide. The company offers a wide range of services, including environmental remediation, facilities management, and logistics and supply chain management, among others. Amentum has a global presence, with operations in over 20 countries, and serves a diverse range of customers, including the Department of Defense, the Department of Energy, and the Department of State. The company is committed to providing high-quality services and has a strong reputation for technical expertise, innovation, and customer satisfaction.
Learn more about Amentum
Size
20,000 employees
Industry
Net Income
$200 million
Founded
2014
Revenue
$5 billion

Similar Jobs

More Jobs at Amentum

More Information Technology Jobs

Find similar Senior Cybersecurity Engineer (IAM) jobs: