1,171,657open jobs
66,118companies
208,459added this week
Browse all
Salary
≈ $77k – $159k per year (Estimated)
Location
Hybrid (Cary, United States)
Seniority
Middle · 3+ years exp
Visa
H-1B filings in 12 months: 20 · for this role: 4 · green card filings: 9

Confirmed on the employer's own hiring board on Oct 4, 2026. First seen by Alion on Aug 25, 2026.

Overview
Company
Impact
Profile match
American Tower is a Boston infrastructure company founded in 1995 that owns and operates wireless communications sites. Its portfolio of hundreds of thousands of towers and data centre assets underpins mobile networks across the Americas, Africa, Europe and India. The company is listed on the New York Stock Exchange as a real estate investment trust.

The Team

We are seeking an Identity Security Engineer to join American Tower’s Information Security organization. This role strengthens identity security, reduces privileged access risk, and enables secure access to enterprise systems, data, and cloud resources. As an Identity Security Engineer, you will engineer and support identity and privileged access solutions across cloud, on-premises, and hybrid environments. You will help advance Zero Trust through Zero Standing Privilege (ZSP), Just-In-Time (JIT) access, least privilege, Role Based Access Controls (RBAC), Conditional Access, and modern authentication technologies. This role works closely with Security Operations, Governance Risk & Compliance, Infrastructure, Cloud, Application Development, Service Desk, and enterprise identity architecture teams.

This position is located onsite in Cary, NC and required to be in the office 3 days per week. We are hybrid, in office Tuesday/Wednesday/Thursday.

What You Can Offer Us

  • Design, implement, and support enterprise Identity Access Management (IAM) and Privileged Access Management (PAM) solutions across cloud, on-premises, and hybrid environments.
  • Engineer privileged access capabilities including credential vaulting, password rotation, session management, privileged account onboarding, break-glass access, and account lifecycle management.
  • Advance ZSP, JIT access, least privilege, privileged access reduction, and RBAC initiatives.
  • Implement and support Microsoft Entra ID capabilities including Conditional Access, Privileged Identity Management (PIM), multi-factor authentication (MFA), Identity Protection, password less authentication, and access security controls.
  • Design and support application access management, single sign-on (SSO), federation, and modern authentication integrations using Security Assertion Markup Language (SAML), Open Authorization version 2.0 (OAuth 2.0), Open ID Connect (OIDC), Lightweight Directory Access Protocol (LDAP), and directory services.
  • Secure privileged users, administrative accounts, service accounts, application identities, machine identities, agentic identities, and other non-human identities.
  • Partner with infrastructure, cloud, application, and platform teams to onboard systems, applications, servers, databases, endpoints, and cloud resources into PAM and identity security platforms.
  • Develop and maintain privileged access standards, administrative access models, engineering runbooks, operational procedures, and Zero Trust access control patterns.
  • Automate identity and privileged access processes using PowerShell, Python, REST APIs, workflow orchestration, and platform integrations.
  • Troubleshoot IAM and PAM platform issues, perform root cause analysis, and implement corrective actions to improve reliability and operational stability.
  • Collaborate with Security Operations to investigate identity-related incidents, privileged access risks, control gaps, and suspicious activity involving high-risk identities.
  • Communicate identity security risks, technical recommendations, and remediation plans to cross-functional teams, senior management, and business stakeholders.
  • Other duties as assigned.

What You Need to Succeed

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent combination of education and experience is required.
  • 3+ years of experience designing, implementing, and supporting IAM, PAM, and/or identity security solutions in large enterprise environments required.
  • 2+ years of confident hands-on experience administering CyberArk Privilege Cloud, CyberArk PAM, Delinea, BeyondTrust, and/or comparable PAM platforms highly preferred.
  • Demonstrated ability to own and improve ZSP, JIT access, least privilege, RBAC, break-glass access, and privileged access reduction capabilities.
  • Strong working knowledge of Microsoft Entra ID, Conditional Access, PIM, MFA, Identity Protection, directory services, and modern authentication controls.
  • Confident understanding of SSO, federation, authentication, and authorization technologies such as SAML, OAuth 2.0, OIDC, LDAP, Active Directory, and cloud identity platforms.
  • Capable of owning automation or integration work using PowerShell, Python, REST APIs, workflow automation, or similar scripting technologies is preferred.
  • Proven ability to assess identity security risks, identify control gaps, recommend practical remediation, and communicate clearly with technical and non-technical stakeholders.
  • Strong judgment, ownership mindset, sense of urgency, customer focus, business integrity, and ability to prioritize work in a fast-paced environment.
  • Approximately 5% travel may be required in support of the position’s responsibilities.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,171,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Cary
≈ $112k – $219k per year (Estimated) • In office • Contractor • Washington
DevOps
Splunk
GCP
Azure
AWS
Cybersecurity
Crowdstrike
Nessus
Snort
Qualys Cloud Platform
Microsoft Sentinel
Suricata
SentinelOne
Microsoft Defender
IBM QRadar
SIEM
Apply
$135k – $203k per year • In office • Secret • Full-Time • 5+ years exp • Bachelor's Degree • Colorado Springs
Python
PowerShell
Bash
DevOps
GCP
Azure
AWS
Linux
Windows
Cybersecurity
Wireshark
Crowdstrike
Tcpdump
Autopsy
SentinelOne
MITRE ATT&CK
Carbon Black
FTK
EnCase
X-Ways Forensics
SIEM
Apply
≈ $62k – $128k per year (Estimated) • In office • Full-Time • 3+ years exp • High School Diploma • Memphis
AI/ML
Supervision
Apply
$80k – $105k per year • Remote (United States) • 1+ year exp • Bachelor's Degree • Washington
Python
SQL
AI/ML
LLM
Red Teaming
Apply
$114k – $140k per year • Remote (United States) • 5+ years exp • Bachelor's Degree • Washington
Python
SQL
AI/ML
LLM
Red Teaming
Apply
$39k – $66k per year • In office
Python
AI/ML
LangGraph
LangChain
Vertex AI
AI Agents
LLM
RAG
OpenAI
OCR
DevOps
GCP
Azure
Apply
$39k – $66k per year • In office
Python
AI/ML
NLP
PyTorch
LLM
Hugging Face
LLMOps
Apply
Apply
≈ $75k – $156k per year (Estimated) • In office • 3+ years exp • Bachelor's Degree • Cary
Python
PowerShell
DevOps
Ansible
Azure
AWS
VPN
Cybersecurity
Microsoft Sentinel
Zscaler
Microsoft Defender
Wiz
Zero Trust
Least Privilege
Microsoft Entra ID
Palo Alto NGFW
SIEM
Apply
Cybersecurity Analyst 2 months ago
≈ $72k – $150k per year (Estimated) • In office • 4+ years exp • Cary
Cybersecurity
Microsoft Sentinel
Microsoft Defender
Apply
≈ $110k – $216k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Boston
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
SIEM
DLP
Analytics
Power BI
Management
Monday.com
Smartsheet
Microsoft Project
Jira
ServiceNow
Agile
Waterfall
Apply
≈ $100k – $197k per year (Estimated) • In office • 5+ years exp • Cary
Python
PowerShell
DevOps
Ansible
Azure
Cybersecurity
Okta
Zscaler
Microsoft Defender
Least Privilege
SIEM
Apply
≈ $37k – $64k per year (Estimated) • In office • 2+ years exp • Bachelor's Degree • Boston
Management
Microsoft Office
Apply
≈ $75k – $157k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Cary
Python
PowerShell
DevOps
Linux
Windows
Unix
TCP/IP
Cybersecurity
Nessus
OpenVAS
Threat Modeling
Active Directory
LDAP
SIEM
Management
Google Workspace
Microsoft Office
Apply
$52k – $68k per year • Equity • Hybrid • Bachelor's Degree • Cary
Python
Design
AutoCAD
Apply
$38k – $50k per year • In office • 1+ year exp • Cary
Apply
$74k – $96k per year • Equity • In office • 7+ years exp • Bachelor's Degree • Cary
Management
Microsoft Office
Apply
≈ $60k – $151k per year (Estimated) • Hybrid • Full-Time • Bachelor's Degree • Cary
Design
AutoCAD
Management
Microsoft Office
Apply
See all jobs
This is one of many
1,171,657 more open roles from verified company boards, updated every day.