{"id":1642851,"url":"https://alion.io/job/american-tower-identity-security-engineer","title":"Identity Security Engineer","company":{"id":176038,"name":"American Tower","domain":"americantower.com","url":"https://alion.io/company/american-tower","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":null},"role":"Security","role_family":"Security","seniority":"middle","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Cary, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":78000,"max_usd":153000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":318},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"AI Agents","optional":false},{"name":"BeyondTrust","optional":false},{"name":"CyberArk","optional":false},{"name":"Delinea","optional":false},{"name":"IAM","optional":false},{"name":"LDAP","optional":false},{"name":"Least Privilege","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"Rest API","optional":false},{"name":"Service Desk","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-08-25T20:49:41Z","employer_posted_date":"2026-08-25","last_verified_at":"2026-10-05T23:00:02Z","board_verified":true,"closed_at":null,"days_open":41,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":41},"description":"The Team\nWe are seeking an Identity Security Engineer to join American Tower’s Information Security organization. This role strengthens identity security, reduces privileged access risk, and enables secure access to enterprise systems, data, and cloud resources. As an Identity Security Engineer, you will engineer and support identity and privileged access solutions across cloud, on-premises, and hybrid environments. You will help advance Zero Trust through Zero Standing Privilege (ZSP), Just-In-Time (JIT) access, least privilege, Role Based Access Controls (RBAC), Conditional Access, and modern authentication technologies. This role works closely with Security Operations, Governance Risk & Compliance, Infrastructure, Cloud, Application Development, Service Desk, and enterprise identity architecture teams.\nThis position is located onsite in Cary, NC and required to be in the office 3 days per week. We are hybrid, in office Tuesday/Wednesday/Thursday.\n What You Can Offer Us\nDesign, implement, and support enterprise Identity Access Management (IAM) and Privileged Access Management (PAM) solutions across cloud, on-premises, and hybrid environments. \nEngineer privileged access capabilities including credential vaulting, password rotation, session management, privileged account onboarding, break-glass access, and account lifecycle management. \nAdvance ZSP, JIT access, least privilege, privileged access reduction, and RBAC initiatives. \nImplement and support Microsoft Entra ID capabilities including Conditional Access, Privileged Identity Management (PIM), multi-factor authentication (MFA), Identity Protection, password less authentication, and access security controls. \nDesign and support application access management, single sign-on (SSO), federation, and modern authentication integrations using Security Assertion Markup Language (SAML), Open Authorization version 2.0 (OAuth 2.0), Open ID Connect (OIDC), Lightweight Directory Access Protocol (LDAP), and directory services. \nSecure privileged users, administrative accounts, service accounts, application identities, machine identities, agentic identities, and other non-human identities. \nPartner with infrastructure, cloud, application, and platform teams to onboard systems, applications, servers, databases, endpoints, and cloud resources into PAM and identity security platforms. \nDevelop and maintain privileged access standards, administrative access models, engineering runbooks, operational procedures, and Zero Trust access control patterns. \nAutomate identity and privileged access processes using PowerShell, Python, REST APIs, workflow orchestration, and platform integrations. \nTroubleshoot IAM and PAM platform issues, perform root cause analysis, and implement corrective actions to improve reliability and operational stability. \nCollaborate with Security Operations to investigate identity-related incidents, privileged access risks, control gaps, and suspicious activity involving high-risk identities. \nCommunicate identity security risks, technical recommendations, and remediation plans to cross-functional teams, senior management, and business stakeholders. \nOther duties as assigned. \n What You Need to Succeed\nBachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent combination of education and experience is required.\n3+ years of experience designing, implementing, and supporting IAM, PAM, and/or identity security solutions in large enterprise environments required.\n2+ years of confident hands-on experience administering CyberArk Privilege Cloud, CyberArk PAM, Delinea, BeyondTrust, and/or comparable PAM platforms highly preferred.\nDemonstrated ability to own and improve ZSP, JIT access, least privilege, RBAC, break-glass access, and privileged access reduction capabilities.\nStrong working knowledge of Microsoft Entra ID, Conditional Access, PIM, MFA, Identity Protection, directory services, and modern authentication controls.\nConfident understanding of SSO, federation, authentication, and authorization technologies such as SAML, OAuth 2.0, OIDC, LDAP, Active Directory, and cloud identity platforms.\nCapable of owning automation or integration work using PowerShell, Python, REST APIs, workflow automation, or similar scripting technologies is preferred.\nProven ability to assess identity security risks, identify control gaps, recommend practical remediation, and communicate clearly with technical and non-technical stakeholders.\nStrong judgment, ownership mindset, sense of urgency, customer focus, business integrity, and ability to prioritize work in a fast-paced environment.\nApproximately 5% travel may be required in support of the position’s responsibilities.","description_format":"text","description_chars":4757,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Telecommunications"],"lifecycle":[{"event":"open","at":"2026-10-01T22:36:32Z"}],"visa":[{"country":"US","licensed_sponsor":true,"evidence":"H-1B filings in 12 months: 20 · green card filings: 9","filings_12m":20,"filings_prev_12m":18,"green_card_filings_12m":9,"median_offered_wage_usd":150259,"route":null,"cap_exempt":false,"checked_at":"2026-10-03T21:08:04+00:00","sources":["US Department of Labor: LCA disclosure data (H-1B, H-1B1, E-3)","US Department of Labor: PERM disclosure data (green cards)"],"filings_for_role_12m":4}],"liveness":{"score":57,"band":"ok","label":"Likely open","p_open":1,"p_active":0.755,"p_room":0.75,"age_days":40,"expected_fill_days":49,"reasons":["conf:1","win:late"],"computed_at":"2026-10-05T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/american-tower-identity-security-engineer","json_url":"https://alion.io/job/american-tower-identity-security-engineer.json","meta":{"generated_at":"2026-10-06T01:32:36Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2154,"day_limit":5000,"remaining_today":2846,"minute_limit":60,"resets_at":"2026-10-07T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":176038},"rest":"https://alion.io/mcp/rest/get_company?id=176038"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Famerican-tower-identity-security-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Famerican-tower-identity-security-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Famerican-tower-identity-security-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/american-tower-identity-security-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Famerican-tower-identity-security-engineer"}]}