|
Job Description
Role: Cyber Security Engineer Location: Onsite in Plymouth, MN Salary: $90,000 - $110,000
About the Role This is a confirmed, full-time opening on a cybersecurity team at our client, operating under one shared IT and security umbrella — that is currently rebuilding. The role is based onsite at the Plymouth, MN headquarters, supporting a workforce distributed across the US and internationally. As the team works to move from fully manual identity administration toward a more mature, tool-supported model, the Cyber Security Engineer will take the lead on designing and implementing role-based access control (RBAC) across both on-premises Active Directory and Microsoft Entra ID (Azure AD), laying the groundwork for a future IAM platform. The environment spans two distinct business entities, and the ideal candidate is comfortable operating across both — understanding how policies, risk, and configuration needs differ between them, much like working at a managed services provider supporting multiple separate clients.
Responsibilities - Design, build, and continuously improve a role-based access control (RBAC) framework spanning on-premises Active Directory and Microsoft Entra ID (Azure AD).
- Manage day-to-day hybrid identity operations, including manual provisioning/deprovisioning, until an IAM platform is adopted.
- Help evaluate and plan for a future IAM tool implementation, contributing engineering-level input on architecture and rollout.
- Partner with stakeholders across two distinct business entities, understanding each one's specific security posture, policies, and requirements.
- Contribute to broader security engineering work, including security architecture, process improvement, and policy development.
- Support and help mentor contract/admin-level team members as the cybersecurity team rebuilds.
- Participate in incident response, vulnerability management, and other security engineering functions as needed.
Requirements - Demonstrated experience with Active Directory and Azure AD/Entra ID administration and engineering in a hybrid (on-premises plus cloud) identity environment.
- Experience designing or implementing role-based access control (RBAC) frameworks.
- Strong understanding of identity and access management best practices.
- Comfortable working across multiple business entities or client environments with differing security requirements — MSP-style experience is valued.
- Bachelor's degree in a related field or equivalent practical experience.
- Able and willing to work onsite at the Plymouth, MN headquarters; this role is not hybrid or remote.
Preferred Qualifications - Hands-on experience implementing or administering an IAM platform (e.g., SailPoint, Okta, or similar).
- Relevant certifications (e.g., CISSP, Security+, or similar).
- Experience operating effectively on a lean or short-staffed security team, with the ability to work independently.
|