The Senior Identity Security Engineer is responsible for designing, implementing, and governing enterprise identity and access management capabilities aligned with cybersecurity risk management objectives, the Microsoft Cybersecurity Reference Architecture (MCRA), and Zero Trust principles. The role serves as a senior technical authority for identity security across on-premises, cloud, and hybrid environments, with an initial focus on Microsoft Entra ID and Active Directory. It defines how authentication, authorization, privileged access, identity governance, and identity threat detection capabilities are designed and secured. It partners with Identity Administration, Cybersecurity Operations, infrastructure, application, governance, compliance, and business teams to establish scalable identity services that protect S&C and customer information while supporting reliable business operations.
Hours
- 8:00 am – 5:00 pm- Remote (Chicago, IL)
Compensation
At S&C, we are dedicated to providing competitive and equitable compensation for all our team members, and we are committed to transparency in our pay practices. The estimated annual base salary range for this position is $128,090 - $169,716.60 Individual pay within this salary range is determined by several compensable factors, including performance, knowledge, job-related skills and experience, and relevant education or training. This role is also eligible for S&C’s annual incentive plan (AIP), subject to eligibility criteria.
Join Our Team as a Lead Identity Security Engineer
Essential Functions:
Identity Strategy, Architecture, and Standards:
Define and maintain the identity security strategy, reference architectures, technical standards, and roadmap aligned with MCRA, Zero Trust, cybersecurity risk priorities, and business needs.
- Design secure, scalable identity and access management solutions across on-premises, cloud, and hybrid environments, with clear separation between governance, engineering, administration, and monitoring responsibilities.
- Govern the identity architecture and control posture for Microsoft Entra ID, Active Directory, cloud synchronization, and related identity services
- Architect authentication and authorization capabilities, including SSO, federation, MFA, passwordless authentication, Conditional Access, session controls, and risk-based access.
- Design privileged access controls, including PIM/PAM, just-in-time access, administrative tiering, emergency access, service-account governance, and least-privilege operating models.
- Develop role-based and attribute-based access models, segregation-of-duties controls, entitlement standards, and secure access patterns for enterprise applications and platforms.
- Lead identity lifecycle and governance improvements, including joiner-mover-leaver processes, provisioning and deprovisioning automation, SCIM integrations, access reviews, recertification, guest access, and non-human identity governance.
- Partner with Identity Administration on implementation and operational execution while maintaining architecture, standards, and control design ownership within Identity Engineering.
- Participate in security architecture, project, and change reviews to ensure identity security requirements are designed into new applications, platforms, and business processes.
- Engineer identity threat detection and response enablement, including log architecture, telemetry collection, detection content, analytics, dashboards, and integrations across Defender for Identity, Sentinel, SIEM/SOAR, PAM, and related platforms.
- Build and tune identity detections and response automation with Cybersecurity Operations, which owns continuous monitoring, investigation, escalation, and incident response.
- Assess identity risk by analyzing authentication patterns, risky identities, privileged-access exposure, stale or orphaned accounts, control exceptions, and detection coverage; translate findings into practical remediation plans.
- Define identity metrics, reporting, and evidence standards that demonstrate control effectiveness, governance performance, risk reduction, and roadmap execution for audit, compliance, client assurance, and cyber insurance needs.
- Evaluate identity and ITDR technologies, lead proofs of concept and vendor assessments, and drive initiatives from strategy through implementation and transition to operations.
- Develop and maintain architecture diagrams, standards, control designs, implementation guidance, operating procedures, and playbooks; provide technical leadership and mentorship across IT.
Protect Firm and client information by complying with information security policies, exercising sound judgment, and promptly reporting security events, control failures, or material risks.
-
Skills, Knowledge & Experience:
6 to 10 years of progressive experience in identity and access management, identity security engineering, security engineering, or a closely related discipline.
Demonstrated experience serving as a senior technical lead for enterprise identity initiatives, including hands-on delivery in complex Microsoft identity environments
Deep knowledge of identity security architecture and engineering across Microsoft Entra ID, Active Directory, and hybrid identity environments.
Advanced experience with MFA, SSO, federation, Conditional Access, PIM/PAM, RBAC/ABAC, identity lifecycle governance, access reviews, and least-privilege design.
Demonstrated ability to design enterprise identity controls while preserving clear boundaries between architecture and governance, platform administration, and security monitoring.
Experience engineering identity security telemetry and detection capabilities, including Entra ID and Active Directory logging, Microsoft Defender for Identity, Microsoft Sentinel or comparable SIEM, SOAR automation, and identity analytics.
Strong understanding of identity attack paths and common threats, including credential theft, token abuse, privilege escalation, lateral movement, legacy authentication, excessive privilege, and persistence through identity systems.
Proficiency with automation and integration technologies such as PowerShell, Python, Microsoft Graph and other APIs, infrastructure-as-code, and structured data formats.
Ability to translate cybersecurity risk and technical complexity into clear standards, decisions, roadmaps, and executive-ready communications.
Proven ability to lead complex cross-functional initiatives, influence without direct authority, manage competing priorities, and drive issues through resolution.
High degree of discretion, integrity, attention to detail, and commitment to client service and professional excellence.
Preferred
Experience in a global, highly confidential, regulated, manufacturing, or professional-services environment.
Working knowledge of cloud security, networking, PKI and certificates, application architecture, and security operations, supported by strong analytical, troubleshooting, documentation, presentation, and stakeholder-management skills.
- Microsoft Certified: Identity and Access Administrator Associate (SC-300), Azure Security Engineer Associate, or comparable Microsoft identity certification (within 6 mos)
CISSP, CISM, CCSP, or a comparable information security certification
-
Education:
Required
- Bachelor’s degree in Cyber Security, Information Systems Management, Computer Science, Computer Engineering, Cloud Security or equivalent experience.
Certifications & Licenses:
Preferred
Advanced certification in a relevant PAM, IGA, ITDR, SIEM/SOAR, or cloud platform is a plus
No fixed deadline
#LI-KD1
In 1909, S&C Electric Company transformed the delivery of safe, reliable electricity with the invention of the Liquid Power Fuse. Today, as the world faces extreme weather events and the demand for electricity grows, S&C continues to innovate and advance the electrical grid, ensuring reliable and resilient power for homes, communities, and critical infrastructure around the world.
With a diverse, global workforce and core values around integrity, safety, and quality, S&C is a trusted industry leader and top workplace that offers meaningful careers to more than 3,500 team members. As a people-first organization, S&C is committed to fostering an inclusive and collaborative workplace where team members advance their careers through robust talent-development programs and involved leadership.
S&C’s deeply rooted belief diversity fosters greater creativity, innovation, and success guides the company to advance and sustain a diverse, equitable, and inclusive workplace culture.
S&C provides a comprehensive and competitive benefit package that includes the following (eligibility requirements apply):
- Health and Welfare Benefits: Medical & Prescription, Dental, Vision, Health Care and Dependent Care Flexible Spending Accounts, , Health Savings Account (HSA), Group Life Insurance, optional Supplemental Life and AD&D Insurance, Wellbeing Resources including Employee Assistance Program and Family Forming Benefits (i.e., Adoption and Fertility support)
- Leave Benefits: Vacation Time, Sick Time, Paid Holidays and Company Shutdown days, Short-Term Disability, Long-Term Disability, Other Leaves, Paid Parental Time and Military Leave
Retirement Benefits: 401(k) Retirement Savings and Employee Stock Ownership Plan (KSOP) offering traditional and Roth 401(k) options and an Employee Stock Ownership Plan (ESOP) component; KSOP participants can receive annual ESOP company contributions of over 11% of eligible earnings (3% Core, up to 3.5% Match, Variable Periodic).