The Must-Haves: Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent practical experience7+ years of progressive experience in IT and Security, including at least 3 years dedicated to IAM or security engineering in an enterprise environmentDemonstrated hands-on ownership of at least two of the following:Entra ID / Microsoft 365A PAM platformQualys or equivalent vulnerability management platformIntune / JAMF device managementHands-on expertise with identity lifecycle, RBAC design, entitlement and access certification, federation and SSO integrations, and privileged-access tooling and workflowsStrong working knowledge of Entra ID, including Conditional Access, Identity Protection, PIM, and entitlement management, plus the Microsoft 365 security and compliance stackWorking knowledge of Intune, JAMF, and Google device management, including compliance policies, configuration profiles, and application deployment across mixed operating-system environmentsStrong scripting and automation skills using PowerShell, Microsoft Graph, Python, or BashAbility to interpret NIST CSF, ISO 27001, or SOC 2 and implement the technical controls and evidence required to meet themCertifications such as SC-300, SC-200, AZ-500, CISSP, CISM, GIAC GCIA, GIAC GDSA, or relevant PAM, JAMF, or Qualys vendor certificationsAbility to travel up to 10%It is the responsibility of every position to understand and adhere to the security guidelines outlined in OnTrac's Acceptable Use policy and to conduct their activities accordingly. Identity and privileged-access engineering: Design, deploy, and maintain enterprise identity services across Entra ID and hybrid Active Directory, including SAML/OIDC federation, SSO, Conditional Access, MFA and phishing-resistant authentication, joiner/mover/leaver automation, RBAC, role and group governance, access reviews, credential vaulting, session monitoring, just-in-time elevation, tiered administration, service-account governance, and break-glass procedures.