EngineerJobs.io
← Back to all jobs

Job Description

Cognizant is seeking a Lead Identity Security Engineer to help drive enterprise Identity Security initiatives from strategy through implementation. Based onsite in New York, NY, this role leads architecture and engineering efforts across IGA, ITDR, PAM, and policy-based access control capabilities, with a focus on integration, monitoring, and operational readiness.

In this position, you will provide technical leadership for identity security platforms, including SailPoint Identity Security Cloud and CrowdStrike Identity Protection, while building identity risk signal integrations and identity-centric detection and response workflows.

Key Responsibilities

  • Lead enterprise Identity Security initiatives across IGA, ITDR, PAM, and Policy-Based Access Control (PBAC).
  • Define and execute Identity Security strategy, roadmap, architecture, and implementation approach aligned with business and security objectives.
  • Provide architectural oversight and technical leadership for SailPoint Identity Security Cloud, CrowdStrike Identity Protection, and related Identity Security platforms.
  • Design and implement identity risk signal integrations across SailPoint ISC, CrowdStrike Identity Protection, Active Directory, Microsoft Entra ID, PAM solutions, and existing security platforms.
  • Develop and operationalize identity threat detection and response capabilities to identify account compromise, privilege escalation, lateral movement, insider threats, and credential abuse.
  • Lead detection engineering, including use case design, correlation logic, monitoring content development, alert tuning, and optimization.
  • Drive SIEM integrations to improve identity-centric threat analytics, monitoring, dashboards, and threat-hunting capabilities.
  • Establish workflow automation, orchestration, and response mechanisms to accelerate identity-related incident remediation.
  • Lead PBAC model implementation, access governance frameworks, entitlement management, and risk-based access controls.
  • Oversee PAM onboarding, integration, governance, monitoring, and operational processes for enterprise privileged accounts.
  • Partner with executive stakeholders and governance forums to deliver program updates, risk visibility, and strategic guidance.
  • Create operational runbooks and playbooks, maintain architecture documentation, develop testing plans, and deliver transition-to-support materials.

Required Qualifications

  • 8+ years of experience in Identity & Access Management (IAM), Identity Governance, Cybersecurity Architecture, or Identity Security Engineering.
  • Deep expertise in SailPoint Identity Security Cloud (ISC) implementation, integration, governance, and access lifecycle management.
  • Hands-on experience with CrowdStrike Identity Protection, ITDR capabilities, and identity risk monitoring.
  • Strong understanding of Privileged Access Management, including CyberArk, BeyondTrust, Delinea, or equivalent PAM solutions.
  • Experience implementing identity security controls using SAML, OAuth 2.0, OpenID Connect (OIDC), SCIM, and modern federation protocols.
  • Expertise in identity threat detection, incident response, threat hunting, and security monitoring use case development.
  • Experience integrating IAM, IGA, PAM, Active Directory, Entra ID, and SIEM platforms in enterprise environments.
  • Knowledge of policy-based access control, role management, identity governance, and compliance requirements.
  • Experience working in Agile delivery environments and leading cross-functional security transformation initiatives.
  • Excellent stakeholder management, executive communication, technical leadership, and governance experience.
  • Relevant certifications in SailPoint, CyberArk, SC-300, CISSP, CISM, or equivalent identity and security technologies are highly desirable.

Technologies

  • SailPoint Identity Security Cloud (ISC)
  • CrowdStrike Identity Protection
  • Privileged Access Management (CyberArk)
  • BeyondTrust
  • Delinea
  • SAML
  • OAuth 2.0
  • OpenID Connect (OIDC)
  • SCIM
  • Active Directory
  • Microsoft Entra ID
  • SIEM
  • CyberArk
  • SC-300
  • CISSP
  • CISM

Compensation

The annual salary range for this position is USD 114,500 - 134,000, depending on experience and other qualifications. This role is also eligible for Cognizant’s discretionary annual incentive program, subject to the terms of applicable plans.

Benefits

  • Medical/Dental/Vision/Life Insurance
  • Paid holidays plus Paid Time Off
  • 401(k) plan and contributions
  • Long-term/Short-term Disability
  • Paid Parental Leave
  • Employee Stock Purchase Plan

Application deadline: 30 Sep 2026.

Similar Jobs