CareerMoonshot

Identity and Access Security Engineer

Brown Advisory · Maryland

📍 Baltimore, MDvia workdayFirst listed here 2026-09-24
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Brown Advisory.
Company Overview Every firm has a culture – the values, beliefs, methodology, attitudes and standards that reflect an organization’s DNA. But the truly inspiring firms – the game-changers, the industry leaders and the disruptors – have cultures that propel them to innovate and stand out. At Brown Advisory, we aim to be one of those inspired firms. Over the years, we have purposefully built and nurtured our client-first culture. Brown Advisory is an independent investment management and strategic advisory firm committed to delivering a combination of first-class performance, strategic advice and the highest level of client service. The firm’s clients—including individuals, families, family offices, endowments, foundations, charities, institutions, consultants, and financial intermediaries—are served by over 1,000 colleagues worldwide, all of whom are equity owners of the firm. Brown Advisory is currently seeking an Identity and Access Security Engineer to lead and mature the firm's identity security controls across Okta, Microsoft Entra ID, Active Directory, CyberArk, BloodHound Enterprise, multifactor authentication, privileged access, application integrations, and access governance. This blended role is designed for a hands-on security professional who understands identity as both a business-enablement workflow and a critical security control plane. The engineer will be responsible for reducing identity-related risk across workforce, privileged, service, application, and machine identities. The role combines identity engineering, privileged-access management, identity threat exposure management, access governance, attack-path remediation, and operational control assurance. As part of a lean Information Security team within a mid-sized financial services organization, this individual will partner with Infrastructure, Enterprise Applications, Compliance, Human Resources, Operations, and business system owners. The role will help ensure that access is appropriately granted, reviewed, monitored, and removed while enabling secure adoption of SaaS, cloud, and on-premises platforms. Blended Role Coverage Primary emphasis: Identity security engineering and governance across IAM, PAM, identity threat exposure management, MFA, privileged access, access reviews, and identity-related risk. Blended coverage: Okta and Entra ID integration, CyberArk platform operations and privileged-account onboarding, service-account governance, BloodHound Enterprise analysis and attack-path remediation, Active Directory privilege hygiene, SaaS access controls, identity lifecycle automation, and selected security-engineering support. Duties and Responsibilities Own the day-to-day security governance and engineering of identity controls across Okta, Microsoft Entra ID, Active Directory, MFA, Conditional Access, privileged access, and identity lifecycle workflows. Design, implement, operate, and continuously improve privileged-access controls using CyberArk, including account discovery, vault onboarding, credential rotation, access workflows, session controls, privileged-account monitoring, break-glass access, and evidence collection. Govern the lifecycle of privileged human and non-human identities, including administrator accounts, service accounts, application credentials, scheduled-task accounts, emergency accounts, and other machine identities. Identify privileged and service accounts that are unmanaged, improperly configured, inactive, or outside established CyberArk controls, and coordinate their onboarding, remediation, or retirement. Develop and maintain CyberArk safes, platforms, policies, account ownership models, reconciliation processes, access permissions, operational procedures, and recovery documentation. Operate BloodHound Enterprise as an identity threat exposure management capability, analyzing attack paths, Tier Zero relationships, excessive privilege, nested group membership, delegated permissions, and other identity-control weaknesses. Translate BloodHound findings into prioritized and actionable remediation plans, working with Infrastructure and application owners to remove unnecessary privilege while preserving required business and system functionality. Validate identity-risk remediation through rescanning, attack-path analysis, ticket evidence, exception documentation, and measurable reduction in identity exposure. Maintain a defined Tier Zero and critical-identity model across Active Directory, Entra ID, privileged platforms, administrative systems, and supporting infrastructure. Assess and improve Active Directory security, including privileged groups, delegated administrative rights, nested group relationships, service accounts, stale privileges, domain and forest trust exposure, and administrative-tier separation. Partner with Infrastructure to reduce standing privilege and implement secure administrative patterns for domain, server, workstation, application, and help-desk administration. Integrate applications with Okta and Entra ID using secure authentication, authorization, SSO, provisioning, deprovisioning, and lifecycle-management patterns. Lead access review routines for critical systems, privileged roles, SaaS platforms, and regulated business processes, ensuring exceptions are documented and remediated. Partner with HR, Compliance, Operations, and application owners to improve joiner, mover, leaver, contractor, vendor, service-account, and application-identity workflows. Strengthen identity detection and response by integrating telemetry from Okta, Entra ID, Active Directory, CyberArk, BloodHound Enterprise, and other identity systems into SIEM and investigation workflows. Support investigations involving suspicious authentication, credential misuse, privileged-account activity, unauthorized role changes, risky OAuth grants, anomalous service-account behavior, and potential identity-based lateral movement. Support security configur

More Maryland jobs

Maryland jobs · Browse all locations