Leidos logo
Leidos

Leidos is an innovation company rapidly addressing the world’s most vexing challenges in national security and health.

Access Control Specialist - Senior

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 10,001+Since 1969H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

5 days ago

Salary

$73.5K - $132.8K / year

Seniority

Senior

Job Description

Access Control Specialist - Senior

Leidos

Role Description The Access Control Specialist - Senior serves as the senior identity and access management authority supporting the SEC ISS contract and SEC OIT enterprise infrastructure. This role is responsible for securing and governing access across hybrid environments, with primary focus on Microsoft Entra ID, Active Directory, Microsoft 365 GCC services, and Azure resources. The position leads implementation and enforcement of RBAC, conditional access, MFA, and identity governance controls aligned with SEC security requirements and zero-trust objectives in the PWS. The role also ensures compliant, reliable access for collaboration and enterprise broadcast capabilities in Microsoft Teams. Primary Responsibilities - Identity and Access Governance - Serve as the senior technical lead for enterprise identity and access control strategy, standards, and operating procedures. - Develop and enforce IAM policies for user lifecycle management, role assignment, and privileged access. - Define and maintain RBAC models, access approval workflows, and least-privilege controls across enterprise platforms. - Partner with cybersecurity and infrastructure leadership to reduce identity risk and strengthen control enforcement. - Access Administration and Security Enforcement - Administer user accounts, groups, permissions, and security roles across Windows Server, Active Directory, Microsoft Entra ID, Microsoft 365, and Azure. - Configure and manage conditional access policies, multifactor authentication (MFA), privileged identity controls, and identity governance workflows. - Support joiner/mover/leaver processes, including provisioning, deprovisioning, access reviews, and entitlement management for workforce and service accounts. - Integrate access control requirements with enterprise applications and collaboration platforms, including Teams and SharePoint. - Compliance, Audit, and Reporting - Conduct periodic access audits and certification reviews to validate policy compliance and control effectiveness. - Produce audit-ready reports, evidence, and metrics to support organizational and regulatory compliance requirements. - Track and remediate identity and access findings, including policy exceptions and control gaps. - Maintain documentation and SOPs for IAM processes, technical baselines, and change history. - Collaboration Platform and Broadcast Access Support - Ensure secure permissions and role assignments for Microsoft Teams conferencing, live events, and enterprise broadcasts. - Troubleshoot access-related issues impacting Teams meetings, live streaming, and collaboration workloads. - Coordinate with operations, service delivery, and security teams to resolve escalated IAM incidents. - Support continuous service improvement through automation and standardized IAM operating practices. Qualifications - Citizenship/Work Authorization: Must meet contract requirements. - Clearance: Ability to obtain and maintain SEC Public Trust (or higher if required). - Education: Bachelors. - Experience: - 8+ years of experience in access control and identity management within enterprise IT environments. - Extensive hands-on experience administering Microsoft Entra ID (formerly Azure Active Directory), including user provisioning, RBAC, conditional access policies, and identity governance. - Strong experience managing identity and access across Windows Server, Active Directory, Microsoft 365 services, and Azure resources. - Experience supporting compliance audits and secure access controls for Microsoft Teams live events and enterprise broadcasts. - Technical Skills: - Microsoft Entra ID (Azure AD), Entra ID Governance, and enterprise identity lifecycle management. - Role-Based Access Control (RBAC), least-privilege enforcement, and access certification. - Conditional Access, MFA, and identity governance policy administration. - Windows Server and Active Directory administration. - Microsoft 365 services, including Teams and SharePoint access controls. - Azure resource access management and security role administration. - IAM compliance auditing, reporting, and control documentation. - Troubleshooting access and authentication issues in enterprise collaboration platforms. Preferred Qualifications - Experience supporting IAM operations in a federal IT environment with FISMA-driven audit and control requirements. - Experience implementing zero-trust identity controls and modern authentication across hybrid enterprise environments. - Advanced experience with privileged identity management, access reviews, and entitlement management at scale. - Experience automating IAM workflows using scripting and enterprise automation tools. - Experience implementing federated identity and single sign-on integrations for enterprise applications. - Microsoft Certified: Identity and Access Administrator Associate (SC-300). - Microsoft Certified: Cybersecurity Architect Expert (SC-100). - CISSP. Work Environment / Other - Operational Support: May require participation in on-call or surge support activities depending on operational needs. - Location: Telework. - Travel: As required per contract direction. If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares. Original Posting: May 22, 2026 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above. Pay Range: $73,450.00 - $132,775.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Related Categories

Related Job Pages

More Security Engineer Jobs

Game Plan Tech logo

Information System Security Manager – ISSM

Game Plan Tech

Mission-driven engineering firm helping government teams innovate.

Full TimeRemoteTeam 51-200Since 2023H1B No Sponsor

• Own the full RMF lifecycle from system categorization through ATO and continuous monitoring • Author and maintain SSPs, POA&Ms, SARs, and SCTM documentation • Coordinate with government AOs, SCAs, and ISSOs across programs • Manage NIST SP 800-53 control implementation, testing, and evidence collection • Govern the security posture of AI and ML systems operating within classified enclaves • Assess novel risks introduced by LLMs and agentic workflows in DoW environments • Apply DISA STIGs and DoW cloud SRG requirements across IL4–IL6 deployments • Support JSIG and ICD 503 requirements where SAP/SCI accreditation applies • Interpret evolving guidance — CMMC 2.0, NSM-8, DoW AI Ethics Principles — and translate into action before it becomes mandatory • Define security approval pathways for AI tools where none yet exist • Build lightweight security review processes that enable engineering teams rather than blocking them • Serve as the primary liaison with government ISSOs, AOs, and DCSA representatives • Communicate risk clearly to non-security audiences including engineers and program leads • Mentor junior ISSOs and build security-awareness culture across the organization

United States
ContractRemoteTeam 11-50H1B No Sponsor

• Design, deploy, and manage enterprise network security solutions • Configure and administer Fortinet, SonicWall, and Palo Alto firewalls • Implement and maintain VPNs, IPS/IDS, web filtering, NAT, ACLs, and segmentation policies • Monitor security events using SIEM, XDR, and SOC monitoring platforms • Investigate security incidents, perform threat analysis, and support incident response activities • Manage firewall policies, security rules, and compliance controls • Implement Zero Trust Network Access (ZTNA) and identity-based security controls • Support cloud security initiatives across AWS, Azure, and hybrid infrastructure • Configure and support SD-WAN and Secure Access Service Edge (SASE) solutions • Conduct vulnerability assessments and remediation activities • Collaborate with infrastructure, cloud, and application teams to secure enterprise environments • Maintain security documentation, diagrams, SOPs, and audit records • Participate in on-call rotations and critical incident handling

India
CrowdStrike logo

Senior Product Security Engineer – Network and Infrastructure

CrowdStrike

CrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?

Full TimeRemoteTeam 5,001-10,000Since 2011H1B Sponsor

• Develop and maintain a comprehensive understanding of CrowdStrike's hybrid networks spanning public cloud (AWS, GCP, Azure) and physical data centers, continuously assessing attack surface and identifying security gaps. • Design and architect new network connection patterns and zone segmentation strategies that reduce risk while enabling product scalability. • Build scalable monitoring, alerting, and automation solutions targeting network security risks across a fast-moving, dynamic environment. • Lead threat modeling efforts focused on network architecture, data flows, and connectivity patterns across platform services. • Evaluate current threat landscape and business priorities to effectively sequence and drive the highest-impact security improvements. • Lead complex, cross-team security initiatives with broad impact across the product group. • Contribute to medium-term strategic direction for network security; proactively identify areas of greatest need and develop actionable plans to address them. • Provide architectural and design expertise that accounts for the broader platform picture, not just point-in-time solutions. • Serve as an internal authority on network security architecture within CrowdStrike's product organization. • Volunteer for and lead working groups and initiatives that have impact at the Product team level or broader industry level. • Partner closely with product engineering, infrastructure, and platform teams to understand scaling requirements and translate them into secure-by-design network architectures. • Work across organizational boundaries to facilitate alignment on security requirements, driving consensus on complex and ambiguous problems. • Clearly communicate decisions and architectural direction to both technical and non-technical stakeholders once alignment is reached. • Serve as a role model for security culture and best practices within your functional area. • Multiply the effectiveness of the broader team by facilitating cross-team knowledge sharing and collaboration. • Guide and develop technical talent through coaching, code reviews, and architectural deep-dives. • Contribute to the growth of the security organization by mentoring team members and helping refine technical interviewing standards.

United States
$160K - $250K / year
Voltus logo

Security Engineer

Voltus

Better Energy, More Cash.

Full TimeRemoteTeam 201-500H1B Sponsor

• Build detections and security signal pipelines in Datadog. • Serve as the subject matter expert on AWS Cloud and on-prem infrastructure security. • Define and set up AWS and on-prem Security Monitoring/Best Practices Strategy. • Act as the technical lead during security incidents, including investigation and remediation. • Improve Terraform Modules and Infrastructure as Code (IaC) to follow security best practices. • Develop and implement a vulnerability monitoring strategy and integrate it into CI/CD pipelines. • Build security automation using Python, scripting, and APIs. • Partner with Infrastructure on AWS security engineering, including IAM, KMS, and network segmentation. • Operate SOC 2 Type 2 evidence collection and audit response. • Drive ISO 27001 implementation work, including risk assessments and control mapping. • Ensure infrastructure compliance with regulatory requirements. • Run vendor and subprocessor risk reviews. • Respond to customer security questionnaires and external inquiries. • Mentor and enable other team members to improve their security posture.

United States
$140K - $160K / year