Senior Cybersecurity Engineer (IAM)

AmentumRichmond, VA
$120,000 - $149,000Remote

About The Position

Amentum is seeking a Senior Cybersecurity Engineer with deep Identity and Access Management (IAM) expertise to protect enterprise assets across a multi-tenant, hybrid (cloud/on-premises) environment. This is a fully remote, hands-on role spanning identity security, multi-cloud security, and endpoint protection. This position is US Remote telework and US Citizenship is required.

Requirements

  • Working knowledge of Zero Trust, RBAC, and ABAC
  • Working knowledge of regulatory/compliance frameworks relevant to IAM (CMMC, NIST 800-171/800-172, or similar)
  • Understanding of network security fundamentals: boundary protection, segmentation, firewalls, endpoint security, threat hunting, data protection
  • Self-starter, strong written/verbal communication, comfortable with minimal supervision and shifting priorities
  • Ability to travel up to 10%
  • Typically, 8 years of hands-on IAM security engineering experience with a Bachelor’s degree in Computer Science, Information Systems or related field plus; 4 with Master's. IAM security engineering experiences includes implementing access controls, privileged access management, and authentication policy, rather than general user/account administration.
  • Hands-on experience securing and administering Entra ID, Okta, and Active Directory identity infrastructure in a hybrid environment
  • Solid experience in Privileged Access Management (PAM), Self-Service Password Management, and Just-In-Time (JIT) access
  • Current CISSP, CISM, or equivalent certification
  • Solid MFA and access-protection implementation experience
  • Solid Microsoft Azure/M365 experience
  • U.S. Citizen (required)

Nice To Haves

  • Experience implementing an IAM governance platform such as Saviynt, SailPoint, or similar
  • Experience supporting CMMC assessments or audits
  • Familiarity with GDPR, SOX, ISO 27001
  • Entra/Azure GCC High exposure

Responsibilities

  • Implement and operate enterprise IAM security controls across a multi-tenant/multi-domain hybrid environment spanning Entra ID, Okta, and Active Directory — including PAM, JIT access, conditional access, and MFA policy enforcement (not day-to-day user/group provisioning or account administration)
  • Execute IAM designs defined by security architecture, translating architectural standards into working security configurations, policies, and integrations
  • Maintain and enforce IAM-related security policies, standards, and best practices in alignment with regulatory and compliance requirements (CMMC, NIST 800-171/800-172, and other applicable frameworks)
  • Configure and tune identity security controls — access policies, privileged access workflows, authentication requirements — protecting users, systems, applications, and data across Entra ID, Okta, and AD environments
  • Serve as 2nd-level SOC escalation point for critical identity-related security incidents
  • Investigate identity-related security anomalies using platform reporting, network traffic, log files, and automated alerts
  • Support audit and assessment activities by maintaining compliant configurations and evidence for IAM controls
  • Automate recurring IAM security operations tasks
  • Maintain system and process documentation, including compliance-relevant control documentation
  • Provide off-hours support as needed (infrequent)
  • Cover other assignments as needed

Benefits

  • Health, dental, and vision insurance
  • Paid time off and holidays
  • Retirement benefits (including 401(k) matching)
  • Educational reimbursement
  • Parental leave
  • Employee stock purchase plan
  • Tax-saving options
  • Disability and life insurance
  • Pet insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service