Summary
KBR is seeking an Associate Security Engineer to join our Identity Security Services team within a global cybersecurity organization. This hands-on role focuses on identity and access management, providing opportunities to build technical expertise while supporting the administration and security of identity platforms.
Responsibilities
- Support the administration and operation of Microsoft Entra ID, Active Directory, hybrid identity, and directory synchronization services
- Perform identity administration activities for users, groups, devices, applications, service accounts, and access permissions
- Troubleshoot authentication, authorization, provisioning, account lifecycle, and access-related issues
- Review logs, alerts, and system data to identify and resolve identity-related incidents and operational problems
- Support Conditional Access, multifactor authentication (MFA), passwordless authentication, and other modern access control solutions
- Assist with privileged access management activities, including role assignments, access reviews, and least-privilege enforcement
- Support identity governance processes, including access reviews, entitlement management, and joiner, mover, and leaver activities
- Assist with enterprise application integrations and identity federation technologies, including SAML, OAuth, OpenID Connect, and SCIM
- Support application identities, service principals, managed identities, and workload identities
- Assist with Active Directory administration, Group Policy management, directory health monitoring, and hybrid identity operations
- Support PKI and certificate lifecycle management activities, including certificate issuance, renewal, inventory, and trust relationships
- Identify and help remediate identity-related risks, including excessive access, stale accounts, weak authentication, and unmanaged credentials
- Support security monitoring, threat detection, and incident investigations using Microsoft security platforms and related tools
- Gather technical evidence, perform root cause analysis, and assist with remediation activities during security and operational incidents
- Participate in cloud deployments, application onboarding, tenant migrations, and other identity-related projects and initiatives
- Support audit, compliance, and governance activities through evidence collection, documentation, and control validation
- Create and maintain technical documentation, procedures, knowledge articles, and operational runbooks
- Assist with reporting, automation, and continuous improvement efforts using PowerShell, Microsoft Graph, KQL, and related technologies
- Follow established security, change management, incident management, and operational procedures
- Collaborate with engineers, administrators, and stakeholders to improve identity security controls and operational effectiveness
- Communicate technical issues, findings, and project updates clearly while continuing to develop identity security knowledge and expertise
Skills
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related field; equivalent combination of education and professional experience may be considered
- 2+ years of experience in information technology, cybersecurity, identity administration, systems administration, cloud support, service desk support, or a related technical field
- U.S. citizenship required
- Foundational understanding of information technology concepts, including user accounts, permissions, authentication, operating systems, networking, and cloud services
- Familiarity with Microsoft Windows, Microsoft 365, Active Directory, Microsoft Entra ID, Azure, or comparable enterprise technologies
- Understanding of core security principles such as least privilege, multifactor authentication, role-based access control, and identity lifecycle management
- Strong technical aptitude and ability to learn new technologies and processes quickly
- Strong troubleshooting, analytical, and problem-solving skills
- Ability to follow established procedures, security standards, and change management requirements
- Strong attention to detail and commitment to handling sensitive information responsibly
- Effective written and verbal communication skills with the ability to document technical work clearly
- Ability to collaborate within a team environment, manage assigned tasks, and escalate issues appropriately
- Demonstrated reliability, integrity, professionalism, and commitment to continuous learning
- Hands-on experience with Microsoft Entra ID, Active Directory, Azure, or Microsoft 365 administration
- Familiarity with identity and access management concepts, including authentication, authorization, provisioning, and identity governance
- Experience supporting user accounts, permissions, enterprise applications, or access management processes
- Basic experience with PowerShell, scripting, automation tools, or API integrations
- Familiarity with Microsoft Sentinel, Microsoft Defender, SIEM technologies, or security monitoring tools
- Exposure to SAML, OAuth, OpenID Connect, SCIM, LDAP, Kerberos, PKI, or certificate-based authentication
- Experience working in environments with formal change management, incident management, compliance, or audit requirements
- Industry certifications such as Microsoft Certified: Security, Compliance, and Identity Fundamentals, Microsoft Certified: Azure Fundamentals, CompTIA Security+, CompTIA Network+, or equivalent
Qualifications
Must Haves
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related field; equivalent combination of education and professional experience may be considered
- 2+ years of experience in information technology, cybersecurity, identity administration, systems administration, cloud support, service desk support, or a related technical field
- U.S. citizenship required
- Foundational understanding of information technology concepts, including user accounts, permissions, authentication, operating systems, networking, and cloud services
- Familiarity with Microsoft Windows, Microsoft 365, Active Directory, Microsoft Entra ID, Azure, or comparable enterprise technologies
- Understanding of core security principles such as least privilege, multifactor authentication, role-based access control, and identity lifecycle management
- Strong technical aptitude and ability to learn new technologies and processes quickly
- Strong troubleshooting, analytical, and problem-solving skills
- Ability to follow established procedures, security standards, and change management requirements
- Strong attention to detail and commitment to handling sensitive information responsibly
- Effective written and verbal communication skills with the ability to document technical work clearly
- Ability to collaborate within a team environment, manage assigned tasks, and escalate issues appropriately
- Demonstrated reliability, integrity, professionalism, and commitment to continuous learning
Nice to Haves
- Hands-on experience with Microsoft Entra ID, Active Directory, Azure, or Microsoft 365 administration
- Familiarity with identity and access management concepts, including authentication, authorization, provisioning, and identity governance
- Experience supporting user accounts, permissions, enterprise applications, or access management processes
- Basic experience with PowerShell, scripting, automation tools, or API integrations
- Familiarity with Microsoft Sentinel, Microsoft Defender, SIEM technologies, or security monitoring tools
- Exposure to SAML, OAuth, OpenID Connect, SCIM, LDAP, Kerberos, PKI, or certificate-based authentication
- Experience working in environments with formal change management, incident management, compliance, or audit requirements
- Industry certifications such as Microsoft Certified: Security, Compliance, and Identity Fundamentals, Microsoft Certified: Azure Fundamentals, CompTIA Security+, CompTIA Network+, or equivalent