Corporate IT Security Engineer
Job description
About the role
Northwood is developing advanced communication technology to bring the benefits of space to a wider audience. We are building a global network of ground stations for reliable satellite communication. This role involves designing and implementing identity architecture to secure access to corporate systems and sensitive government workloads. You will own the end-to-end identity and access management lifecycle, translating complex compliance mandates into secure, auditable technical controls. You will serve as the technical authority for identity strategy, ensuring that authentication, authorization, and session management align with stringent government requirements. You will partner closely with engineering and product teams to embed security into the development lifecycle without impeding delivery. You will drive standardization across the organization by creating reusable patterns for identity and access management. You will anticipate future security risks and architect resilient solutions that scale with our expanding infrastructure.
Key facts
- Define role taxonomies and access review processes to meet CMMC, FedRAMP, and NIST 800-171 requirements.
- Conduct periodic access reviews and validate entitlements with system owners.
- Document access controls, role definitions, and provisioning procedures for compliance.
- Enforce segregation of duties and address access conflicts.
- Architect and manage a unified Mobile Device Management (MDM) solution for various operating systems.
- Establish and maintain OS hardening benchmarks and enforce them via MDM policies.
- Lead SSO onboarding for new applications, ensuring adherence to security policies.
- Evaluate and enforce SAML, OIDC, and OAuth 2.0 standards for integrated applications.
- Collaborate with the Security Engineering Lead on Okta log ingestion and identity-based alerting.
- Support the integration of identity controls with endpoint management platforms.
- Design and maintain privileged access management for administrative and service accounts.
- Define service account governance standards, including credential rotation and audit logging.
- Work with the Product Security Lead on secrets management integration.
- Ensure IAM environment compliance with CMMC Level 2, FedRAMP, SOC 2, and ITAR.
- Partner with the GRC Lead for audit activities and remediation.
- Collaborate with network engineering on identity-aware network access controls.
- Maintain IAM architecture documentation, including data flow diagrams and access control matrices.
What you'll do
You will own the design, implementation, and operation of identity and access management controls across global satellite communication infrastructure. You will define and enforce role taxonomies, access review cadences, and certification workflows to satisfy CMMC, FedRAMP, and NIST 800-171 mandates. You will conduct periodic access reviews, validate entitlements with system owners, and document controls, role definitions, and provisioning procedures to ensure auditability. You will enforce segregation of duties and resolve access conflicts to maintain least-privilege and compliance. You will architect and manage a unified Mobile Device Management solution across macOS, Windows, Linux, iOS, and Android, establishing and maintaining OS hardening benchmarks enforced through MDM policies. You will lead SSO onboarding for new applications, ensuring policy adherence and evaluating SAML 2.0, OIDC, and OAuth 2.0 integrations. You will collaborate with the Security Engineering Lead on Okta log ingestion and identity-based alerting, and support integration of identity controls with endpoint management platforms. You will design and maintain privileged access management for administrative and service accounts, define service account governance standards including credential rotation and audit logging, and work with the Product Security Lead on secrets management integration. You will ensure the IAM environment remains compliant with CMMC Level 2, FedRAMP, SOC 2, and ITAR, and partner with the GRC Lead on audit activities and remediation. You will collaborate with network engineering on identity-aware network access controls and maintain IAM architecture documentation, including data flow diagrams and access control matrices.
Requirements
- 3+ years of hands-on IAM engineering experience, specifically with Okta administration in a production setting.
- Deep expertise in Okta, including SSO, lifecycle management, MFA, adaptive authentication, Workflows, and SIEM integration.
- Strong understanding of SSO protocols (SAML 2.0, OIDC, OAuth 2.0) and experience troubleshooting integrations.
- Experience designing and implementing RBAC frameworks, including role taxonomy and access certification.
- Familiarity with privileged access management concepts like service account governance and least-privilege enforcement.
- Understanding of IAM requirements within government compliance frameworks, such as NIST 800-171.
- Experience integrating identity platforms with endpoint management, cloud environments, and security monitoring tools.
- Ability to obtain and maintain a TS/SCI clearance.
- U.S. citizenship or lawful permanent resident status is required due to ITAR regulations.
Nice to have
- Active TS clearance or higher.
- Experience operating Okta in AWS GovCloud or Microsoft GCC environments.
- Familiarity with Okta Identity Governance (OIG) or similar IGA platforms.
- Experience with Cloudflare Zero Trust access policies and Okta integration.
- Hands-on experience with privileged access management platforms like CyberArk or BeyondTrust.
- Background in aerospace, defense, critical infrastructure, or other regulated environments.
- Experience supporting CMMC, FedRAMP, or SOC 2 audits in an IAM engineering capacity.
- Okta Certified Administrator, Okta Certified Professional, or equivalent identity platform certification.
- CISSP, CISM, or equivalent professional security certification.
Skills & tools
- Okta
- SAML 2.0
- OIDC
- OAuth 2.0
- RBAC
- MDM (macOS, Windows, Linux, iOS/Android)
- SIEM
- CMMC
- FedRAMP
- NIST 800-171
- SOC 2
- ITAR
- AWS GovCloud
- Microsoft GCC
- Cloudflare Zero Trust
- CyberArk
- BeyondTrust
Practical notes
- Obtaining and maintaining a Top Secret Security Clearance is a condition of employment. The application process should be initiated promptly upon accepting an offer.
- To comply with U.S. Government export regulations (ITAR), applicants must be a U.S. citizen, lawful permanent resident, protected individual, or eligible to obtain required authorizations.