American Tower Logo

American Tower

Identity Security Engineer

Posted 2 Days Ago
Be an Early Applicant
In-Office
Boston, MA, USA
Mid level
In-Office
Boston, MA, USA
Mid level
Designs, implements, and supports IAM and PAM solutions across cloud, on-premises, and hybrid environments. Engineers privileged access controls, Entra ID capabilities, authentication integrations, RBAC, Zero Standing Privilege, and Just-In-Time access. Automates identity processes, onboards systems and applications into PAM platforms, troubleshoots identity security issues, investigates risks with Security Operations, and communicates remediation plans to technical and business stakeholders.
The summary above was generated by AI

The Team

We are seeking an Identity Security Engineer to join American Tower’s Information Security organization. This role strengthens identity security, reduces privileged access risk, and enables secure access to enterprise systems, data, and cloud resources. As an Identity Security Engineer, you will engineer and support identity and privileged access solutions across cloud, on-premises, and hybrid environments. You will help advance Zero Trust through Zero Standing Privilege (ZSP), Just-In-Time (JIT) access, least privilege, Role Based Access Controls (RBAC), Conditional Access, and modern authentication technologies. This role works closely with Security Operations, Governance Risk & Compliance, Infrastructure, Cloud, Application Development, Service Desk, and enterprise identity architecture teams.

This position is located onsite in Cary, NC and required to be in the office 3 days per week. We are hybrid, in office Tuesday/Wednesday/Thursday. 

Responsibilities

What You Can Offer Us

  • Design, implement, and support enterprise Identity Access Management (IAM) and Privileged Access Management (PAM) solutions across cloud, on-premises, and hybrid environments.    
  • Engineer privileged access capabilities including credential vaulting, password rotation, session management, privileged account onboarding, break-glass access, and account lifecycle management.    
  • Advance ZSP, JIT access, least privilege, privileged access reduction, and RBAC initiatives.    
  • Implement and support Microsoft Entra ID capabilities including Conditional Access, Privileged Identity Management (PIM), multi-factor authentication (MFA), Identity Protection, password less authentication, and access security controls.    
  • Design and support application access management, single sign-on (SSO), federation, and modern authentication integrations using Security Assertion Markup Language (SAML), Open Authorization version 2.0 (OAuth 2.0), Open ID Connect (OIDC), Lightweight Directory Access Protocol (LDAP), and directory services.    
  • Secure privileged users, administrative accounts, service accounts, application identities, machine identities, agentic identities, and other non-human identities.    
  • Partner with infrastructure, cloud, application, and platform teams to onboard systems, applications, servers, databases, endpoints, and cloud resources into PAM and identity security platforms.    
  • Develop and maintain privileged access standards, administrative access models, engineering runbooks, operational procedures, and Zero Trust access control patterns.    
  • Automate identity and privileged access processes using PowerShell, Python, REST APIs, workflow orchestration, and platform integrations.    
  • Troubleshoot IAM and PAM platform issues, perform root cause analysis, and implement corrective actions to improve reliability and operational stability.    
  • Collaborate with Security Operations to investigate identity-related incidents, privileged access risks, control gaps, and suspicious activity involving high-risk identities.    
  • Communicate identity security risks, technical recommendations, and remediation plans to cross-functional teams, senior management, and business stakeholders.    
  • Other duties as assigned.    
Qualifications

What You Need to Succeed

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent combination of education and experience is required.
  • 3+ years of experience designing, implementing, and supporting IAM, PAM, and/or identity security solutions in large enterprise environments required.
  • 2+ years of confident hands-on experience administering CyberArk Privilege Cloud, CyberArk PAM, Delinea, BeyondTrust, and/or comparable PAM platforms highly preferred.
  • Demonstrated ability to own and improve ZSP, JIT access, least privilege, RBAC, break-glass access, and privileged access reduction capabilities.
  • Strong working knowledge of Microsoft Entra ID, Conditional Access, PIM, MFA, Identity Protection, directory services, and modern authentication controls.
  • Confident understanding of SSO, federation, authentication, and authorization technologies such as SAML, OAuth 2.0, OIDC, LDAP, Active Directory, and cloud identity platforms.
  • Capable of owning automation or integration work using PowerShell, Python, REST APIs, workflow automation, or similar scripting technologies is preferred.
  • Proven ability to assess identity security risks, identify control gaps, recommend practical remediation, and communicate clearly with technical and non-technical stakeholders.
  • Strong judgment, ownership mindset, sense of urgency, customer focus, business integrity, and ability to prioritize work in a fast-paced environment.
  • Approximately 5% travel may be required in support of the position’s responsibilities.
About Us
American Tower is a global digital infrastructure company serving customers through tower sites and other real estate solutions that support connectivity and opportunity, focused on achieving our vision of Building a More Connected World. Our success is rooted in the potential of our people and the power of local teams at our offices and sites across 25 countries.

We are one of the largest global Real Estate Investment Trusts (REITs) and a publicly traded (NYSE:AMT), Fortune 500 Company headquartered in Boston, Massachusetts. The next decade will be an exciting time as we evolve our infrastructure to meet tomorrow’s needs and position our people to elevate their impact, their potential, and our shared success. Come grow your career with us!

For more information about how American Tower is building a more connected world, visit americantower.com 

American Tower is proud to be an equal opportunity employer and will not discriminate against an applicant or employee based on age, sex, sexual orientation, gender identity, race, color, creed, religion, national origin or ancestry, citizenship, marital status, familial status, disability, military or veteran status, genetic information, pregnancy, reproductive decisions, or any other characteristic protected under applicable law.

American Tower is committed to fair and equitable compensation practices. Placement within the salary range is based on a variety of factors, including relevant experience, skills, certifications, job level, and location. For U.S.-based candidates only, please see the base salary range for this position listed below. This position is also eligible for annual bonus, and annual equity award and participation in the Employee Stock Purchase Plan (ESPP).  For candidates outside of the U.S., salary and benefits are based upon local market practice.

American Tower also offers a comprehensive benefits package, which includes healthcare coverage, a 401(k) savings plan, paid time off, company holidays, sick leave, parental leave, and access to an Employee Assistance Program focused on mental and financial wellness, please click here to learn more.

HQ

American Tower Boston, Massachusetts, USA Office

116 Huntington Avenue, Boston, MA, United States, 02116

American Tower Woburn, Massachusetts, USA Office

10 Presidential Way, Woburn, United States, 01801

Similar Jobs

Senior level
Consumer Web • eCommerce • Information Technology • Retail • Software • Analytics • App development
Lead technical design and implementation of enterprise information security tools and services. Provide expert guidance on identity/access and certificate management, incident response, secure coding, vulnerability assessments, remediation design, CI/CD pipeline security, and mentor engineering teams to maintain compliance and reduce risk.
Top Skills: CloudContainersContinuous Integration/Continuous DeploymentDefect/Incident TrackingDevOpsDigital Certificate ManagementIdentity And Access ManagementIncident ResponseItilScriptingSecure CodingSource Code Control
11 Days Ago
In-Office or Remote
14 Locations
86K-139K Annually
Senior level
86K-139K Annually
Senior level
Healthtech
Designs, implements, tests, and maintains enterprise IAM/SSO solutions. Troubleshoots authentication/authorization issues, integrates federation protocols (SAML/OAuth/SCIM), applies patches, trains stakeholders, and advises on IAM best practices and compliance.
Top Skills: Active DirectoryApacheC#C++CentrifyCyberarkDilineaDuoEntra IdFidoIisJavaJava BeanshellJavaScriptJbossLdapLdap V3LinuxOamOauthOidcOimOracleOracle Access ManagerPing IdentityPingone Advanced Identity CloudPowershellPythonRacfRadiantlogicSailpointSAMLSaviyntScimSecureauthSharepointSQL ServerUnixUnix Shell ScriptingWeblogicWebsphereWindowsXML
11 Days Ago
In-Office
Senior level
Senior level
Legal Tech
Designs, implements, and maintains enterprise identity and access management (AD DS, Entra ID, SSO, MFA). Architects RBAC, JIT, conditional access and non-human identity governance. Leads PKI, privileged access, detection engineering, identity incident response, automation (PowerShell, APIs, IaC), and Tier-3 support. Collaborates across security, DevOps, and infrastructure, authors documentation and runs on-call rotation.
Top Skills: Active Directory Domain Services (Ad Ds)Adcs (Active Directory Certificate Services)AWSDhcpDnsEdrEntra Id (Azure Ad)Entra Id ProtectionGCPItdrKerberosLdapMfaMicrosoft Defender For IdentityMicrosoft Defender XdrMicrosoft Graph ApiWindowsOauth 2.0OidcOktaPing IdentityPkiPowershellPrivileged Access Management (Pam)PythonSAMLSIEMSingle Sign-On (Sso)Tcp/IpTerraform

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account