Trek Bicycle logo
Trek BicyclePosted 1 month ago

IT Security Engineer

HybridWaterloo, Wisconsin, United States

Full TimeSenior LevelLarge

Job Summary

Own the Identity & Access Management program lifecycle, including governance, role-based access control, joiner-mover-leaver processes, and Microsoft Entra ID optimization. Monitor alerts across CrowdStrike Falcon, Microsoft Sentinel, and Zscaler to triage, investigate, and escalate security incidents while developing detection rules and incident response playbooks. Integrate identity signals into SOC workflows to unify threat detection and leverage AI tools to automate access reviews, accelerate alert triage, and refine governance documentation. Collaborate cross-functionally with IT, HR, and engineering teams to enforce least-privilege models and audit compliance requirements.

Required Qualifications

  • 5+ years' experience in IT or information security, with demonstrable hands-on ownership across both IAM and security operations functions
  • Deep hands-on experience with Microsoft Entra ID (Azure AD) including SSO, MFA, Conditional Access, and directory operations
  • Strong understanding of IAM concepts: RBAC, least privilege, PAM, JML processes, access certification, and federated identity
  • Experience with endpoint detection and response (EDR) platforms — CrowdStrike Falcon strongly preferred
  • Experience with SIEM platforms for alert monitoring, investigation, and detection rule management — Microsoft Sentinel preferred
  • Experience with network security monitoring and proxy platforms — Zscaler ZIA/ZPA preferred
  • Demonstrated ability to own incident response end-to-end: triage, investigation, containment, eradication, and documentation
  • Strong understanding of Windows and *nix systems, network architecture and protocols (TCP/IP, DNS, HTTPS), and cloud technologies
  • Demonstrated ability to incorporate AI tools into security workflows — not just awareness of them
  • Excellent written and verbal communication skills — able to explain identity risk and security incidents to non-technical stakeholders
  • Holds or is actively pursuing relevant certification: (ISC)2 CISSP/CCSP/SSCP; SANS GIAC GCIH/GCIA/GCFA; Microsoft SC-300; CompTIA Security+; or equivalent

Desired Qualifications

  • Experience with privileged access management platforms (CyberArk, BeyondTrust, Admin by Request, or similar)
  • Scripting experience — PowerShell or Python — for automating identity workflows, detection pipelines, and security integrations
  • Experience with physical security systems (access control, CCTV) as a secondary function
  • Experience supporting compliance frameworks — PCI DSS, ISO 27001, SOC 2, or similar — with technical evidence and control documentation
  • Experience with threat hunting methodologies and hypothesis-driven investigation
  • Bachelor's degree in Computer Science, Information Security, MIS, or equivalent experience

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce