OnTrac
Sr Cyber Security Engineer
Virginia · Posted today
Opens jobs.dayforcehcm.com
Get a version of your resume written for this job.
- Salary
- Not listed
- Job type
- Not specified
- Work mode
- Not specified
- Source
- Dayforce (employer's hiring system)
Skills mentioned
IAM, Python, SOC 2, ISO 27001, SaaS, Bash, iOS, Android
About the role
OnTrac is hiring a Sr Cyber Security Engineer (PAM / IAM)!
Are you eager to join a dynamic and expanding company where you can both learn and make a meaningful impact? If you possess a strong sense of empathy, enjoy assisting others, thrive in a fast-paced environment, and excel at problem-solving, we encourage you to apply today to connect with a recruiter!
Founded in 1986, OnTrac has evolved into the leading provider of same-day and next-day delivery services in the U.S. for premier e-commerce and product-supply businesses, including five of the largest retailers in the U.S.
Location: Remote - This position may be performed remotely in states where the company is authorized to employ individuals.
Compensation: The expected starting base pay range for this position is $156,000 - $195,000, with full potential base salary range over a successful candidate’s tenure in the position of $156,000 - $234,000. Actual compensation will be determined based on experience, skills, internal equity, and other job-related factors.
This position may also be eligible for bonus, commission, or other incentive compensation in accordance with the terms of the applicable plan of up to a 20% Bonus Target.
Employment Logistics:
The Sr. Cyber Security Engineer is a senior-level individual contributor and hands-on technical owner for Identity and Access Management (IAM), Privileged Access Management (PAM), Entra ID, Microsoft 365, vulnerability management, and mobile device management. This broad security engineering role requires deep identity expertise alongside the ability to support endpoint, cloud, and SaaS security. The Engineer partners daily with IT to secure infrastructure and end-user services, enables the Cyber Security Incident Response Team (CSIRT) as a Tier 3 escalation point, and supports Governance, Risk, and Compliance (GRC) by translating control requirements into technical configurations and automated evidence collection.
Unpacking the Benefits:
Employees are eligible for a comprehensive benefits package which may include:
Medical, dental, and vision insurance
Life and short- and long-term disability coverage
401(k) retirement savings plan with company match
Flex vacation in states other than CA, CO, IL, MA, MT, and NE, with accruals up to 96 hours for first year of employment with tenure-based increases up to 160 hours
Two (2) floating holidays per year
Paid sick leave*
Six (6) paid company holidays
Two (2) weeks paid pregnancy disability leave, four (4) weeks paid parental bonding leave
Additional wellness and employee assistance programs
Benefits eligibility and offerings are subject to the terms and conditions of the applicable plans and company policies.
The Must-Haves:
Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent practical experience
7+ years of progressive experience in IT and Security, including at least 3 years dedicated to IAM or security engineering in an enterprise environment
Demonstrated hands-on ownership of at least two of the following:
Entra ID / Microsoft 365
A PAM platform
Qualys or equivalent vulnerability management platform
Intune / JAMF device management
Hands-on expertise with identity lifecycle, RBAC design, entitlement and access certification, federation and SSO integrations, and privileged-access tooling and workflows
Strong working knowledge of Entra ID, including Conditional Access, Identity Protection, PIM, and entitlement management, plus the Microsoft 365 security and compliance stack
Working knowledge of Intune, JAMF, and Google device management, including compliance policies, configuration profiles, and application deployment across mixed operating-system environments
Strong scripting and automation skills using PowerShell, Microsoft Graph, Python, or Bash
Ability to interpret NIST CSF, ISO 27001, or SOC 2 and implement the technical controls and evidence required to meet them
Certifications such as SC-300, SC-200, AZ-500, CISSP, CISM, GIAC GCIA, GIAC GDSA, or relevant PAM, JAMF, or Qualys vendor certifications
Ability to travel up to 10%
It is the responsibility of every position to understand and adhere to the security guidelines outlined in OnTrac’s Acceptable Use policy and to conduct their activities accordingly.
Your Mission in Motion:
A summary of key responsibilities for the role is outlined below. Additional duties may be assigned as needed to support business objectives.
Identity and privileged-access engineering: Design, deploy, and maintain enterprise identity services across Entra ID and hybrid Active Directory, including SAML/OIDC federation, SSO, Conditional Access, MFA and phishing-resistant authentication, joiner/mover/leaver automation, RBAC, role and group governance, access reviews, credential vaulting, session monitoring, just-in-time elevation, tiered administration, service-account governance, and break-glass procedures.
Microsoft 365 and Entra ID security: Harden and administer Exchange Online, SharePoint, OneDrive, Teams, Defender, Purview, and the Entra ID tenant, including configuration baselines, application registration and OAuth consent governance, license-aligned feature enablement, and posture remediation.
Vulnerability, endpoint and mobile security: Operate Qualys, including asset coverage, tagging, authenticated scanning, agents, policy compliance, and risk-based reporting; drive remediation within established SLAs; and manage compliance, configuration, enrollment, encryption, patching, application deployment, and device-posture signals across Intune, JAMF, and Google device management for Windows, macOS, iOS, and Android.
IT partnership and security by design: Serve as the embedded security engineering partner for directory, endpoint, network, and infrastructure changes, applying security by design to projects, migrations, and new deployments without unnecessarily slowing delivery.
CSIRT enablement and Tier 3 escalation: Support complex identity and endpoint incidents through containment actions, including token revocation, account disablement, and device isolation; assist with evidence collection, log-source onboarding, and detection tuning in partnership with CSIRT and the MDR provider.
GRC enablement and technical controls: Translate requirements from NIST CSF, ISO 27001, and SOC 2 into technical configurations and automated evidence collection that supports audits, third-party risk reviews, and risk-remediation tracking.
Automation, documentation and mentorship: Automate recurring identity, access, integration, and reporting tasks using PowerShell, Microsoft Graph, and Python; maintain runbooks, SOPs, architecture diagrams, and platform standards; and provide technical guidance to analysts and junior engineers.
Paving your way to your success:
You explain technical risk clearly to non-technical stakeholders and collaborate effectively across IT, CSIRT, GRC, and business teams.
You bring proficiency across identity, endpoint, network security, cloud environments including Azure, GCP, and AWS, and SaaS administration, moving effectively between domains as priorities shift.
You analyze complex issues by thoroughly evaluating multiple variables and their technical and business implications.
You define appropriate methods and procedures for new assignments, using sound judgment to select, adapt, and evaluate advanced techniques.
You build strong stakeholder relationships beyond your area of expertise, adapting your communication style and using persuasive skills to align decisions with broader business objectives.
Posting Timeline:
This job posting is anticipated to remain open for at least 15 days from the date of posting
Disclosures:
*Washington state employees are eligible for up to 56 hours of paid sick leave annually.
The salary range above represents the national range for this position. The salary range may be inclusive of several career levels at OnTrac, and the actual base salary offered may vary depending on several factors including, but not limited to: Geographic location, candidate experience and qualifications, job-related skills and competencies, market alignment, and financial considerations.
Compensation decisions are made based on the specific circumstances of each hire to ensure fair and competitive pay.
ADA Statement:
We are committed to providing equal employment opportunities to all qualified individuals. If you require reasonable accommodation to participate in the application or interview process, perform essential job functions, or access other employment benefits, please contact Human Resources.
If you are excited to be part of our team and grow with our OnTrac family, we invite you to apply!
OnTrac is proud to be an Equal Opportunity Employer
Lasership, Inc. dba OnTrac Final Mile with its affiliates, including OnTrac Logistics, Inc. (collectively, "OnTrac" or the "Company") is an equal opportunity employer. We value diversity and welcome applications from individuals of all backgrounds, abilities, and experiences. We do not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or age. Join us in our commitment to creating a diverse and inclusive workplace. If you are excited to be part of our team and contribute to our talent acquisition efforts, we invite you to apply.
Job ID df-ontrac-candidateportal-75428 · Original posting ↗
Similar jobs
Forescout Cyber Security Engineer - Mid2dGuidePoint SecurityReston, Virginia
Cyber Security Engineer III6dFidelis TechnologiesAnnapolis Junction, Maryland
- Cyber Security Engineer8dSamsung ResearchAustin, Texas · On-site
- Jr Cyber Security Engineer8dbarcodesincUnited States
- Cyber Security Engineer9dApex Technology, Inc.Los Angeles, California · On-site · US$100,000–135,000 / year