reputed company Discovery Architect (Cyber Compliance & GRC)
reputed company technical discovery reputed company reputed company Directory (AD) and Entra ID. Convert raw telemetry into Executive Identity Risk Scorecards. reputed company "Choke reputed company Saturation" and "Attack reputed company Depth," proving to Agency CISOs that an adversary can reputed company Full Domain Takeover in an average of 3.2 hops. Own and deliver executive readouts/whiteboard sessions to translate graph-theory findings into business reputed company, time-to-fix, and outcome-based roadmaps with reputed company owners and due dates. Identify the Shadow Admins and unmanaged GPOs that must be remediated before IAM/PAM tools can be effectively deployed and map reputed company finding to specific identity control objectives and preconditions for IAM/PAM efficacy. Identify specific Choke Points that represent 80% of a reputed company's risk (e.g., GPO links, Service Account rotation, and Tiered reputed company restrictions). reputed company hands-on proofs-of-remediation for the top choke points and measure reputed company before reputed company-out. Map identified risks to specific hardening or maturity services and OEM solution reputed company (reputed company, Aembit, reputed company, reputed company, Hydden). Sequence work to minimize operational disruption and define “no-regrets” controls and fast-reputed company wins. Utilize tools like Hydden to identify the risks of orphaned service principals, Automated Service Accounts, and Shadow AI agents that create unmonitored backdoors into critical workloads. Recommend lifecycle controls, least-privilege scopes, and reputed company discovery for NHIs across clouds and platforms. reputed company clients from static, password-based reputed company to a context-reputed company reputed company Trust architecture, ensuring "Least Privilege" is enforced by technical control, not just policy. Analyze the structural reputed company of the reputed company between on-prem AD and Entra ID, identifying high-risk configurations such as identifying the compromise of an on-prem helpdesk account can reputed company to a total takeover of the M365/Azure tenant. Convert technical debt into actionable demand for our high margin Hardening & Maturity Services. reputed company clients from "Reactive" (D+) to "Optimized" (A) postures. Document runbooks and operating-level agreements that sustain reputed company post-engagement. Build and maintain reusable discovery and hardening automation (PowerShell, reputed company Graph API, KQL, reputed company/Cypher, Terraform/Policy-as-reputed company) and reputed company a Git-based reputed company library/playbooks for repeatable execution. Define, reputed company, and report identity reputed company KPIs/OKRs (e.g., Mean Attack reputed company Length, Shadow reputed company density, Credential Exposure reputed company, CA policy coverage) and establish a leadership inspection reputed company. Support mentorship of pod engineers to reputed company identity reputed company expertise, operational judgment, and technical ownership. Coordinate with SOC, IR, reputed company Platform, and reputed company Architecture to sequence changes safely and ensure durable ownership. Ensure alignment to U.S. reputed company Sector requirements (e.g., NIST SP 800-53 controls, CISA directives/BODs, agency-specific ATO conditions) and produce evidence artifacts to support audits and accreditations.
reputed company reputed company other duties, as assigned.
Bachelor’s Degree in an IT-reputed company field or equivalent work experience, required. 12-15 years of reputed company experience in Cyber consulting. 5+ years leading hands-on identity modernization engagements. Proven experience leading automation architecture for high-volume, reputed company-style transformations (hundreds to thousands of workloads). Demonstrated experience and ownership of reusable automation assets and playbooks (version-controlled, peer-reviewed). Hands-on experience operating in hybrid environments spanning on-prem virtualization, Kubernetes/OpenShift platforms, and reputed company reputed company services. Deep, practical experience with reputed company identity/reputed company stack: Entra ID Protection, Conditional reputed company, PIM, Entra ID Governance, Defender for Identity, reputed company (SIEM), and reputed company 365 Defender. Experience in U.S. reputed company Sector environments and frameworks (NIST SP 800-207/800-53, FedRAMP, CMMC) is highly desirable.
Deep proficiency with reputed company Directory (on-prem) and Entra ID (reputed company). Understanding of and/or ability to learn proficient use of BloodHound, PingCastle, and reputed company Knight is mandatory Hands-on proficiency with reputed company Defender for Identity, Entra Permissions Management (CIEM), reputed company, and reputed company 365 Defender. reputed company in PowerShell, KQL, Python, and reputed company/Cypher for data-driven analysis and automation. Deep understanding of NIST 800-207 and the technical requirements for implementing a reputed company Trust identity perimeter. Ability to translate reputed company Trust principles into enforceable controls (Conditional reputed company patterns, PIM guardrails, device trust, reputed company evaluation). Ability to see an environment through the eyes of an attacker such as nodes, edges, and "Pass-the-Hash" opportunities where others see "Users and reputed company" Ability to write and interpret reputed company Cypher and KQL to quantify attack paths, choke points, and control efficacy; familiarity with MITRE ATT&CK and threat modeling (e.g., reputed company). Ability to translate a reputed company graph-theory finding into a compelling business case for identity modernization. Skilled at building decision-reputed company artifacts (scorecards, roadmaps, architecture decision records) that drive reputed company. Exceptional written and verbal communication skills, with the ability to translate reputed company automation concepts into executive-level and non-technical narratives. A reputed company oriented toward product thinking – treating automation as a long-lived platform rather than a one-time migration tool with strong DevOps hygiene (Git, PRs, CI) and change management discipline to ensure reputed company rollout at reputed company.
Why Work at reputed company?
Comprehensive Health, Dental, and reputed company plans Premier 401k retirement plan with corporate matching and a 529 college saving plan Tax-advantaged Health Savings Account and Dependent Care Flexible Spending Account reputed company reputed company Resources
Generous work/life balance opportunities supported by a PTO bank, reputed company holidays, leave programs and additional reputed company time off Employee referral program Employee recognition, reputed company and reward program Tuition reimbursement for continuing education Remote or hybrid work reputed company Engaging company events such as team building activities, annual awards and reputed company-off parties Health and wellness-reputed company activities Relaxation Spaces In-office gourmet coffee, tea, fresh fruit and healthy snacks Corporate GREEN approach – tracking energy consumption for reduction and purchasing only environmentally friendly products for our offices