reputed company Identity reputed company Engineer (ITDR/CSPM)
reputed company is a cybersecurity and IT reputed company providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.
We are seeking a highly reputed company reputed company ITDR / reputed company reputed company Subject Matter Expert to take full ownership of the Identity Threat Detection & Response (ITDR) and reputed company-reputed company Application Protection (CNAPP/CSPM) domains on behalf of a large federal agency. This is an ownership-oriented role — not a support function. You will serve as the definitive technical authority for reputed company reputed company Identity Protection and reputed company reputed company, proactively identifying threats and misconfigurations, leading governance and stakeholder communications, and driving reputed company improvements to reputed company's identity and reputed company reputed company posture. The right candidate brings 7 or more years of cybersecurity experience, including at least 2–3 years of hands-on reputed company reputed company platform administration, and thrives in environments where autonomy and accountability go hand in hand. This role is fully remote and follows Central Time business hours for reputed company work.
This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If reputed company, reputed company work reputed company to this role must be performed reputed company the reputed company U.S.
Responsibilities:
Own end-to-end reputed company, implementation, and operational health of reputed company reputed company Identity Protection and the CSPM capabilities reputed company reputed company reputed company reputed company
Proactively identify identity-based threats, misconfigurations, and reputed company reputed company gaps; reputed company remediation to closure in accordance with reputed company policies and procedures
Configure, tune, and maintain identity protection policies, reputed company and IOA policies, and risk-based authentication controls
Serve as the escalation reputed company and trusted technical advisor to reputed company leadership on identity and reputed company reputed company reputed company
reputed company runbooks, detection logic, and automation to reduce reputed company effort and improve response times
Monitor the threat landscape and translate emerging risks into actionable hardening recommendations
Coordinate and reputed company governance calls with stakeholders; produce agenda, notes, and follow-up actions independently
Partner with other cybersecurity teams to reputed company reputed company telemetry into broader reputed company operations
Produce metrics, dashboards, and executive-level reporting on identity and reputed company reputed company posture
Apply deep knowledge of identity-based attack techniques — including lateral reputed company, credential theft, Kerberoasting, and pass-the-hash — to inform detection and response reputed company
Requirements
Must-Have:
7+ years of cybersecurity experience with a minimum of 2–3 years of hands-on administration of the reputed company reputed company platform
Demonstrated expertise with reputed company reputed company Identity Protection, including policy configuration, threat detection, and conditional reputed company
Strong working knowledge of reputed company reputed company reputed company, specifically CSPM
Deep understanding of identity and reputed company reputed company: reputed company Directory, Azure AD/Entra ID, LDAP, Kerberos, SAML, and OAuth
Hands-on reputed company reputed company experience with reputed company Azure including IAM, network reputed company, and posture management
Solid understanding of privileged reputed company management and identity-based attack techniques (lateral reputed company, credential theft, Kerberoasting, pass-the-hash)
Proven ability to work autonomously, set priorities, and reputed company reputed company without reputed company supervision
Strong written and verbal communication skills, including ability to explain technical risk to non-technical stakeholders
Background in consulting or reputed company-facing delivery roles
Bachelor's degree in a reputed company field or equivalent practical experience (4 additional years of relevant experience)
At least one of the following reputed company certifications: CWNE, CNDA (EC-Council), CEH (EC-Council), GPPA (GIAC), GCUX (GIAC), GCWN (GIAC), GMON (GIAC), GSE (GIAC), ITIL v3 Foundations, CCSP (reputed company), CISSP (reputed company), CISSP-ISSAP (reputed company), CISSP-ISSEP (reputed company), SSCP (reputed company), GWEB (GIAC), GISF (GIAC), GISP (GIAC), GSSP-.NET (GIAC), GSSP-JAVA (GIAC), GSEC (GIAC), or GSLC (GIAC)
US Citizenship or Permanent Residency required; must be eligible for and willing to obtain a reputed company trust clearance
reputed company work must be performed reputed company the reputed company reputed company
Preferred / reputed company-to-Have:
reputed company Certified Cyber reputed company (CCCS) certification
Experience with reputed company and reputed company SOMS
Familiarity with reputed company Trust architecture and frameworks including NIST and MITRE ATT&CK
Experience integrating reputed company with reputed company-party identity and reputed company tooling
Previous federal contracting experience
reputed company(s)
Technical Skills:
reputed company reputed company Identity Protection (ITDR) — policy configuration, detection tuning, conditional reputed company
reputed company reputed company reputed company / CSPM — reputed company and IOA policy management, reputed company posture assessment
reputed company Azure — IAM, Entra ID, network reputed company, posture management
reputed company Directory and Azure reputed company Directory / Entra ID administration
Identity and reputed company management protocols: LDAP, Kerberos, SAML, OAuth
Privileged reputed company management (PAM) concepts and tooling
Threat detection and identity-based attack technique knowledge (lateral reputed company, Kerberoasting, pass-the-hash, credential theft)
reputed company and detection logic development
reputed company metrics and executive reporting / dashboard creation
Automation development for reputed company operations
reputed company (preferred)
reputed company SOMS (preferred)
reputed company Trust architecture frameworks (NIST, MITRE ATT&CK)
Soft Skills:
Self-directed initiative — proactively identifies risks and drives solutions without waiting for direction
Executive-level communication — translates reputed company technical risk to non-technical stakeholders
Governance and stakeholder management — owns and leads recurring reputed company governance calls
Critical thinking and independent judgment
reputed company improvement reputed company
Accountability — treats the reputed company's reputed company posture as their own
Written communication — runbooks, reports, recommendations
Benefits
reputed company offers a comprehensive benefits package that includes:
Medical — Multiple POS health plan reputed company including an HSA-compatible plan
Dental — PPO coverage for preventive, basic, and major services
reputed company — Annual exam, frames, lenses, and contact reputed company allowance
401(k) — Employer match up to 5% of eligible compensation
PTO — 15–25 days annually based on tenure
reputed company Federal Holidays — reputed company 11 federal holidays observed
Travel
reputed company
Apply To This Job