Senior Identity Security Architect
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Responsibilities
Customer Advisory & Remediation
- Serve as a trusted advisor to enterprise customers implementing Identity Attack Path Management programs.
- Translate BloodHound Enterprise findings and attack path analysis into actionable remediation strategies.
- Help customers prioritize remediation activities based on risk, impact, dependencies, and operational constraints.
- Facilitate discussions across Security, Infrastructure, IAM, Endpoint Management, Engineering teams, and other stakeholders.
- Advise customers on architectural and operational improvements that reduce attack path risk.
Architecture & Identity Security
- Provide guidance on Active Directory, Microsoft Entra ID, and hybrid identity architectures.
- Advise on delegated administration, privileged access management, administrative tiering, identity governance, service account security, and identity modernization initiatives.
- Assist customers with Privilege Zone development and operationalization.
- Evaluate identity architectures through an adversary and attack path lens.
Methodology Development
- Develop attack-path-centric remediation frameworks, playbooks, and reference architectures.
- Create repeatable guidance for remediation prioritization, ownership, implementation planning, and validation.
- Identify recurring customer challenges and codify successful remediation patterns.
- Help establish scalable delivery methodologies across BloodHound Scentry.
Internal Enablement
- Partner with researchers to operationalize emerging tradecraft and attack path research.
- Support consultants and TAMs through training, mentorship, and guidance.
- Contribute to the evolution of Identity Attack Path Management methodologies and best practices.
Requirements
- 8+ years of experience designing, operating, securing, or modernizing enterprise identity environments.
- Deep expertise in Active Directory and Microsoft Entra ID.
- Experience with BloodHound or attack path analysis.
- Experience with hybrid identity architectures and identity synchronization technologies.
- Demonstrated experience leading enterprise remediation, modernization, migration, or security improvement initiatives.
- Strong understanding of administrative tiering, delegated administration, privileged access management, identity governance, and enterprise identity operations.
- Experience working directly with technical and business stakeholders.
- Excellent written and verbal communication skills.
- Experience in consulting, professional services, or customer-facing advisory roles.
- Experience building methodologies, frameworks, or operational programs.
Preferred Qualifications
- Experience supporting large-scale enterprise Active Directory environments (50,000+ users).
- Familiarity with offensive security concepts, adversary tradecraft, or red team operations.
- Experience with Okta, Ping Identity, CyberArk, SailPoint, or similar identity platforms.
- Experience with Microsoft Intune, SCCM, Tanium, Jamf, or other endpoint management platforms.
- Familiarity with PKI, virtualization platforms, cloud infrastructure, and other critical enterprise technologies.
What Success Looks Like
Within the first year, this individual will:
- Become a core contributor to BloodHound Scentry engagements.
- Help establish SpecterOps' remediation methodology and architectural guidance frameworks.
- Improve customer outcomes by helping organizations move from attack path identification to measurable risk reduction.
- Enable consultants and TAMs through repeatable remediation patterns and implementation guidance.
- Strengthen SpecterOps' ability to help customers operationalize Identity Attack Path Management at scale.
What We Offer
- Health/Dental/Vision/life insurance: 100% covered for both the employee and their family
- Flexible time off policy
- 13 paid holidays annually
- 401(k) with up to 4% company match
- Equity and quarterly bonus based on company performance
- Remote work: $1,500 first year allowance to set up home office
- $500 annual home office allowance after the first year
- $150 monthly cell phone and internet reimbursement
- $5,000 annual professional development allowance
- $5,250 towards continuing education or student loan repayment
- $1,200 annual benefit for lifestyle, wellness, pet insurance and more
- A one-time $10,000 benefit towards family planning
- In person and virtual employee events throughout the year
- And of course, company swag!
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at SpecterOps
Explore Top Companies in this Space
Futurae
Cybersecurity / Identity & Access Management (IAM) / Multi-Factor Authentication / FinTech Security
1Password
Cybersecurity / Identity and Access Management / Software
Delinea
Cybersecurity / Identity Security / PAM
Obsidian Security
Cybersecurity / SaaS Security Posture Management (SSPM) / AI & Identity Threat Detection
SpecterOps
View Company ProfileSpecterOps is the premier, enterprise-grade cybersecurity solutions pioneer, Identity Attack Path Management innovator, and offensive tradecraft powerhouse engineered to operate as the definitive, proactive defense and threat elimination layer for global enterprises, financial institutions, and national security networks. The company completely eliminates the severe systemic friction of modern enterprise infrastructure defenseโwhere security operations center (SOC) cells struggle against complex, deeply nested privilege escalation paths, misconfigured directory service permissions, and invisible lateral adversary movements that bypass traditional endpoint detection systemsโby deploying an advanced, graph-based security ecosystem. Moving far beyond traditional, passive vulnerability scanners or generic penetration testing services, SpecterOps natively unifies real-time identity relationship mapping across Active Directory and Azure AD (Entra ID), automated security choke-point isolation, step-by-step impact-aware remediation pipelines, and elite red-teaming adversary simulations into its flagship corporate workspace, BloodHound Enterprise. As the creators and maintainers of BloodHoundโthe world's leading open-source tool for visualizing hidden directory attack paths trusted by an ecosystem of over 20,000 security expertsโthe institution empowers global security cells to enforce strict least-privilege models and dismantle millions of exploit paths with a single strategic patch. Under the hood, its sophisticated technical practiceโbacked by a massive $75 million Series B funding round led by Insight Partners along with Cisco Investments and M12โnatively orchestrates advanced graph database infrastructure pipelines, patent-protected directory services analysis loops, and secure cloud-to-edge risk profiling grids. What sets SpecterOps apart is its uncompromising dedication to replacing blind, reactive patching cycles with absolute threat-informed architectural momentum; by bridging the gap between deep offensive research and automated, deterministic enterprise hazard mitigation, the firm remains the definitive cornerstone of modern enterprise identity protection and cloud security management.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
