About the Role
As a Lead Security Engineer, you will be an integral team member of the Information Security Engineering team, protecting workforce, customer, and business partner access to the organization's environment. This role designs, builds, and maintains identity, access, and endpoint security solutions, translating security requirements into technical solutions and guiding the organization on security best practices. You will also mentor junior Security Engineers and ensure systems, identities, and endpoints remain secure.
Responsibilities
- Own the design, configuration, and maintenance of SSO/federation, conditional access, and privileged access management solutions.
- Report to leadership on relevant statistics for area of expertise.
- Lead and guide offshore resources.
- Design, configure, and troubleshoot SAML/SSO integrations for customers, vendors, and internal applications, including certificate and signing-key rotation.
- Build and tune Conditional Access Policies and lead passwordless/Passkey rollouts for privileged account populations.
- Drive Privileged Access Management (PAM) operations and migrations, onboard service accounts and secrets, and integrate PAM with cloud key vaults and automation platforms.
- Oversee all aspects of area of expertise inside Information Security Engineering, including establishing metrics, applying industry best practices, and developing new tools and processes.
- Lead endpoint detection and response, identity governance, and security tooling initiatives, coordinating resources internally and externally.
- Lead migrations from legacy AV/EDR tools to modern XDR platforms, including automated response tuning and phishing simulation/security awareness programs.
- Manage Active Directory/Entra ID hygiene, including service account ownership reviews, RBAC/access-role cleanup, security group governance, and privileged role alerting.
- Coordinate NSG, firewall, and WAF rule changes with the Network team to support secure application and integration architectures.
- Provide technical leadership and mentorship to other security engineers, review designs, and help prioritize and estimate the team's engineering backlog.
- Lead processes and create additional documentation and runbooks to optimize security operations.
- Build and maintain Information Security Engineering documentation and runbooks.
- Manage SSO/certificate lifecycle for monitoring and observability tooling integrations.
- Work independently with multiple teams, including Network and Infrastructure, as well as on multiple projects.
Requirements
- Bachelor's degree or equivalent experience in Computer Science, Information Security, or related field
- 6+ years of experience in identity and access management, security engineering, and enterprise IT infrastructure
- CISSP, CISM, or equivalent security certification preferred
- 7 to 10+ years of security engineering, identity & access management, or infrastructure security experience
- Strong leadership and mentoring qualities
- Oversee all aspects of identity, access, and endpoint security including establishing metrics, applying industry best practices, and developing new tools and processes to ensure security goals are met
- Act as key point of contact for identity and endpoint security matters, providing security engineering services, and coordinating resources internally and externally
- Lead and mentor other Security Engineers
- Lead and review security configurations, scripts, plans, and procedures
- Good knowledge of SDLC processes
- Good knowledge of Agile methodology
- Very good communication skills and able to lead others
- Must have experience administering SSO/SAML federation and Conditional Access policies.
- Experience working with privileged access management tooling (e.g., CyberArk)
- Experience with endpoint detection & response tools (e.g., Microsoft Defender)
- Understanding of Active Directory administration and identity governance
- Basic knowledge of network security constructs (e.g., NSGs, firewalls, WAF)
- Familiarity with automation tooling (e.g., Ansible) for provisioning and secret management
- Ability to write SQL
- Able to work independently across multiple teams
- Must have experience using security and IT tools like JIRA and Confluence
- Must have experience working with onsite offshore teams
- Excellent English written and verbal communication skills
- Should be able to lead security team members Onsite and Offshore.
- Partner with multiple teams and provide high-quality security engineering services.
- Should be able to work individually as well as in a team.
- Experience with automation for identity and access provisioning
- Experience with certificate and vulnerability management platforms
- Experience with security monitoring/observability platforms (e.g., Splunk, Dynatrace).
Skills
- Identity providers (e.g., Microsoft Entra ID, Okta)
- Privileged access management platforms (e.g., CyberArk)
- Endpoint detection & response tools (e.g., Microsoft Defender)
- Active Directory
- SQL
- SSO/SAML federation
- Conditional Access policies
- Privileged Access Management (PAM)
- Endpoint Detection and Response (EDR)
- XDR platforms
- Microsoft Defender suite
- Active Directory/Entra ID hygiene
- NSG
- Firewall
- WAF
- Confluence
- JIRA
- Splunk
- Dynatrace
- Zabbix
- Ansible
Location
- Austin, TX 78729
- Boca Raton, FL 33496
Work Type
- 4 days onsite
Experience Level
- 6+ years of experience in identity and access management, security engineering, and enterprise IT infrastructure
- 7 to 10+ years of security engineering, identity & access management, or infrastructure security experience
Education Level
- Bachelor's degree or equivalent experience in Computer Science, Information Security, or related field
Benefits
- Competitive salaries
- 401(k)
- Incentive program
About the Company
- The ODP Group, through its business entities ODP Business Solutions and Office Depot, is a leading provider of products, services, and technology solutions through an integrated business-to-business (B2B) distribution platform and omnichannel presence, which includes world-class supply chain and distribution operations, dedicated sales professionals, online presence, and a network of Office Depot and OfficeMax retail stores.
Equal Opportunity
- The company is committed to providing equal employment opportunities in all employment practices. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, citizenship status, marital status, age, disability, protected veteran status, sexual orientation or any other characteristic protected by law.
- We will consider for employment qualified applicants with arrest and conviction records pursuant to the City & County of San Francisco Fair Chance Ordinance.
