Senior Identity Security Engineer (Arlington, VA or San Diego, CA)

CoStar Group - Arlington, VA

Hiring: Senior Identity Security Engineer (Arlington, VA or San Diego, CA) Company: CoStar Group Location: Arlington, VA Job Posted Time: 2026-09-15 11:42:40 Employment Type: Full-time / On-site Target Skills & Keywords : Bash, CI/CD, IAM, LLM, OAuth, OIDC, Okta, PKI, PowerShell, Python, SAML, SIEM, Zero Trust About the job Experience: •4+ years of hands-on security engineering experience, including implementation of new controls to address threats Required Skills: •This position can be located in either •Arlington, VA or San Diego, CA and is in office Monday through Thursday and work from home on Friday. •Design, implement, and continuously improve identity security controls across various platforms •Develop and maintain conditional access policies that enforce appropriate authentication strength, device compliance, etc including for privileged roles, sensitive applications, and workload identities •Analyze logs to scope and guide rollouts of new security initiatives •Support an org-wide, multi-platform phish-resistant authentication rollout •Engineer controls around AI and workload identities (service principals, managed identities, OAuth app registrations) •Research, prototype, and operationalize AI-assisted tooling and agentic workflows to improve team efficiency, including automating repetitive analysis and building internal tools that surface identity risk Qualifications: •Bachelor’s Degree required from an accredited, not for profit, in person, university or college. •A track record of commitment to prior employers •Thorough understanding of AitM attacks, Evilgnx and understanding on how to neutralize them through strong identity security hygiene •Strong analytical and problem-solving skills with a data-driven approach to decision-making •Hands-on experience administrating industry-standard IDPs (Okta, PingID, Microsoft Entra ID, Active Directory) •Knowledge of authentication and authorization protocols such as SAML, OAuth, OIDC, Kerberos •Firm understanding of PKI, the FIDO2 framework, passkeys, Windows Hello for Business, and Platform SSO, Okta FastPass, Okta Device Trust •Solid understanding of role-based access control, least privilege, just-in-time access, and other identity security paradigms •Demonstrated capacity to read and author basic scripts in at least one common language (Python, PowerShell, Bash) Compensation: •$133,000 - $203,000 / year •401(K) retirement plan with matching contributions Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!