Identity & Endpoint Security Engineer at Northwood Space
Los Angeles, CA
$120,000–$190,000
Jul 23, 2026
Los Angeles, CA
Jul 25, 2026
What this job asks for AI summary
This role centers on owning and operating an Okta-based identity platform, covering SSO architecture, lifecycle management, adaptive authentication, and RBAC across corporate, cloud, and government workloads. The engineer also manages MDM across multiple operating systems and handles privileged access controls, all within compliance frameworks such as CMMC Level 2, FedRAMP, and NIST 800-171. It suits a mid-level IAM specialist comfortable working in regulated, government-adjacent environments and willing to pursue a TS/SCI clearance.
Mid level · 3+ years · TS/SCI clearance · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (11)
No work location is specified in the posting. Given the nature of the role (government/ITAR-regulated, TS/SCI clearance required, on-premises environment references), this is almost certainly an on-site or hybrid US-based position, but the city/metro could not be determined — CBSA left blank.
The posting explicitly describes this as a 'mid-level individual contributor role,' which aligns with the 3+ years experience requirement — both advertised and assessed seniority are Mid.
TS/SCI clearance is listed as a hard condition of employment ('successfully obtaining and maintaining a Top Secret Security Clearance as a condition of employment'), though it may not be required on day one.
The role spans IAM/identity engineering, MDM/endpoint management, and compliance — a genuine hybrid. 15-1212 (Information Security Analysts) was chosen as the primary SOC because the dominant day-to-day work is security analysis and governance (IAM architecture, access control, compliance frameworks). 15-1299 is noted as an alternative given the strong identity engineering and MDM administration components.
MDM platforms (e.g., Jamf, Intune) are not named explicitly in the posting; 'MDM' is captured as a required skill reflecting the hard-gated responsibility to 'architect, deploy, and manage a unified MDM solution.'
CMMC, FedRAMP, and SOC 2 audit experience appear under Preferred Qualifications; NIST 800-171 appears under Basic Qualifications and is marked required. CMMC/FedRAMP/SOC 2 are marked preferred accordingly.
CIS benchmarks and DISA STIG appear in the MDM responsibilities section (not a qualifications gate), so they are marked preferred. Similarly, NIST 800-53 appears in the MDM policy section rather than the Basic Qualifications block and is marked preferred.
Cloudflare appears in both the responsibilities narrative and Preferred Qualifications; it is marked preferred as the qualifications block is the authoritative gate signal.
No compensation range is provided in the posting.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Okta Identity Governance.
Requires a TS/SCI clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.