IAM Security Engineer – Identity Threat Detection & Response
Insight Global · Northville Township, MI
$35–$40/hrfrom the description
Jul 17, 2026
Northville Township, MI
Jul 21, 2026
What this job asks for AI summary
This role centers on deploying and operating CrowdStrike Identity Protection across Active Directory and Entra ID environments to detect, investigate, and remediate identity-based threats. Day-to-day work involves building detection logic for attacks such as Kerberoasting and Pass-the-Hash, tuning risk scoring and security policies, and collaborating with IAM teams on vulnerability remediation. An on-call rotation for high-severity incidents is also required.
Mid level · 2+ years · National · Contract
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (6)
No work location or metro area is specified in the posting; CBSA is left blank. The role is staffed through Insight Global (a staffing firm), and the hourly pay rate strongly indicates a contract/W2 engagement.
Identity attack technique knowledge (Kerberoasting, Pass-the-Hash, DCSync, Golden Ticket, ACL Abuse) is listed as a required skill but names no single discrete tool — captured in the Active Directory and Entra ID requirements rather than as a standalone skill entry, as the techniques are context for those environments.
CrowdStrike Identity Protection / Falcon platform is listed under 'Nice to Haves' alongside Microsoft Defender for Identity and Semperis as interchangeable alternatives.
PowerShell and Python are listed together under Nice to Haves as scripting options; PowerShell is named first with Python as the alternative.
Security certifications (CISSP, GIAC, SC-300) appear under Nice to Haves; CISSP is used as the primary name with the others as alternatives.
Posting is for a contract engagement — the market benchmarks below price full-time roles, so read the comp comparison with that in mind.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.