Boston, MA

Salary
$126,000–$151,000
Posted
Jul 20, 2026
Location
Boston, MA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior engineering role focused on designing and operating identity and access management systems across enterprise and cloud-hosted environments. Day-to-day work involves building and standardizing platforms such as Entra ID, Okta, and Active Directory; implementing authentication protocols; managing secrets and privileged access; and supporting zero-trust security initiatives. Suited to an experienced IAM or security engineer comfortable working across regulated, multi-cloud environments.

Senior level · 7+ years · Boston-Cambridge-Newton, MA-NH · Full-time

Pay in the description: $126,000–$151,000

Must have (7)
Microsoft Entra IDOktaSAMLOAuth2OpenID ConnectLDAPHashiCorp Vault
Nice to have (2)
RBAC or AbacCISSP, Microsoft Identity Certification or Okta Certified

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 25 people in the Boston-Cambridge-Newton, MA-NH area plausibly meet what this posting asks for (information security analysts). range 15–40

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
HashiCorp Vault8%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Microsoft Entra ID50%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $139,553 (middle half $110,917–$180,330). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (6)

This role sits at the intersection of IAM engineering and security architecture; 15-1212 (Information Security Analysts) was chosen as the primary code because the core mandate is identity-driven security controls, zero trust, and access governance. 15-1299 is noted as a runner-up since IAM engineering is not a perfect fit for any single SOC.

The posting does not specify a remote or hybrid arrangement; remote is set to false by default given the Boston HQ context and no explicit remote language.

RBAC and ABAC are listed together as interchangeable access-model concepts in the responsibilities section rather than as distinct required tools; captured as a single preferred skill with ABAC as an alternative.

Certifications (CISSP, Microsoft Identity, Okta Certified) are explicitly 'encouraged' rather than required, so they are marked as preferred.

Experience in regulated environments is listed as 'preferred' in the required qualifications block and is a domain characteristic rather than a named technology — omitted from the skills list per guidelines.

AI-driven identity security capabilities and AI-assisted analytics appear in the responsibilities narrative as forward-looking context rather than gated requirements; no specific AI tool or platform is named, so no skill was emitted for them.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗