waypointjobs

Expand Energy

Cybersecurity Engineer

oklahoma city, OK

Check who can apply and the requirements below before continuing.

About this opportunity

Expand Energy lists this Cybersecurity Engineer opportunity in oklahoma city, Oklahoma. Review the employer’s description below for duties, qualifications and application requirements.

Job description

Our core values — Stewardship, Character, Collaborate, Learn, Disrupt — are the lens through which we evaluate every business decision. As a dynamic, growing company that offers extremely competitive compensation and benefits, our employees are our most valued assets and the foundation of Expand's performance among our E&P competitors.

We seek applicants from all backgrounds to ensure we get the best, most creative talent on our team. We realize that, historically, underrepresented groups feel the need to be 100% qualified in order to apply. If you meet any combination of our requirements, we encourage you to apply. We strive to hire people from a wide variety of backgrounds, not just because it’s the right thing to do, but because it makes our company stronger.

Job Summary

This senior-level cybersecurity engineering position is responsible for designing, implementing, administering, and supporting enterprise identity, directory services, privileged access, and access governance solutions. The role serves as a senior technical contributor below the architect level, translating security architecture and standards into reliable operational capabilities across Active Directory, Okta, SailPoint, CyberArk, Quest Active Roles Server, TLS certificate management, and Group Policy. This position leads complex engineering efforts, supports critical cybersecurity services, mentors less experienced team members, and ensures identity and access platforms remain secure, resilient, auditable, and aligned with business and regulatory requirements.

Job Duties & Responsibilities

Design, implement, administer, and support enterprise identity and access management services, including Active Directory, Okta, SailPoint, CyberArk, Quest Active Roles Server, and related integrations

Serve as a senior technical owner for directory services, authentication, authorization, privileged access, identity governance, and access lifecycle processes

Implement solution architectures, technical standards, and security patterns defined by cybersecurity architects and leadership

Maintain and improve Active Directory security, including domain administration, OU structure, delegation models, privileged groups, administrative accounts, and GPO policies

Administer Quest Active Roles Server capabilities, including delegated administration, workflow support, provisioning controls, and operational automation

Configure, support, and troubleshoot Okta SSO, MFA, federation, application integrations, authentication policies, and related identity controls

Support SailPoint identity governance processes, including access requests, access certifications, entitlement ownership, provisioning workflows, and integration health

Administer CyberArk privileged access management capabilities, including vaulted credential onboarding, safe permissions, credential rotation, privileged session controls, and operational support

Manage and improve enterprise TLS certificate lifecycle processes, including certificate inventory, issuance, renewal coordination, expiration tracking, and remediation of certificate-related risks

Troubleshoot and resolve complex identity, directory, authentication, authorization, certificate, and privileged access incidents; participate in root-cause analysis and corrective action planning

Identify and implement automation opportunities using tools such as PowerShell, scripting, APIs, and workflow automation to improve repeatability, control effectiveness, and operational efficiency

Partner with infrastructure, application, cloud, audit, and business teams to implement secure access patterns and resolve identity-related issues

Develop and maintain technical documentation, standards, runbooks, recovery procedures, diagrams, and operational evidence supporting audit and compliance requirements

Lead significant technical work efforts or smaller projects related to identity modernization, privileged access, access governance, directory hardening, and certificate management

Provide technical guidance and mentoring to cybersecurity analysts, administrators, and engineers while escalating architectural decisions when appropriate

Participate in cybersecurity operational support and on-call responsibilities as required for critical identity and access services

Perform other duties as assigned

Job Specific Skills

Advanced knowledge of enterprise identity and access management principles, including SSO, MFA, federation, identity governance, privileged access management, RBAC, least privilege, and Zero Trust concepts

Strong hands-on experience administering Microsoft Active Directory in a complex enterprise environment, including domain services, GPOs, administrative delegation, privileged access, and directory hardening

Experience with Quest Active Roles Server or similar delegated administration and identity automation tools

Experience administering Okta, including application integrations, authentication policies, MFA, SSO, federation, delegated authentication, and troubleshooting

Experience supporting SailPoint IdentityNow or similar identity governance platforms, including access requests, certifications, entitlement ownership, provisioning, and workflow support

Experience administering CyberArk or similar privileged access management platforms, including credential vaulting, safe permissions, credential rotation, session management, and privileged account controls

Strong understanding of TLS certificate management, certificate authorities, certificate lifecycle processes, and operational risks associated with expired or misconfigured certificates

Proficiency with PowerShell and scripting or automation tools used to manage identity, directory, certificate, and access-related processes at scale

Strong troubleshooting and problem-solving skills across hybrid identity, SaaS applications, Windows infrastructure, cloud services, and enterprise security platforms

Good understanding of audit, compliance, SOX control expectations, access review evidence, and documentation practices related to identity and privileged access management

Ability to translate cybersecurity architecture, standards, and control objectives into practical engineering tasks and operational processes

Effective written and verbal communication skills; able to work with technical teams, application owners, vendors, auditors, and business stakeholders

Demonstrated ability to lead complex technical work, manage competing priorities, mentor others, and drive assigned initiatives to completion with limited supervision

Education

Minimum: Bachelor’s degree from an accredited university in Cybersecurity, Information Security, Information Technology, MIS, Computer Science, or a related field; equivalent experience and cybersecurity training may be considered

Preferred: Bachelor’s degree from an accredited university in Cybersecurity, Information Security, Information Technology, MIS, Computer Science, or a related technical field

Experience

Minimum: 8 years related work experience in cybersecurity engineering, identity and access management, directory services, privileged access management, infrastructure security, or related enterprise technology functions

Preferred Certifications

CISSP, CISM, or similar cybersecurity certification

Microsoft identity, security, or Azure certifications such as SC-300, AZ-500, or equivalent

Okta, SailPoint, CyberArk, Microsoft, or directory services certifications relevant to identity, access governance, or privileged access management

CompTIA Security+ or other foundational cybersecurity certification

What Success Looks Like

Becomes a trusted senior engineer for Active Directory, Quest Active Roles Server, Okta, SailPoint, CyberArk, TLS certificate management, and GPO-related support

Stabilizes and improves identity and access operations while reducing dependence on any single individual for critical platform knowledge

Improves documentation, recovery readiness, audit evidence, and operational procedures for key identity and privileged access services

Identifies automation opportunities that reduce manual effort and improve the reliability of access, certificate, and directory management processes

Contributes to senior engineering and architecture discussions while remaining focused on hands-on execution, platform ownership, and operational excellence

Expand Energy takes necessary action to ensure that all applicants are treated without regard to their race, color, religion, sex, sexual orientation, age, gender identity, national origin, genetic information, disability, pregnancy, military or veteran status or any other protected characteristic as established by law.

Expand Energy Corporation's operations are focused on discovering and developing its large and geographically diverse resource base of unconventional oil and natural gas assets onshore in the United States.

Nearest Major Market

Oklahoma City

Nearest Secondary Market

Oklahoma

Job Segment

Developer, Computer Science, Compliance, Engineer, Information Security, Technology, Legal, Engineering

#J-18808-Ljbffr

Worksite address

oklahoma city, OK, 73116, US

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Ready for your next step?Apply on the official website
Apply on WhatJobs ↗

Explore related searches

Current related jobs

UF Health

WhatJobs

Information Technology Specialist

gainesville, FL

Salary not specified

UF Health is seeking an ECMO Specialist to provide expert support to critically ill adult and pediatric patients requiring extracorporeal life su…

Listing review due 2026-10-06View job

Epic

WhatJobs

Software Developer

madison, WI

Salary not specified

Software Developer Code that saves lives.  As a software developer at Epic, you’ll write software that impacts the lives of 75% of Americans …

Listing review due 2026-10-06View job

Johns Hopkins Applied Physics Laboratory (APL)

WhatJobs

Reverse Engineer and AI Workflow Developer

laurel, MD

See pay details in description

Description Are you passionate about reverse engineering complex software, firmware, and hardware? Do you enjoy developing agentic AI workflo…

Listing review due 2026-10-06View job

Johns Hopkins Applied Physics Laboratory (APL)

WhatJobs

AFSIM Developer

laurel, MD

See pay details in description

Description Are you passionate about building high-fidelity simulations that shape the future of U.S. Space Force capabilities and force design …

Listing review due 2026-10-06View job

Johns Hopkins Applied Physics Laboratory (APL)

WhatJobs

Senior Software Engineer/Architect - TS SCI cleared

laurel, MD

See pay details in description

Description Are you passionate about building solutions for our greatest national security challenges? Are you searching for engaging work wi…

Listing review due 2026-10-06View job

Johns Hopkins Applied Physics Laboratory (APL)

WhatJobs

Senior Software Engineer

laurel, MD

See pay details in description

Description Are you passionate about building solutions for our greatest national security challenges? Are you searching for engaging work wi…

Listing review due 2026-10-06View job