waypointjobs

OnTrac

Sr Cyber Security Engineer

workfromhome, MN

Check who can apply and the requirements below before continuing.

About this opportunity

OnTrac lists this Sr Cyber Security Engineer opportunity in workfromhome, Minnesota. Review the employer’s description below for duties, qualifications and application requirements.

Job description

OnTrac is hiring a Sr Cyber Security Engineer (PAM / IAM)!

Are you eager to join a dynamic and expanding company where you can both learn and make a meaningful impact? If you possess a strong sense of empathy, enjoy assisting others, thrive in a fast-paced environment, and excel at problem-solving,

Founded in 1986, OnTrac has evolved into the leading provider of same-day and next-day delivery services in the U.S. for premier e-commerce and product-supply businesses, including five of the largest retailers in the U.S.

Location

Remote - This position may be performed remotely in states where the company is authorized to employ individuals.

Compensation

The expected starting base pay range for this position is $156,000 - $195,000 , with full potential base salary range over a successful candidate’s tenure in the position of $156,000 - $234,000 . Actual compensation will be determined based on experience, skills, internal equity, and other job-related factors.

This position may also be eligible for bonus, commission, or other incentive compensation in accordance with the terms of the applicable plan of up to a 20% Bonus Target.

Employment Logistics

The Sr. Cyber Security Engineer is a senior-level individual contributor and hands-on technical owner for Identity and Access Management (IAM), Privileged Access Management (PAM), Entra ID, Microsoft 365, vulnerability management, and mobile device management. This broad security engineering role requires deep identity expertise alongside the ability to support endpoint, cloud, and SaaS security. The Engineer partners daily with IT to secure infrastructure and end-user services, enables the Cyber Security Incident Response Team (CSIRT) as a Tier 3 escalation point, and supports Governance, Risk, and Compliance (GRC) by translating control requirements into technical configurations and automated evidence collection.

Unpacking the Benefits

Employees are eligible for a comprehensive benefits package which may include:

Medical, dental, and vision insurance

Life and short- and long-term disability coverage

401(k) retirement savings plan with company match

Flex vacation in states other than CA, CO, IL, MA, MT, and NE, with accruals up to 96 hours for first year of employment with tenure-based increases up to 160 hours

Two (2) floating holidays per year

Paid sick leave*

Six (6) paid company holidays

Two (2) weeks paid pregnancy disability leave, four (4) weeks paid parental bonding leave

Additional wellness and employee assistance programs

Benefits eligibility and offerings are subject to the terms and conditions of the applicable plans and company policies.

The Must-Haves

Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent practical experience

7+ years of progressive experience in IT and Security, including at least 3 years dedicated to IAM or security engineering in an enterprise environment

Demonstrated hands-on ownership of at least two of the following:

Entra ID / Microsoft 365

A PAM platform

Qualys or equivalent vulnerability management platform

Intune / JAMF device management

Hands-on expertise with identity lifecycle, RBAC design, entitlement and access certification, federation and SSO integrations, and privileged-access tooling and workflows

Strong working knowledge of Entra ID, including Conditional Access, Identity Protection, PIM, and entitlement management, plus the Microsoft 365 security and compliance stack

Working knowledge of Intune, JAMF, and Google device management, including compliance policies, configuration profiles, and application deployment across mixed operating-system environments

Strong scripting and automation skills using PowerShell, Microsoft Graph, Python, or Bash

Ability to interpret NIST CSF, ISO 27001, or SOC 2 and implement the technical controls and evidence required to meet them

Certifications such as SC-300, SC-200, AZ-500, CISSP, CISM, GIAC GCIA, GIAC GDSA, or relevant PAM, JAMF, or Qualys vendor certifications

Ability to travel up to 10%

It is the responsibility of every position to understand and adhere to the security guidelines outlined in OnTrac’s Acceptable Use policy and to conduct their activities accordingly.

Your Mission in Motion

A summary of key responsibilities for the role is outlined below. Additional duties may be assigned as needed to support business objectives.

Identity and privileged-access engineering: Design, deploy, and maintain enterprise identity services across Entra ID and hybrid Active Directory, including SAML/OIDC federation, SSO, Conditional Access, MFA and phishing-resistant authentication, joiner/mover/leaver automation, RBAC, role and group governance, access reviews, credential vaulting, session monitoring, just-in-time elevation, tiered administration, service-account governance, and break-glass procedures.

Microsoft 365 and Entra ID security: Harden and administer Exchange Online, SharePoint, OneDrive, Teams, Defender, Purview, and the Entra ID tenant, including configuration baselines, application registration and OAuth consent governance, license-aligned feature enablement, and posture remediation.

Vulnerability, endpoint and mobile security: Operate Qualys, including asset coverage, tagging, authenticated scanning, agents, policy compliance, and risk-based reporting; drive remediation within established SLAs; and manage compliance, configuration, enrollment, encryption, patching, application deployment, and device-posture signals across Intune, JAMF, and Google device management for Windows, macOS, iOS, and Android.

IT partnership and security by design: Serve as the embedded security engineering partner for directory, endpoint, network, and infrastructure changes, applying security by design to projects, migrations, and new deployments without unnecessarily slowing delivery.

CSIRT enablement and Tier 3 escalation: Support complex identity and endpoint incidents through containment actions, including token revocation, account disablement, and device isolation; assist with evidence collection, log-source onboarding, and detection tuning in partnership with CSIRT and the MDR provider.

GRC enablement and technical controls: Translate requirements from NIST CSF, ISO 27001, and SOC 2 into technical configurations and automated evidence collection that supports audits, third-party risk reviews, and risk-remediation tracking.

Automation, documentation and mentorship: Automate recurring identity, access, integration, and reporting tasks using PowerShell, Microsoft Graph, and Python; maintain runbooks, SOPs, architecture diagrams, and platform standards; and provide technical guidance to analysts and junior engineers.

Paving your way to your success

You explain technical risk clearly to non-technical stakeholders and collaborate effectively across IT, CSIRT, GRC, and business teams.

You bring proficiency across identity, endpoint, network security, cloud environments including Azure, GCP, and AWS, and SaaS administration, moving effectively between domains as priorities shift.

You analyze complex issues by thoroughly evaluating multiple variables and their technical and business implications.

You define appropriate methods and procedures for new assignments, using sound judgment to select, adapt, and evaluate advanced techniques.

You build strong stakeholder relationships beyond your area of expertise, adapting your communication style and using persuasive skills to align decisions with broader business objectives.

Posting Timeline

This job posting is anticipated to remain open for at least 15 days from the date of posting

Disclosures

*Washington state employees are eligible for up to 56 hours of paid sick leave annually.

The salary range above represents the national range for this position. The salary range may be inclusive of several career levels at OnTrac, and the actual base salary offered may vary depending on several factors including, but not limited to: Geographic location, candidate experience and qualifications, job-related skills and competencies, market alignment, and financial considerations.

Compensation decisions are made based on the specific circumstances of each hire to ensure fair and competitive pay.

ADA Statement

We are committed to providing equal employment opportunities to all qualified individuals. If you require reasonable accommodation to participate in the application or interview process, perform essential job functions, or access other employment benefits, please contact Human Resources.

OnTrac is proud to be an Equal Opportunity Employer

Lasership, Inc. dba OnTrac Final Mile with its affiliates, including OnTrac Logistics, Inc. (collectively, 'OnTrac' or the 'Company') is an equal opportunity employer. We value diversity and welcome applications from individuals of all backgrounds, abilities, and experiences. We do not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or age. Join us in our commitment to creating a diverse and inclusive workplace.

#J-18808-Ljbffr

Worksite address

workfromhome, MN, 55792, US

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Ready for your next step?Apply on the official website
Apply on WhatJobs ↗

Explore related searches

Current related jobs

Govcio LLC

WhatJobs

Senior Systems Engineer (NSGS)

alexandria, VA

$145,000.00 /Yr

Overview: GovCIO is seeking a Senior Systems Engineer to support mission-critical IT programs for the U.S. Coast Guard (USCG). This position wil…

Last received from source 2026-10-07View job

Govcio LLC

WhatJobs

Cyber / DevOps Systems Engineer (Ft. Bragg)

fort liberty, NC

$130,000.00 /Yr

Overview: GovCIO is currently hiring for a Senior Cyber Security / DevOps Systems Engineer to engineer, automate, secure, and optimize full-stack…

Last received from source 2026-10-07View job

Govcio LLC

WhatJobs

Site W/Classified Support Engineer

herndon, VA

$100,000.00 /Yr

Overview: GovCIO is currently hiring for aGovCIO is currently hiring for an Site W/Classified Support Engineer.  for an upcoming award. This p…

Last received from source 2026-10-07View job

Govcio LLC

WhatJobs

Cloud Platform Engineer

fort meade, MD

$217,000.00 /Yr

Overview: GovCIO is currently hiring for a Cloud Platform Engineer  to create tools and environments that improve developer productivity. This po…

Last received from source 2026-10-07View job

Govcio LLC

WhatJobs

CSOC Classified Support Engineer

colorado springs, CO

$140,000.00 /Yr

Overview: GovCIO is currently hiring for a Senior CSOC Support Engineer in Colorado Springs, CO. This position is onsite.  Responsibilities: P…

Last received from source 2026-10-07View job

Govcio LLC

WhatJobs

Senior CSOC Support Engineer

colorado springs, CO

$145,000.00 /Yr

Overview: GovCIO is currently hiring for a Senior CSOC Support Engineer in Colorado Springs, CO.  Responsibilities: Provides technical and man…

Last received from source 2026-10-07View job