AirLife

Security Engineer – Identity, Access Management & Detection

AirLife Grand Rapids, Michigan, United States

Medical Equipment Manufacturing · 5,001-10,000 employees

5 h ago
security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Security Engineer will design and manage identity and access management infrastructure while collaborating with managed detection providers to mitigate cyber threats. This role ensures the implementation of Zero Trust principles and maintains a secure, compliant IT environment through continuous monitoring and alert triage.

What they look for

Identity and Access Management Microsoft Entra ID Active Directory PowerShell Cisco Duo MFA Microsoft Intune Microsoft Defender Privileged Access Management Zero Trust architecture SIEM Vulnerability management Data loss prevention NIST ISO 27001 GDPR Incident response

Requirements

Candidates must have 4-8 years of IT experience with at least 3 years in cybersecurity or IAM, including hands-on experience with Microsoft identity tools. A bachelor's degree in a related field is required, along with strong knowledge of security compliance frameworks and threat detection concepts.

Benefits

Medical coverage Dental coverage Vision coverage 401(k) Paid time off Paid holidays Bereavement leave Employee assistance program Medical leave benefits

Full description

COMPANY DESCRIPTION

At AirLife, we are dedicated to improving the quality of every breath. Excellence with Every Breath is not just a tag line, but the way we work and take care of our customers. With a mindset to evolve, innovate, and grow, we are a premier manufacturer of the highest-quality and market-leading breathing consumables. This growth philosophy has positioned us to increase our global footprint and business reach, impacting even more people around the world. Our expanding family of the most trusted brands offers a product portfolio that spans the continuum of care from first responder to home care, with safety, patient comfort, and clinical performance in mind. Collective expertise allows us to provide quality products and experiences to our patients, customers, and our people. Our values of Customer first, Differentiate with our People, Bias for Action, Continuous Improvement and Accountability define who we are and how we work. Join us!

POSITION SUMMARY

The Security Engineer – Identity, Access Management & Detection is responsible for designing, implementing, and operating AirLife's identity and access management infrastructure while also contributing to the detection and response capabilities that protect the enterprise from evolving cyber threats. This role manages user identities, authentication mechanisms, access privileges, and privileged account controls across AirLife's global environment, while partnering with AirLife's managed detection and response provider (Arctic Wolf) to ensure that identity-based and broader cyber threats are effectively detected, investigated, and remediated. This dual-focus role is central to AirLife's Zero Trust maturity journey and its ability to maintain a secure, compliant, and resilient IT environment.

POSITION QUALIFICATIONS

Knowledge, Skills, & Abilities:

  • Deep understanding of Identity and Access Management architecture, including IAM lifecycle management, Identity Governance and Administration (IGA), and Privileged Access Management (PAM).
  • Hands-on experience with Microsoft Entra ID and on-premises Active Directory; PowerShell scripting experience required.
  • Experience with Cisco Duo MFA, Microsoft Intune MDM, and the Microsoft Defender security suite.
  • Practical knowledge of automated provisioning and deprovisioning, role-based access control (RBAC), Single Sign-On (SSO) configuration, LDAP, and federation standards.
  • Working knowledge of security threat detection concepts, SIEM platform interaction, and security alert triage; experience collaborating with MDR/MSSP providers on alert tuning and incident escalation (Arctic Wolf experience preferred).
  • Understanding of Zero Trust architecture principles and their application to identity-first security design.
  • Experience with vulnerability management, endpoint protection agent management, and data loss prevention tooling.
  • Knowledge of security compliance frameworks (NIST, ISO 27001, CIS Controls, GDPR) with practical experience applying them to IAM control design.
  • Experience with backup and disaster recovery systems (Rubrik/Azure preferred).
  • Strong root cause analysis and technical troubleshooting skills for complex identity and security issues.
  • Ability to manage concurrent projects and tasks in a dynamic environment; Smartsheet experience preferred.
  • Experience with KnowBe4 security awareness and phishing simulation administration preferred.
  • Relevant IAM or cybersecurity certification preferred (Microsoft SC-300, CompTIA Security+, SSCP, or equivalent).

Level of Experience:

Minimum 4–8 years of IT experience with 3+ years in a cybersecurity or IAM-focused role in an enterprise environment. Experience in a manufacturing, healthcare, or regulated environment preferred.

Level of Education:

Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent experience. IAM or security certification preferred.

Travel:

Up to 20% as required by the business.

ESSENTIAL DUTIES AND RESPONSIBILITIES

  • Design, implement, and continuously improve AirLife's Identity and Access Management architecture, including full IAM lifecycle management, automated provisioning and deprovisioning workflows, and role-based access control frameworks aligned to least-privilege principles.
  • Administer and optimize Microsoft Entra ID and on-premises Active Directory services, including group policy management, directory synchronization, hybrid identity configuration, and identity governance rule maintenance.
  • Manage and continuously improve AirLife's Single Sign-On and Multi-Factor Authentication platforms (Cisco Duo, Entra ID), ensuring high availability, consistent user experience, and compliance with AirLife's authentication standards.
  • Develop and maintain Privileged Access Management (PAM) and Privileged Identity Management (PIM) controls, enforcing least-privilege principles and time-bound access for administrative and privileged accounts across the environment.
  • Conduct and coordinate periodic access reviews and certification campaigns to validate compliance with AirLife's access control policies, support segregation-of-duties requirements, and produce audit evidence for internal and external auditors.
  • Partner with Arctic Wolf (MDR provider) as AirLife's primary IAM subject matter expert: ensure identity-based threat alerts are properly tuned, reviewed, and investigated; participate in security incident response activities; and contribute to alert triage and false positive reduction efforts.
  • Monitor and triage security alerts from endpoint protection, SIEM, and identity platforms; collaborate with the managed security partner on threat detection rule refinement and response playbook execution.
  • Manage endpoint protection agent configurations, patch compliance levels, and agent health across AirLife's device fleet in coordination with the Infrastructure team.
  • Administer AirLife's data loss prevention capabilities and backup/disaster recovery systems (Rubrik/Azure), ensuring configurations align with data protection and recovery time objectives.
  • Support KnowBe4 security awareness and phishing simulation administration in coordination with the Security GRC Engineer, contributing to campaign configuration and completion tracking.
  • Develop and maintain comprehensive documentation of IAM architecture, configurations, access control standards, identity governance policies, and operational runbooks.
  • Collaborate with the Infrastructure, Applications, and Security GRC teams to ensure security-by-design principles — particularly identity-first and Zero Trust concepts — are applied to new system implementations, integrations, and cloud migrations.

OTHER RESPONSIBILITIES

  • Uphold and embody AirLife's values in all aspects of work.
  • Demonstrate accuracy and thoroughness in daily work; look for ways to improve and promote quality & safety.
  • Inspire the trust of others; treat people with respect and dignity and embrace the value of diversity.
  • Use time efficiently; perform job accurately, thoroughly, and conserve Company resources to improve profits.
  • Contribute to building and maintaining a positive team environment.
  • Assure all policies and guidelines are implemented and followed.

QUALITY POLICY

At AirLife, Quality is our promise. It is our commitment to customer satisfaction and our dedication to product excellence in an evolving global healthcare market. This promise is kept through a continuously improving and effective Quality Management System and compliance to Regulatory Requirements.

DEIA STATEMENT

At AirLife, we are committed to building a diverse workforce and an inclusive workplace that reflects the communities and customers we serve. We believe our philosophy on Diversity, Equity, Inclusion, and Advancement (DEIA) encourages excellence and equips us to serve an evolving global marketplace.

Please note: The responsibilities outlined above are not exhaustive and may evolve over time. The role holder may be required to undertake additional duties as reasonably expected to meet the needs of the company.

Benefits

AirLife offers a comprehensive benefits package, including medical, dental, and vision coverage, 401(k), paid time off, paid holidays, bereavement leave, Employee Assistance Program resources, and medical leave benefits, subject to applicable eligibility requirements. Certain positions may also be eligible for bonus, commission, or other incentive compensation.

Similar roles