About this role
ABOUT ADVANCED ENERGY
Advanced Energy (Nasdaq: AEIS) is a global leader in the design and manufacturing of highly engineered, precision power conversion, measurement and control solutions for mission-critical applications and processes. AE’s power solutions enable customer innovation in complex applications for a wide range of industries including semiconductor equipment, industrial, manufacturing, telecommunications, data center computing and healthcare. Advanced Energy has devoted four decades to perfecting power for its global customers and is headquartered in Denver, Colorado.
WHY BE A PART OF ADVANCED ENERGY?
Some people say it’s like working in the best of two worlds. We operate like an agile, growing, small company – you can see your work make a difference to the company every day. Things move quickly and you can see and feel it. At the same time, we’re a global company founded in 1981 and have been publicly traded for more than 28 years. We have a strong cash position, deep trust and partnership with leading customers, a global best-in-class operations capability, and a proven leadership team. We have a track record and resources to make things happen both organically and inorganically. Being part of a nimble company with a solid foundation attracts team members that are capable, driven and like a challenge. Our employees collaborate and know how to have fun inventing, working, building and winning together. At our core, we are Advanced Energy – powering the future, together.
POSITION SUMMARY:
The IT Security Analyst III plays a critical role in shaping the future of identity security at Advanced Energy. This position offers the opportunity to lead enterprise-wide IAM initiatives, influence Zero Trust strategy, and modernize identity controls across global cloud and SaaS environments. Working alongside security, infrastructure, and business leaders, you'll drive solutions that protect the business while enabling growth and innovation. This is an opportunity to make a visible impact in a global technology organization.
RESPONSIBILITIES:
IAM Architecture & Engineering
- Design, implement, and maintain enterprise Identity and Access Management (IAM) solutions supporting workforce, privileged, and application identities.
- Lead the integration, administration, and optimization of IAM platforms.
- Develop IAM architecture standards, design patterns, and technical roadmaps that align with business and security objectives.
- Establish scalable identity solutions that support cloud-first and hybrid environments.
- Evaluate emerging IAM technologies and industry best practices to strengthen the organization's security posture.
Identity Governance & Access Management
- Lead initiatives related to Identity Governance and Administration (IGA), Access Management, Privileged Access Management (PAM), Identity Threat Detection and Response (ITDR), and Zero Trust security programs.
- Design and implement identity lifecycle management processes, including provisioning, deprovisioning, role management, and access certification activities.
- Develop and maintain authorization models including Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), and Policy-Based Access Control (PBAC).
- Support segregation of duties (SoD), least privilege, just-in-time access, and privileged account governance programs.
Authentication & Directory Services
- Administer and enhance enterprise authentication services, including Single Sign-On (SSO), Multi-Factor Authentication (MFA), passwordless authentication, federation, and conditional access controls.
- Manage and support on-premise, cloud, and hybrid identity environments.
- Configure Identity Protection policies, Conditional Access policies, risk-based authentication controls, and adaptive access capabilities.
- Design and maintain integrations between identity platforms, cloud services, and business applications through APIs, provisioning connectors, and automation frameworks.
Cloud & Application Integration
- Implement secure identity integrations with enterprise applications, SaaS platforms, and cloud environments including Microsoft Azure, AWS, and Google Cloud Platform.
- Partner with application owners and development teams to ensure secure authentication and authorization controls are implemented consistently across platforms.
- Support application onboarding, federation, provisioning, and access governance activities.
Automation & Operational Excellence
- Develop automation solutions using PowerShell, Python, SQL, Power Automate, or similar technologies to improve operational efficiency and reduce manual effort
- Create and maintain technical documentation, architecture diagrams, operational procedures, and support runbooks.
- Recommend and implement process improvements that enhance security, user experience, and operational effectiveness.
Leadership & Collaboration
- Serve as a senior IAM subject matter expert and trusted advisor to Information Security, IT, Audit, Compliance, and business stakeholders.
- Lead technical projects from planning and design through deployment and operational transition.
- Mentor junior employees and provide technical guidance across IAM-related initiatives.
- Support audit, compliance, and regulatory activities by implementing appropriate controls and providing required evidence.
Additional Duties
- Participate in identity-related incident response activities and root cause investigations.
- Stay informed of emerging IAM threats, technologies, and industry trends.
- Perform other duties as assigned.
WORK ENVIRONMENT:
- Location: On-Site, Denver, Colorado at Corporate Headquarters
- Environment: Standard office environment
QUALIFICATIONS :
Required Qualifications
- Advanced knowledge of Identity and Access Management (IAM) principles, including Identity Governance and Administration (IGA), Privileged Access Management (PAM), authentication, authorization, and identity lifecycle management.
- Strong understanding of modern identity security concepts, including Zero Trust, least privilege, adaptive authentication, risk-based access controls, continuous access evaluation, and identity threat detection and response (ITDR).
- Advanced knowledge of on-premise, cloud, and hybrid identity environments.
- Strong understanding of authentication, federation, and directory protocols, including SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), LDAP, Kerberos, RADIUS, and SCIM.
- Knowledge of access control frameworks, including Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), and Policy-Based Access Control (PBAC).
- Strong analytical and problem-solving skills, with the ability to diagnose and resolve complex technical issues.
- Excellent verbal and written communication skills, including the ability to communicate technical concepts to both technical and non-technical audiences.
- Strong organizational and project leadership skills with the ability to manage multiple priorities and initiatives simultaneously.
- Demonstrated ability to influence stakeholders and collaborate effectively across cross-functional teams.
- Ability to develop and maintain technical documentation, standards, procedures, and operational runbooks.
Preferred Qualifications
- Knowledge of regulatory and compliance frameworks such as SOX, NIST, ISO 27001, and CIS Controls.
- Familiarity with IT and Security platforms or applications within Customer Relationship Management (CRM), Zero Trust, and other enterprise driven product families.
- Understanding of cloud security architectures within Azure, AWS, and Google Cloud Platform environments.
EXPERIENCE:
Required Experience
- Seven (7) or more years of experience in Identity and Access Management, Cybersecurity Engineering, Information Security, or a related technical discipline.
- Five (5) or more years of experience administering and supporting enterprise IAM platforms and access management processes.
- Three (3) or more years of experience supporting on-premise, cloud, and/or hybrid identity directory services in a medium to large enterprise environment.
- Experience implementing and supporting Identity Governance and Administration (IGA) and Privileged Access Management (PAM) solutions.
- Experience administering enterprise authentication solutions, including Single Sign-On (SSO), Multi-Factor Authentication (MFA), federation services, and conditional access policies.
- Experience integrating identity platforms with cloud providers, enterprise applications, and SaaS solutions.
- Experience designing and implementing user provisioning, deprovisioning, access reviews, role management, and access certification processes.
- Experience developing automation solutions using PowerShell, Python, SQL, Power Automate, or similar technologies.
- Experience leading technical projects from planning and design through implementation and operational support.
- Experience collaborating with Information Security, Infrastructure, Application Development, Audit, and business stakeholders to deliver IAM solutions.
Preferred Experience
- Experience with IAM platforms and technologies.
- Experience supporting global or manufacturing organizations.
- Experience supporting regulatory audits, compliance initiatives, and remediation activities.
- Experience implementing Zero Trust, Privileged Access Management, or enterprise IAM modernization programs.
EDUCATION:
Required
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Engineering, or a related field; or an equivalent combination of education, training, and experience.
Preferred Certifications
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Certified Information Systems Security Professional (CISSP)
- Certified Identity and Access Manager (CIAM)
- Certified Identity Management Professional (CIMP)
- Additional cloud, cybersecurity, or identity management certifications relevant to the role.
COMPENSATION:
As required by multiple state pay transparency laws, Advanced Energy provides a reasonable range of compensation for each job posting. Actual compensation is influenced by an array of factors including, but not limited to, skill set, level of experience, and specific office location. The range of starting pay for this role is $110,000 to $150,000 per year.
BENEFITS:
As part of our total rewards philosophy, we believe in offering and maintaining competitive compensation and benefits programs for our employees to attract and retain a talented, highly engaged workforce. Our compensation programs are focused on equitable, fair pay practices including market-based base pay, an annual pay-for-performance incentive plan, and discounted Employee Stock Purchase Plan.
In addition to our competitive compensation practices, we offer a strong benefits package in each of the countries in which we operate. In the U.S., we offer a rich benefits package that includes:
- Medical - multiple medical plans are available to choose from
- Short and long-term disability and life insurance
- Health savings and flexible spending accounts
- Generous time off policy starting with 3 weeks of paid vacation, 7 days of paid sick time, and 12 paid holidays
- 8 hours of paid volunteer time off
- 8 weeks of paid parental leave for both parents
- Company matched 401(k)
- Tuition reimbursement
- Expanded mental health coverage and employee assistance programs
- Other voluntary benefits include critical illness, accident and hospital indemnity, pet insurance, identity theft, and legal assistance
Advanced Energy is committed to diversity in its workforce including Equal Employment Opportunity for Minorities, Females, Protected Veterans, and Individuals with Disabilities.
Advanced Energy is also committed to providing reasonable accommodations in our job application process/procedures for qualified individuals with disabilities. If you require assistance in completing an Advanced Energy application, please reach out to [email protected].
CO ONLY:
Applications will be accepted through 10/23/2026, the company reserves the right to review applications at any point after they are submitted.