Skip to main content
Posted August 23, 2026

Security Engineer - Network & Identity (Contractor)

Sungrow USA Corporation
Houston, TX, US Full Time
90000USD - 130000USD per year

Job Description

Job Description

About the Company: Sungrow North America is a leading provider of renewable energy solutions, specializing in the development and manufacturing of photovoltaic inverters and energy storage systems. The company offers a comprehensive range of products and services designed to optimize the performance and efficiency of solar power installations. Sungrow North America aims to provide sustainable and reliable energy solutions to meet the growing demand for clean power and is known for its commitment to innovation, high-quality standards, and exceptional customer service.



Security Engineer – Network & Identity:

The Security Engineer (Network & Identity) is a hands-on engineering role within the IT team responsible for designing, implementing, securing, and automating Sungrow USA's network security, PKI and certificate management, and identity & access infrastructure across on-premises, cloud, and SaaS environments. This role serves as the technical owner for network security architecture, cryptographic services, certificate lifecycle management, authentication, and access controls. The position focuses on Zero Trust security, network segmentation, certificate-based authentication, and identity protection to reduce organizational risk and enable secure business operations and platform ownership rather than SOC operations, threat monitoring, or incident response.

Essential Duties and Responsibilities:

Network Security

  • Design, implement, and maintain secure enterprise network architectures across corporate offices, data centers, cloud platforms, and remote workforce environments.
  • Architect network segmentation, Zero Trust access controls, and secure connectivity standards using Fortinet and Zscaler security solutions.
  • Develop and maintain Zero Trust architectures across network, identity, endpoint, application, and cloud environments.
  • Design and administer secure remote access using Zscaler Private Access, VPN technologies, and identity-aware access controls.
  • Manage firewall policies, network security controls, routing security, DNS security, and hybrid-cloud connectivity.
  • Design and support Network Access Control architectures using IEEE 802.1X, RADIUS, and certificate-based authentication.
  • Assess network security posture, develop remediation plans, and drive continuous security improvements.

Cryptography, PKI & Certificate Management

  • Own the enterprise PKI, cryptography, and certificate lifecycle management architecture, standards, and governance program.
  • Design and manage certificate-based authentication and machine identity solutions for users, devices, servers, applications, cloud workloads, and network infrastructure across Azure, AWS, and hybrid environments.
  • Implement and maintain certificate lifecycle automation using Microsoft Cloud PKI, Keyfactor, CyberArk Certificate Manager, EJBCA, DigiCert, AppViewX, or comparable platforms.
  • Manage certificate issuance, enrollment, discovery, deployment, monitoring, renewal, revocation, auditing, and compliance across the enterprise.
  • Design and support cryptographic services and certificate-based security controls, including TLS/mTLS, code signing, PKI trust hierarchies, certificate-based authentication, SCEP, PKCS, and machine identities.
  • Establish PKI and cryptographic standards, key management practices, and security controls to support Zero Trust, regulatory compliance, and enterprise security requirements.
  • Troubleshoot and resolve complex certificate, cryptographic, trust chain, authentication, and secure communications issues across enterprise systems and applications.

Identity & Access

  • Define authentication and authorization standards for workforce, partner, application, service, and machine identities.
  • Design, implement, and maintain Microsoft Entra ID architecture, tenant governance, and identity security controls.
  • Develop, test, and enforce Conditional Access policies and Zero Trust access controls.
  • Implement and maintain MFA, passwordless authentication, phishing-resistant authentication, and Microsoft Entra ID Protection capabilities.
  • Design and support enterprise SSO and federation integrations using SAML, OAuth 2.0, OpenID Connect, and SCIM.
  • Implement least-privilege and risk-based access models across enterprise platforms.
  • Administer RBAC, administrative separation, Microsoft Entra Privileged Identity Management, and least-privilege access controls.
  • Govern application registrations, service principals, enterprise applications, API permissions, and managed identities.
  • Support B2B collaboration, guest-user governance, external workforce access, and third-party identity integrations.
  • Design and implement security controls across Microsoft Azure and AWS environments.
  • Apply least privilege, RBAC, encryption, secrets management, and secure configuration standards to on-prem and cloud resources.
  • Automate identity provisioning and deprovisioning, access governance, certificate management, configuration validation, and security operations.
  • Create reusable secure-by-default templates and reduce manual administration through automation and orchestration
  • Conduct access reviews, entitlement certifications, and identity governance activities.

Education or Desired License and Certificates:

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent professional experience.
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300) preferred.
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500) preferred.
  • CCNA, Fortinet, Zscaler, AWS Security, CISSP, CISM, Terraform, or relevant PKI certification preferred

Preferred Experience & Qualifications:

  • 5+ years of experience in security engineering, identity & access management (IAM), network security, cloud security, or a related enterprise IT discipline.
  • Hands-on experience with Microsoft Entra ID, including Conditional Access, MFA, SSO, Identity Protection, PIM, RBAC, identity governance, and modern authentication protocols (SAML, OAuth, OpenID Connect, SCIM).
  • Experience designing, implementing, and securing enterprise identity, privileged access, and machine identity solutions across hybrid and multi-cloud environments.
  • Hands-on experience with Fortinet, Zscaler (ZIA/ZPA), Zero Trust architectures, least-privilege access models, and network security controls.
  • Experience designing and operating enterprise PKI, certificate lifecycle management, certificate-based authentication, and machine identity platforms such as Keyfactor, DigiCert, EJBCA, AppViewX, CyberArk Certificate Manager, or similar solutions.
  • Experience securing Azure and AWS environments, including identity, networking, encryption, secrets management, logging, and security monitoring.
  • Experience with PAM and IGA platforms such as CyberArk, Delinea, BeyondTrust, SailPoint, Saviynt, or similar technologies.
  • Experience integrating identity, network, cloud, and security telemetry with SIEM and security operations platforms.
  • Strong automation and Infrastructure as Code skills using PowerShell, Python, Microsoft Graph API, REST APIs, Terraform, or similar technologies.
  • Strong troubleshooting skills across authentication, federation, certificates, PKI, network security, cloud access, application integrations, and enterprise identity services.
  • Knowledge of cybersecurity and compliance frameworks including SOC 2, ISO/IEC 27001, NIST CSF, NIST 800-63, CIS Controls, Zero Trust, and NERC CIP.

Competencies:

  • Mandarin fluency preferred but not required.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Ability to work independently and collaboratively in a fast-paced environment.
  • Excellent communication, stakeholder management, and technical documentation skills.
  • Strong organization, attention to detail, initiative, and ownership.
  • Ability to balance security, reliability, usability, scalability, and business requirements.
  • Proactive approach to automation, standardization, and continuous improvement.

Travel

5%-20%

Work Location and Status:

  • Full time, Hybrid at any Sungrow USA office in Phoenix, Costa Mesa, or Houston
  • No visa sponsorship

Compensation:

  • Compensation commensurate with experience
  • Competitive salary and annual bonus eligibility
  • Comprehensive benefits package including health, dental, vision, and retirement plans
  • Strong personal and company growth opportunities

Sungrow is an equal opportunity employer. Due to strong interest in this position, Sungrow will only reach out to those candidates who best meet the requirements. Thank you for your interest in Sungrow.


#LI-LB1

Sign up for Job Alerts