Назад
Company hidden
5 дней назад

Senior Active Directory Engineer (Cybersecurity)

97 100 - 161 800$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Active Directory Engineer (Microsoft Entra ID and cybersecurity): Designing, securing, and operating large-scale Active Directory and hybrid identity environments in regulated, high-availability financial infrastructure with an accent on resilience, compliance, and risk-based access controls. Focus on building secure multi-forest architectures, automating auditable identity operations with PowerShell, and strengthening disaster recovery, monitoring, and audit readiness.

Location: Buffalo, New York, United States; four days onsite at the Seneca One Buffalo location and one day working from home each week

Salary: $97,100–$161,800 USD annually

Company

M&T Bank is a financial services organization operating regulated, high-availability technology environments.

What you will do

  • Design, secure, and operate enterprise Microsoft Active Directory Domain Services environments, including multi-domain, multi-forest, trust, FSMO, and Active Directory-integrated DNS architectures.
  • Integrate on-premises Active Directory with Microsoft Entra ID using Entra Connect, Cloud Sync, Password Hash Synchronization, Pass-through Authentication, and federation.
  • Implement identity security controls including tiered administration, privileged access workstations, least privilege, role separation, dual control, Conditional Access, and Zero Trust practices.
  • Manage replication, SYSVOL health and recovery, backup and authoritative restore procedures, disaster recovery objectives, monitoring, and alerting across data centers and regions.
  • Build auditable PowerShell automation for provisioning, deprovisioning, reporting, change management, IAM, ticketing, and security tooling.
  • Act as the technical authority and escalation point, define identity standards and runbooks, support audits, and mentor engineers while partnering with security, IAM, risk, audit, infrastructure, cloud, and application teams.

Requirements

  • Expertise supporting large-scale, Tier-1 Active Directory identity infrastructures with strict uptime, latency, and change-control requirements.
  • Extensive experience with Microsoft Entra ID hybrid identity, Conditional Access, Hybrid Join, Entra ID Join, identity lifecycle controls, and privileged identity management.
  • Strong knowledge of Active Directory security hardening, credential and delegation threats, access reviews, entitlement recertification, and defense-in-depth strategies.
  • Experience supporting SOX, GLBA, PCI DSS, SOC 2, internal risk management, model governance, audit logging, traceability, and evidence generation.
  • Advanced PowerShell skills and deep experience with replication, DFSR, authentication dependencies, backup, recovery, monitoring, and alerting.
  • Bachelor's degree and at least three years of relevant experience, or a combined minimum of seven years of higher education and/or work experience without a degree; strong communication, critical thinking, problem-solving, and collaboration skills.

Culture & Benefits

  • Hybrid work arrangement with four onsite days and one work-from-home day per week.
  • Work in a regulated financial environment with a strong security, risk, audit, and compliance focus.
  • Opportunity to mentor engineers and influence enterprise identity standards, secure configuration baselines, and operational procedures.
  • Market-informed annual compensation range of $97,100–$161,800 USD.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →