Назад
Company hidden
1 день назад

Lead Active Directory Engineer (Microsoft Entra ID)

128 100 - 213 500$
Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Active Directory Engineer (Microsoft Entra ID): Designing, securing, and operating large-scale Microsoft Active Directory and hybrid Entra ID environments in regulated, high-availability financial systems with an accent on identity architecture, security controls, and audit readiness. Focus on building resilient multi-forest infrastructures, automating compliant identity workflows with PowerShell, and implementing recovery, monitoring, and Zero Trust strategies.

Location: Wilmington, Delaware, United States; four days onsite at the Wilmington Tech Hub and one day working from home per week

Salary: $128,100.00–$213,500.00 USD per year

Company

M&T Bank operates regulated financial services environments requiring secure, resilient, and auditable identity infrastructure.

What you will do

  • Design, secure, and operate large-scale, Tier-1 Microsoft Active Directory Domain Services environments.
  • Develop multi-domain and multi-forest architectures, trusts, FSMO role placement, and Active Directory-integrated DNS.
  • Integrate on-premises Active Directory with Microsoft Entra ID using Entra Connect, Cloud Sync, password hash synchronization, pass-through authentication, and federation.
  • Implement identity security controls including tiered administration, privileged access workstations, least privilege, dual control, PIM, access reviews, and Zero Trust practices.
  • Automate provisioning, deprovisioning, reporting, and controlled administrative changes with PowerShell and related IAM, ticketing, and security tools.
  • Manage replication, SYSVOL recovery, backup and authoritative restore procedures, disaster recovery, monitoring, and alerting across data centers and regions.

Requirements

  • Bachelor's degree and at least five years of relevant experience, or a combined minimum of nine years of higher education and/or work experience without a degree.
  • Extensive experience supporting large-scale Active Directory infrastructures in high-availability and regulated environments.
  • Strong knowledge of Microsoft Entra ID, hybrid identity, Active Directory security hardening, DNS, replication, backup, and recovery.
  • Advanced PowerShell expertise for auditable administration, compliance workflows, identity reporting, and tool integration.
  • Experience with financial-sector security threats, SOX, GLBA, PCI DSS, SOC 2, audit evidence, logging, and traceability.
  • Ability to work four days onsite in Wilmington, Delaware, with one work-from-home day per week.

Nice to have

  • Experience developing or customizing cybersecurity tools and translating architecture into technical requirements.
  • Strong critical thinking, problem-solving, quantitative analysis, communication, and persuasive stakeholder-management skills.
  • Experience designing solutions with business leaders and serving in an indirect leadership role.

Culture & Benefits

  • Work in partnership with Information Security, IAM, risk, audit, compliance, infrastructure, cloud, and application teams.
  • Serve as a technical authority and escalation point for directory and identity services.
  • Define enterprise identity standards, secure configuration baselines, operational runbooks, and procedures.
  • Mentor engineers and review designs from a security- and risk-first perspective.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →