Active Directory Security Engineer
The Active Directory Security GPO Engineering team is seeking an AD Security Engineer responsible for analysis, design, implementation coordination and 4th level escalation support of complex, enterprise level Active Directory solutions, specifically pertaining to security. The individual will work within the engineering organization, interacting with peer teams and partner groups, scaling and deploying improvement, consolidation and migration efforts within the enterprise. The candidate must be able to operate and function well in a multi-cultural, geographically dispersed virtual team environment.¿Primary responsibilities:Analysis, design, capacity planning and implementation of Active Directory SecurityTranslate business needs into workable technology solutions that meet the requirements of internal customers and peer Active Directory Engineering and Operations teamsResponsible for developing standards, target states, roadmaps, effectively socializing and obtaining consensus across architecture, engineering and operations teamsIndependently manage and perform engineering role for large scale Active Directory efforts and initiativesPerform various functions and duties in support of audit and compliance deliverables - verification/remittance of directory security evidenceDevelop detailed architecture, standards, design and implementation documentationAnalyze current Active Directory environment to identify both technical and operational challenges while making recommendations and developing solutions for improvementParticipate in or lead complex or high severity troubleshooting and incident/problem resolutions with other infrastructure teamsPrimary Skills: Active Directory, PowerShell, Windows OSAt least 5-10 years of dedicated Active Directory engineering and architecture experience that includes designing, implementing and maintaining complex enterprise level (50K+ objects) Active Directory solutions and security modelsOverarching broad and deep technical experience with Active Directory SecurityExtensive experience and advanced knowledge implementing Windows security concepts and policies, least-privilege design principlesExtensive knowledge of AD Security best-practices, latest security threats/trends and mitigation thereofExperience with best practices for Active Directory disaster recovery, object management, security models and trust creationGranular ACE permissions models meeting functional and technical requirementsAdvanced PowerShell scripting experience and capabilitiesStrong working knowledge of Windows Server operating systems platforms, DNS, networks, DMZs, firewalls, network security zones and IPv6Deep, in-depth working knowledge of Kerberos (Microsoft and MIT/Heimdal) and NTLM authentication, MFA, SSO and federation technologiesExtensive and deep knowledge of Group Policy Objects (GPOs), engineering, implementing and 3rd party management solutions thereofStrong knowledge of LDAP and ability to comfortably construct queriesExperience performing large scale upgrades, migrations, transitions and consolidation of Active Directory domains and forestsExperience and confidence to be the subject matter expert (SME) in an environment of this size and scale in order to coordinate technical efforts and resolve issues across multiple teamsWorking knowledge of Certificate/CA/PKI infrastructureExcellent communication skills, including proven experience effectively communicating technical challenges and solutions to peers, customers and senior managementExperience with Microsoft's Enhanced Security Architecture Environment (ESAE) - Red/Bastion/Admin? forest design; including JIT (just in time) JEA (just enough administration) conceptsExperience engineering password vaulting solutions (CyberArk, Lieberman, Thycotic, etc.)Red Team assessment, exposure and interactionAlternative scripting/programming skills (C#, VBscript, Javascript, Python, Perl)Microsoft Azure integrationMS SQL/DB knowledgeExperience with RESTful APIsMicrosoft or 3rd party management and monitoring solutions (SCCM, SCOM, VCM, Quest GPO Admin)Unix/Linux skills; Vintela VAS integration; RedHat IdM