Active Directory Engineer (GPO)
3B Staffing LLC
Active Directory Engineer (GPO) with our client in the financial industry located in Charlotte, NC, Plano, TX, and Pennington, NJ. This is a 12+ month contract position.
Responsibilities:
Responsibilities:
- Analysis, design, implementation coordination and 4th level escalation support of complex, enterprise level Active Directory solutions, specifically pertaining to security
- Work within the engineering organization, interact with peer teams and partner groups, scale and deploy improvement, consolidation and migration efforts within the enterprise
- Translate business needs into workable technology solutions that meet the requirements of internal customers and peer Active Directory Engineering and Operations teams
- Develop standards, target states, roadmaps, effectively socializing and obtaining consensus across architecture, engineering and operations teams
- Independently manage and perform engineering role for large scale Active Directory efforts and initiatives
- Perform various functions and duties in support of audit and compliance deliverables - verification/remittance of directory security evidence
- Develop detailed architecture, standards, design and implementation documentation
- Analyze current Active Directory environment to identify both technical and operational challenges while making recommendations and developing solutions for improvement
- Participate in or lead complex or high severity troubleshooting and incident/problem resolutions with other infrastructure teams
- At least 5-10 years of dedicated Active Directory engineering and architecture experience that includes designing, implementing and maintaining complex enterprise level (50K+ objects) Active Directory solutions and security models
- Overarching broad and deep technical experience with Active Directory Security
- Extensive experience and advanced knowledge implementing Windows security concepts and policies, least-privilege design principles
- Extensive knowledge of AD Security best-practices, latest security threats/trends and mitigation thereof
- Experience with best practices for Active Directory disaster recovery, object management, security models and trust creation
- Granular ACE permissions models meeting functional and technical requirements
- Advanced PowerShell scripting experience and capabilities
- Strong working knowledge of Windows Server operating systems platforms, DNS, networks, DMZs, firewalls, network security zones and IPv6
- Deep, in-depth working knowledge of Kerberos (Microsoft and MIT/Heimdal) and NTLM authentication, MFA, SSO and federation technologies
- Extensive and deep knowledge of Group Policy Objects (GPOs), engineering, implementing and 3rd party management solutions thereof
- Strong knowledge of LDAP and ability to comfortably construct queries
- Experience performing large scale upgrades, migrations, transitions and consolidation of Active Directory domains and forests
- Experience and confidence to be the subject matter expert (SME) in an environment of this size and scale in order to coordinate technical efforts and resolve issues across multiple teams
- Working knowledge of Certificate/CA/PKI infrastructure
- Excellent communication skills, including proven experience effectively communicating technical challenges and solutions to peers, customers and senior management
- Able to operate and function well in a multi-cultural, geographically dispersed virtual team environment
- Experience with Microsoft's Enhanced Security Architecture Environment (ESAE) - "Red/Bastion/Admin forest design; including JIT (just in time) and JEA (just enough administration) concepts
- Experience engineering password vaulting solutions (CyberArk, Lieberman, Thycotic, etc.)
- Red Team assessment, exposure, and interaction
- Alternative scripting/programming skills (C#, VBscript, Javascript, Python, Perl)
- Microsoft Azure integration
- MS SQL/DB knowledge
- Experience with RESTful APIs
- Microsoft or 3rd party management and monitoring solutions (SCCM, SCOM, VCM, Quest GPO Admin)
- Unix/Linux skills; Vintela VAS integration; RedHat IdM
Vacancy posted more than 2 months ago
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Active Directory Engineer (GPO). Be the first to apply!
