Avatar for ATEM
ATEM
Actively Hiring
IT consulting, enterprise application solutions, and training services

Senior Active Directory Engineer

  • |3 years of exp
  • |Full Time
Posted: 2 weeks ago• Recruiter recently active
Job Location
Remote Work Policy

In office - WFH flexibility

Visa Sponsorship

Not Available

RelocationAllowed
Skills
Kerberos
OAuth
Active Directory
SAML
NTLM
Azure AD
Azure AD Connect
Microsoft Entra ID
Hybrid Identity Environments
Tier 0 Concepts
Identity As a Control Plane

About the job

Role: Engineer (Directory Services)

Location: Dallas TX- Hybrid 3 days/week

Final interview will be F2F Interview

Job Description

Operationalize automated data discovery, classification, and inventory; apply sensitivity labels and consistent taxonomy across data stores, pipelines, and collaboration systems.

Engineer DSPM capabilities with tools (e.g., Securiti, BigID) to surface data posture risks (overexposure, shadow data, stale sensitive data) and drive remediation workflows.

Implement and support encryption, tokenization, masking, anonymization/pseudonymization for data at rest and in transit; integrate with cloud key management systems and enforce approved cryptographic standards; define crypto baselines and policy-as-code guardrails.

Configure and govern access controls with RBAC/ABAC and purpose-based authorization; perform least-privilege and fine-grained access reviews across data platforms.

Deploy, tune, and operate DLP and DAM solutions (e.g., Microsoft Purview DLP, Imperva/Guardium); build detections for PII/PCI/PHI and reduce false positives with policy and context improvements.

Integrate and tune UEBA and Insider Risk signals to detect anomalous data access and exfiltration, partner on response workflows and preventive control changes.

Integrate data protection telemetry with SIEM/SOAR; build detections, correlation rules, and automated response playbooks for data-related threats and policy violations.

Implement data minimization and retention/ROT enforcement patterns; automate monitoring of lifecycle actions (archive, delete, redact) aligned to policy and legal holds.

Implement DSAR (data subject access request) orchestration and fulfillment with SLA monitoring; automate data collection, redaction, and secure delivery with audit trails.

Contribute to cookie/tag governance and catalog assurance; validate consent signals, storage durations, and vendor script behavior against policy.

Support privacy platform capabilities and integrate with identity, ticketing, data catalogs/lineage, and evidence repositories.

Embed data protection and privacy-by-design controls into services and CI/CD (pre-commit/CI privacy code scanning, secret scanning, schema checks for sensitive fields, data egress policies).

Produce compliance evidence and reports for GDPR/CCPA/CPRA, PCI DSS, HIPAA, and internal audits; maintain controls health dashboards, regulatory tracking, and program KPIs.

Investigate data-related incidents and privacy events in partnership with IR/SOC/Privacy Office. Collect artifacts, support forensics, document findings, and drive preventive engineering fixes.

Conduct platform hardening and vulnerability remediation for data control tooling (misconfigurations, exposed buckets, weak crypto, excessive permissions).

Participate in red teaming/tabletop exercises for data scenarios (insider misuse, public link exposures, unintended AI training data); translate findings into control improvements.

Partner with Cybersecurity, Privacy Office, Enterprise Data, Legal, and product/platform teams to align designs and deliver privacy- and data protection-by-design outcomes.

Document engineering patterns, runbooks, and reference architectures; create training and technical guidance that strengthen secure data handling practices across teams.

Communicate clearly and concisely with technical and non‑technical audiences - summarize incidents, risks, and recommended actions with accurate, complete context.

Required Skills & Experience

3–7 years of hands-on experience in:

Active Directory administration/engineering

Microsoft Entra ID (Azure AD)

Azure AD Connect / hybrid identity environments

Experience With

AD security hardening

Identity-related attack techniques (privilege escalation, lateral movement)

Attack path analysis or remediation activities

Strong Working Knowledge Of

Tier 0 concepts and identity as a control plane

Authentication protocols (Kerberos, NTLM, SAML, OAuth)

[hr align="center" size="1" width="100%"]

Preferred Experience

Exposure to:

CyberArk or other PAM tools

Saviynt or similar IGA platforms

Ping Identity or federation solutions

HashiCorp Vault, Keyfactor, or PKI environments

Experience supporting AD forest recovery exercises

Familiarity with Zero Trust principles

[hr align="center" size="1" width="100%"]

Key Traits for Success

Strong execution and delivery focus

Security and resiliency mindset

Ability to quickly identify and remediate risks

Works effectively in a cross-functional cybersecurity environment

Comfortable working in fast-paced, project-driven (contract) engagements

About the company

ATEM company logo

ATEM

Actively Hiring
IT consulting, enterprise application solutions, and training services51-200 Employees
Company Location
Rancho Cucamonga
Company Size
51-200
Learn more about ATEM image

Similar Jobs

Archesys company logo
Archesys
Improving the government services that impact everyday lives
Zippy MH company logo
Zippy MH
Zippy provides fast, simple home loans & insurance to manufactured home buyers
Zippy MH company logo
Zippy MH
Zippy provides fast, simple home loans & insurance to manufactured home buyers
Kollasoft company logo
Kollasoft
We provide clients exceptional IT talent to meet their demanding technology initiatives at local
Corvara Inc d/b/a Certamen company logo
Corvara Inc d/b/a Certamen
Blend athletic movement, spatial computing, and AI to create arenas without VR headsets
avs-solutions company logo
avs-solutions
For more than 15 years AVSSolutions has established itself as a key player in audiovisual