Active Directory Engineer
Bank of America Corporation
Contract Pennington, New Jersey, United States Posted 1 week ago
About Position
Active Directory Engineer (Contract)
$75.00 / Hourly
Pennington, New Jersey, United States
Active Directory Engineer
Contract Pennington, New Jersey, United States Posted 1 week ago
Skills
5-10 years of dedicated Active Directory engineering and architecture experience that includes designing implementing and maintaining complex enterprise level (50K+ objects) Active Directory solutions and security models Overarching broad and deep technical experience with Active Directory Security Extensive experience and advanced knowledge implementing Windows security concepts and policies least-privilege design principles Extensive knowledge of AD Security best-practices latest security threats/trends and mitigation thereof Experience with best practices for Active Directory disaster recovery object management security models and trust creation Granular ACE permissions models meeting functional and technical requirements Advanced PowerShell scripting experience and capabilities Strong working knowledge of Windows Server operating systems platforms DNS networks DMZs firewalls network security zones and IPv6 Deep in-depth working knowledge of Kerberos (Microsoft and MIT/Heimdal) and NTLM authentication MFA SSO and federation technologies Extensive and deep knowledge of Group Policy Objects (GPOs) engineering implementing and 3rd party management solutions thereof Strong knowledge of LDAP and ability to comfortably construct queries Experience performing large scale upgrades migrations transitions and consolidation of Active Directory domains and forests Experience and confidence to be the subject matter expert (SME) in a large global environment in order to coordinate technical efforts and resolve issues across multiple teams Working knowledge of Certificate/CA/PKI infrastructure Excellent communication skills including proven experience effectively communicating technical challenges and solutions to peers customers and senior management Able to operate and function well in a multi-cultural geographically dispersed virtual team environmentDescription
Responsible for analysis, design, implementation coordination and 4th level escalation support of complex, enterprise level Active Directory solutions, specifically pertaining to security
Work within the engineering organization, interacting with peer teams and partner groups, scaling and deploying improvement, consolidation, and migration efforts within the enterprise
Analysis, design, capacity planning and implementation of Active Directory Security
Translate business needs into workable technology solutions that meet the requirements of internal customers and peer Active Directory Engineering and Operations teams
Responsible for developing standards, target states, roadmaps, effectively socializing and obtaining consensus across architecture, engineering and operations teams
Independently manage and perform engineering role for large scale Active Directory efforts and initiatives
Perform various functions and duties in support of audit and compliance deliverables – verification/remittance of directory security evidence
Develop detailed architecture, standards, design and implementation documentation
Analyze current Active Directory environment to identify both technical and operational challenges while making recommendations and developing solutions for improvement
Participate in or lead complex or high severity troubleshooting and incident/problem resolutions with other infrastructure teams
Responsibilities
- Experience with Microsoft's Enhanced Security Architecture Environment (ESAE) - "Red/Bastion/Admin forest design; including JIT (just in time) & JEA (just enough administration) concepts
- Experience engineering password vaulting solutions (CyberArk, Lieberman, Thycotic, etc.)
- Red Team assessment, exposure and interaction
- Alternative scripting/programming skills (C#, VBScript, JavaScript, Python, Perl)
- Microsoft Azure integration
- MS SQL/DB knowledge
- Experience with RESTful APIs
- Microsoft or 3rd party management and monitoring solutions (SCCM, SCOM, VCM, Quest GPO Admin)
- Unix/Linux skills; Vintela VAS integration; RedHat IdM
By applying to a job using PingJob.com you are agreeing to comply with and be subject to the PingJob.com Terms and Conditions for use of our website. To use our website, you must agree with the Terms and Conditions and both meet and comply with their provisions.