Cyber Security Principal

Federal Express Corporation•Memphis, TN
•$9,208 - $20,872•Hybrid

About The Position

We are seeking a seasoned and strategic Cyber Security Principal to serve as the enterprise technical authority for our Enterprise Directory and Certificate Services ecosystem. In this role, you will lead the strategic architecture, security hardening, governance, and operational resilience of our mission-critical identity tier—focusing exclusively on Active Directory Domain Services (AD DS), Oracle Unified Directory (OUD) LDAP, and Microsoft Entra ID (Azure AD), along with enterprise Public Key Infrastructure (PKI) / Certificate Services.

Requirements

  • Expert-level knowledge of multi-forest/multi-domain topologies, trusts, Kerberos (constrained/unconstrained delegation, PKINIT), DNS, and replication mechanics.
  • In-depth expertise in AD hardening/security techniques and attack path reduction.
  • Advanced design, administration, performance tuning, and replication architecture of OUD LDAP services.
  • Deep understanding of LDAP RFCs, search filter indexing, backend database partitions, and directory proxy architectures.
  • Comprehensive expertise in Entra ID architecture, App Registrations, Service Principals, Entra Connect/Cloud Sync, Conditional Access, and hybrid tenant security.
  • Proven ability to drive consensus and influence architectural standards across security, infrastructure, and application engineering teams.
  • Strong communication skills with the ability to convey identity risks and cryptographic concepts clearly to executive stakeholders.
  • Experience leading technical response and post-incident hardening during critical Tier-0 / identity security incidents.
  • Bachelor's degree/Equivalent in computer science, information systems and/or equivalent formal training.
  • Five (5+) years of experience in IT information security.
  • Skills include IT security and infrastructure.
  • Strong technical and consulting skills, project management capability.
  • Experience with security and risk frameworks, standards and best practices.
  • Strong communication skill.

Nice To Haves

  • PowerShell: Advanced scripting and module development for Active Directory administration, reporting, remediation, and API interactions (Microsoft.Graph, ActiveDirectory module).
  • Ansible: Proven experience developing and maintaining Ansible playbooks for automated provisioning, configuration management, security baseline enforcement, and deployment of directory infrastructure.
  • Familiarity with directory integrations into enterprise IGA platforms (e.g., SailPoint IdentityIQ / Identity Security Cloud).
  • Familiarity with Identity Providers (e.g. Okta) and Identity Protection modules (e.g Crowdstrike IDP).

Responsibilities

  • Define, maintain, and enforce target-state architecture, security baselines, and configuration standards across on-premises and cloud directory environments (AD DS, OUD LDAP, and Microsoft Entra ID).
  • Lead security engineering for domain controllers, schema governance, trust relationships, Group Policy, and authentication protocol security.
  • Architect, tune, and secure enterprise Oracle Unified Directory deployments, including multi-master replication topologies, access control instructions (ACIs), schema extensions, and high-throughput LDAP integrations.
  • Design and govern Entra ID tenant configurations, Conditional Access policies, hybrid directory synchronization (Entra Connect), and Privileged Identity Management (PIM).
  • Architect, document, and routinely validate comprehensive forest recovery and disaster recovery runbooks for AD and OUD, ensuring rapid recovery against ransomware and catastrophic failure.
  • Provide SME guidance on identity security architecture across enterprise projects, mentor directory engineering staff, and establish security posture KPIs/KRIs for leadership.

Benefits

  • Comprehensive benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service