Senior Active Directory Engineer

M&T BankBuffalo, NY
$97,100 - $161,800Hybrid

About The Position

Responsible for designing, securing, and operating Microsoft Active Directory Domain Services (AD DS) in regulated, high-availability environments. Acts as knowledge resource for and trains less experienced engineers. Completes day-to-day support activities and special projects.

Requirements

  • Bachelor's degree and a minimum of 3 years’ relevant work experience, or in lieu of a degree, a combined minimum of 7 years’ higher education and/or work experience.
  • Proven expertise supporting large-scale, Tier‑1 identity infrastructures with strict uptime, latency, and change‑control requirements.
  • Strong experience with multi-domain and multi-forest designs aligned to business units, regions, or regulatory boundaries.
  • Strong experience with forest and external trusts supporting M&A, joint ventures, and third-party integrations.
  • Strong experience with FSMO role placement optimized for resilience and auditability.
  • Advanced understanding of Active Directory–integrated DNS, split‑brain DNS, and secure name resolution models.
  • Extensive experience integrating on-prem AD with Microsoft Entra ID in regulated financial environments.
  • Hands-on implementation of Entra Connect (Cloud Sync and Traditional), Password Hash Sync, Pass-through Authentication, and Federation.
  • Strong experience with Conditional Access aligned to regulatory and risk-based controls.
  • Strong experience with Hybrid Join, Entra ID Join, and legacy device coexistence.
  • Understanding of identity lifecycle controls to support joiners, movers, leavers, and separation-of-duties requirements.
  • Expert-level knowledge of Active Directory security hardening in financial services, including: Tiered administrative model (Tier 0/1/2), Dedicated admin forests or hardened admin boundaries (where applicable), Privileged Access Workstations (PAWs) / Secure Admin Workstations.
  • Experience enforcing least privilege, role separation, and dual‑control models.
  • Deep familiarity with threats targeting financial institutions: Credential theft, Kerberoasting, Pass-the-Hash/Ticket, Delegation and ACL abuse.
  • Hands-on experience with Privileged Identity Management (PIM).
  • Hands-on experience with regular access reviews and entitlement recertification.
  • Strong alignment with Zero Trust and defense-in-depth identity strategies.
  • Demonstrated experience supporting audits and controls for financial regulations and frameworks, such as: SOX, GLBA, PCI DSS, SOC 2.
  • Demonstrated experience supporting internal risk management and model governance requirements.
  • Ability to design AD environments that support strong logging and traceability.
  • Ability to design AD environments that support tamper-resistant audit logs.
  • Ability to design AD environments that support evidence generation for internal and external auditors.
  • Advanced PowerShell expertise for controlled, auditable administrative changes.
  • Advanced PowerShell expertise for automated provisioning/deprovisioning aligned to compliance workflows.
  • Advanced PowerShell expertise for identity reporting for risk, security, and audit teams.
  • Experience building automation that integrates with change management processes.
  • Experience building automation that integrates with IAM, ticketing, and security tooling.
  • Deep experience managing AD replication topology across data centers and regions.
  • Deep experience managing SYSVOL (DFSR) health and recovery.
  • Deep experience managing latency-sensitive authentication dependencies.
  • Strong understanding of AD backup, recovery, and authoritative restore procedures.
  • Strong understanding of identity disaster recovery scenarios with defined RTO/RPO.
  • Experience implementing monitoring and alerting with a focus on early risk detection.
  • Acts as technical authority and escalation point for all directory and identity services.
  • Defines and enforces enterprise identity standards.
  • Defines and enforces secure configuration baselines.
  • Defines and enforces operational runbooks and procedures.
  • Partners closely with Information Security and IAM teams.
  • Partners closely with risk, audit, and compliance stakeholders.
  • Partners closely with infrastructure, cloud, and application teams.
  • Mentors engineers and reviews designs from a security and risk-first perspective.

Nice To Haves

  • Intermediate understanding of the security system development and infrastructure lifecycle and architecture, and systems design.
  • Proven experience with the tools utilized in assigned Cybersecurity function.
  • Experience translating architecture into technical requirements.
  • Proficient level of critical thinking and problem solving.
  • Excellent written and verbal communication skills.
  • Proven experience collaborating with leaders to execute results.
  • Prior experience seeking buy-in of others to align on processes.
  • Ability to analyze and draw conclusions based on quantitative data from multiple sources.

Responsibilities

  • Enterprise Active Directory Architecture: Proven expertise supporting large-scale, Tier‑1 identity infrastructures with strict uptime, latency, and change‑control requirements.
  • Multi-domain and multi-forest designs aligned to business units, regions, or regulatory boundaries.
  • Forest and external trusts supporting M&A, joint ventures, and third-party integrations.
  • FSMO role placement optimized for resilience and auditability.
  • Advanced understanding of Active Directory–integrated DNS, split‑brain DNS, and secure name resolution models.
  • Hybrid Identity & Microsoft Entra ID (Azure AD): Extensive experience integrating on-prem AD with Microsoft Entra ID in regulated financial environments.
  • Hands-on implementation of: Entra Connect (Cloud Sync and Traditional), Password Hash Sync, Pass-through Authentication, and Federation.
  • Strong experience with: Conditional Access aligned to regulatory and risk-based controls, Hybrid Join, Entra ID Join, and legacy device coexistence.
  • Understanding of identity lifecycle controls to support joiners, movers, leavers, and separation-of-duties requirements.
  • Security, Compliance & Risk Controls: Expert-level knowledge of Active Directory security hardening in financial services, including: Tiered administrative model (Tier 0/1/2), Dedicated admin forests or hardened admin boundaries (where applicable), Privileged Access Workstations (PAWs) / Secure Admin Workstations.
  • Experience enforcing least privilege, role separation, and dual‑control models.
  • Deep familiarity with threats targeting financial institutions: Credential theft, Kerberoasting, Pass-the-Hash/Ticket, Delegation and ACL abuse.
  • Hands-on experience with: Privileged Identity Management (PIM), Regular access reviews and entitlement recertification.
  • Strong alignment with Zero Trust and defense-in-depth identity strategies.
  • Regulatory & Audit Readiness: Demonstrated experience supporting audits and controls for financial regulations and frameworks, such as: SOX, GLBA, PCI DSS, SOC 2, Internal risk management and model governance requirements.
  • Ability to design AD environments that support: Strong logging and traceability, Tamper-resistant audit logs, Evidence generation for internal and external auditors.
  • Automation & PowerShell: Advanced PowerShell expertise for: Controlled, auditable administrative changes, Automated provisioning/deprovisioning aligned to compliance workflows, Identity reporting for risk, security, and audit teams.
  • Experience building automation that integrates with: Change management processes, IAM, ticketing, and security tooling.
  • Operations, Resilience & Recovery: Deep experience managing: AD replication topology across data centers and regions, SYSVOL (DFSR) health and recovery, Latency-sensitive authentication dependencies.
  • Strong understanding of: AD backup, recovery, and authoritative restore procedures, Identity disaster recovery scenarios with defined RTO/RPO.
  • Experience implementing monitoring and alerting with a focus on early risk detection.
  • Leadership & Governance: Acts as technical authority and escalation point for all directory and identity services.
  • Defines and enforces: Enterprise identity standards, Secure configuration baselines, Operational runbooks and procedures.
  • Partners closely with: Information Security and IAM teams, Risk, audit, and compliance stakeholders, Infrastructure, cloud, and application teams.
  • Mentors engineers and reviews designs from a security and risk-first perspective.

Benefits

  • The pay range for this position is $97,100.00 - $161,800.00 (USD).
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service