Sr Platform Engineer (AD/PAM)

TEKsystems•Burbank, CA
•$95 - $100•Hybrid

About The Position

TEKsystems is looking to hire a Senior Platform Engineer (Active Directory & PAM) for one of our media & entertainment clients. Candidates can sit out of the following locations: Burbank/Orlando/Seattle. This role involves analyzing and automating the life cycle management of Identities in Active Directory and Entra, documenting and guiding the operations team with the decommissioning of legacy Active Directory instances, evaluating service/product capabilities to design future offerings, and assisting with compliance and remediation activities for AD, Entra, and related technology platforms. The engineer will define engineered designs with full documentation and follow structured methodologies for technical analysis.

Requirements

  • Minimum of 8 years of work experience in Identity & Access Management
  • Demonstrated experience designing, implementing, and integrating enterprise-level highly connected hybrid IAM solutions including: Active Directory, Azure Active Directory / Entra ID, Microsoft Identity Manager, Active Directory Federation, PAM Solutions, Integrations between key services and various LDAP providers.
  • Experience in engineering, designing, and integrating both infrastructure components (domain controllers, sites and services, connectivity, etc.) and logical aspects (GPO management, directory structure, and management toolsets)
  • Experience working with and directing suppliers in an outsourced environment
  • Hands-on experience with PAM platforms (e.g., CyberArk), including privileged account vaulting, Tier 0/1/2 credential management, and privileged access workstation (PAW) deployment
  • Experience designing and enforcing role-based access controls (RBAC) and privileged identity management (PIM) across Active Directory and Entra ID
  • Experience with PKI architecture, certificate lifecycle management, and certificate authority rationalization or migration
  • Experience with Active Directory domain consolidation, migration, and legacy domain decommissioning
  • Familiarity with Entra ID governance, including cross-tenant identity governance models
  • Experience automating non-human (service) account lifecycle management, including provisioning, ownership enforcement, and deprovisioning
  • Experience conducting AD/Entra security baseline assessments and remediating identified findings

Nice To Haves

  • Experience with Cyber Ark / Idira will be a huge plus.

Responsibilities

  • Analyze the existing life cycle management of Identities created in Active Directory and Entra and help automate and modernize the process.
  • Document and guide the operations team with the decommissioning of legacy instances of Active Directory.
  • Evaluate capabilities of services/products and design solutions to deliver future service offerings through detailed technical analysis.
  • Help with compliance and remediation activities of AD, Entra and related technology platforms.
  • Define engineered designs, including full documentation.
  • Follow structured methodologies for technical analysis of products and solutions.
  • Lead consolidation and decommissioning of the legacy MGMT and iDMZ Active Directory domains and their associated PKI infrastructure.
  • Onboard privileged accounts into the PAM platform, vaulting Tier 0/1/2 credentials and enforcing zero standing privileged access across AD domains.
  • Implement role-based access controls (RBAC) and privileged identity management (PIM) across Active Directory and Entra ID, replacing legacy, overly broad permissions.
  • Automate provisioning and deprovisioning of non-human (service) accounts, including ownership enforcement and lifecycle management.
  • Standardize AD architecture and governance across Enterprise Tech and business unit/segment-managed domains, including baseline security assessments.
  • Design and pilot cross-tenant Entra ID governance to extend identity controls across business segments and partners.
  • Deploy Privileged Access Workstations (PAW) and restrict Tier 0 administrative activity to hardened, isolated devices.
  • Remediate high-priority security findings across AD and Entra/M365 tenants to reduce the attack surface ahead of migration.
  • Work with security and infrastructure teams to remediate vulnerabilities.
  • Document configurations, policies, and procedures for future reference.

Benefits

  • Medical, dental & vision
  • Critical Illness, Accident, and Hospital
  • 401(k) Retirement Plan
  • Pre-tax and Roth post-tax contributions available
  • Life Insurance (Voluntary Life & AD&D for the employee and dependents)
  • Short and long-term disability
  • Health Spending Account (HSA)
  • Transportation benefits
  • Employee Assistance Program
  • Time Off/Leave (PTO, Vacation or Sick Leave)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service