Senior Security Engineer - Active Directory

CVS HealthWork At Home-North Carolina, NC
$83,430 - $166,860Hybrid

About The Position

As an Active Directory Senior Security Engineer on our team, you will be responsible for securing, hardening, and continuously improving the security posture of a large enterprise, multi‑domain Active Directory environment in a hybrid on‑prem and Azure cloud configuration. This role is primarily focused on identity security engineering, with an emphasis on reducing attack paths, remediating vulnerabilities, and defending against modern identity‑based threats. You will operate as a key contributor in identifying and eliminating security risks across Active Directory and Azure AD, working closely with Cybersecurity, Red Team, and vulnerability management teams. This role requires deep technical expertise in AD security, a proactive mindset toward threat mitigation, and the ability to translate security findings into scalable, sustainable engineering solutions that strengthen the overall identity landscape.

Requirements

  • 5–7 years of experience supporting and securing enterprise Active Directory environments
  • 5–7 years of hands‑on experience administering Active Directory in multi‑domain or complex environments, with a strong emphasis on security
  • 4–6 years of experience administering Azure and Azure Active Directory, including identity security controls
  • 5+ years of experience working with Windows Server and Windows operating systems
  • 3–5 years of experience using PowerShell for administration, automation, and security remediation
  • 4–6 years of experience with vulnerability management, security hardening, and remediation of enterprise systems

Nice To Haves

  • Strong hands-on experience with Active Directory security assessments, attack path analysis, and remediation using tools such as BloodHound, Microsoft AD Assessment, CrowdStrike, or similar platforms
  • Deep expertise in Active Directory security, including privileged access management, credential protection, delegation and permissions modeling, Group Policy hardening, and authentication/authorization controls
  • Experience partnering with Red Teams and penetration testing teams to identify, validate, and remediate identity-related security weaknesses
  • Strong understanding of identity-focused attack techniques such as pass-the-hash, Kerberoasting, and privilege escalation, with experience implementing effective mitigation strategies
  • Experience with SIEM and security monitoring tools (e.g., Splunk, Microsoft SCOM, Microsoft Sentinel) and supporting remediation efforts for SOX, PCI, and HIPAA audit findings

Responsibilities

  • Lead the security hardening and governance of Active Directory (AD) and Microsoft Entra ID (Azure AD) environments, reducing attack surfaces and enforcing secure identity configurations
  • Identify, assess, and remediate identity and access management vulnerabilities, including privilege escalation risks, excessive permissions, and lateral movement attack paths
  • Design and implement enterprise identity security controls, including privileged access management, tiered administration, secure delegation, Conditional Access, and authentication protections
  • Partner with Cybersecurity, Red Team, and Infrastructure teams to validate findings, drive remediation efforts, and strengthen overall security posture
  • Monitor and investigate security events, threats, and indicators of compromise using tools such as Microsoft Security, Splunk, CrowdStrike, BloodHound, and Qualys
  • Develop and maintain security standards, conduct security assessments, and support compliance and audit initiatives (SOX, PCI, HIPAA) through remediation of identity-related findings

Benefits

  • medical
  • dental
  • vision coverage
  • paid time off
  • retirement savings options
  • wellness programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service