Technical Engineer III

Computer Task Group, IncBuffalo, NY
Onsite

About The Position

CTG is seeking to fill a Technical Engineer III opening for our client. This role involves engineering and supporting enterprise Active Directory (AD) and Microsoft Entra ID environments. The primary responsibilities include managing AD forests, domains, trusts, replication, Group Policy, and Entra Connect. The engineer will implement Conditional Access, MFA, PAM/PIM, Zero Trust, and identity security controls. Development of PowerShell automation and integration with Microsoft Graph, REST APIs, JSON, and Git is also a key part of the role. Monitoring and troubleshooting identity services using Splunk, KQL, and CrowdStrike IDP, as well as supporting identity lifecycle, RBAC, access governance, audit, and regulatory compliance are essential. The role requires collaboration with various teams to deliver technical solutions and mentoring of other engineers.

Requirements

  • 6+ years of professional experience in technical engineering, infrastructure, systems design, or architecture.
  • Advanced experience with Active Directory, Microsoft Entra ID, hybrid identity, and authentication.
  • Strong knowledge of Kerberos, LDAP/LDAPS, NTLM, SAML, OAuth 2.0, OIDC, and certificate-based authentication.
  • Advanced PowerShell, troubleshooting, analytical, and problem-solving skills.
  • Excellent communication and collaboration skills.
  • Excellent verbal and written English communication skills and the ability to interact professionally with a diverse group are required.

Nice To Haves

  • Bachelor's degree in Computer Science, Computer Engineering, or related field.
  • Experience with Python, Terraform, Bicep, ARM, GitLab, Azure DevOps, ServiceNow, CyberArk, or SailPoint.
  • Experience with SOX, NIST, FFIEC, or NYDFS in a regulated environment.
  • Financial services or enterprise identity engineering experience preferred.

Responsibilities

  • Engineer and support enterprise Active Directory (AD) and Microsoft Entra ID environments.
  • Manage AD forests, domains, trusts, replication, Group Policy, and Entra Connect (PHS/PTA).
  • Implement Conditional Access, MFA, PAM/PIM, Zero Trust, and identity security controls.
  • Develop PowerShell automation and integrate Microsoft Graph, REST APIs, JSON, and Git.
  • Monitor and troubleshoot identity services using Splunk, KQL, and CrowdStrike IDP.
  • Support identity lifecycle, RBAC, access governance, audit, and regulatory compliance.
  • Collaborate with engineering, business, security, and vendor teams to deliver technical solutions.
  • Mentor engineers and provide technical guidance.
  • Serve as a technical SME for identity, authentication, and infrastructure technologies.
  • Develop technical designs, standards, documentation, and implementation solutions.
  • Troubleshoot complex technical issues and apply industry best practices.
  • Support risk management, security, audit, and regulatory requirements.
  • Mentor and coach technical staff.
  • Review technical documentation, designs, and proposed changes.
  • Coordinate vendor resources as needed.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service