> Markdown version of [/jobs/ext/204727-senior-active-directory-cloud-identity](https://www.wearedevelopers.com/jobs/ext/204727-senior-active-directory-cloud-identity). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Active Directory - Cloud Identity... - **Company:** Bank of America - **Location:** Boston, MA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Active Directory, Active Directory Federation Services, Audit Trail, Microsoft Azure, Domain Name System (DNS), Federated Identity Management, Identity and Access Management, Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Ping (Networking Utility), Public Key Infrastructure, Windows PowerShell, Role-Based Access Control, Openid Connect, Azure Active Directory, Cloud Services, Zero Trust Network Access, Security Assertion Markup Language (SAML), Single Sign-On, TCP/IP, Transport Layer Security, Okta, Cyberark, Firewalls (Computer Science), Cloud Migration, SailPoint - **Published:** May 24, 2026 - **Apply:** https://www.juju.com/job/00000000g20n2p ## About the Role + 10+ years of hands-on experience administering and engineering enterprise Active Directory in a large, multi-site environment. + Strong expertise in: AD forest/domain design, trusts, DNS, Group Policy, replication, and AD security hardening. + 5+ years working with Azure AD/Entra ID and hybrid identity (synchronization, federation, ADFS or equivalent, cloud-only and hybrid scenarios). + Deep understanding of identity and access management concepts: authentication, authorization, RBAC, least privilege, PAM, Zero Trust. + Strong experience with MFA, Conditional Access, SSO, and identity federation using SAML, OAuth2, and OpenID Connect. + Proficiency with PowerShell for automation, reporting, and bulk operations in AD and Azure AD. + Experience operating in regulated environments (preferably banking/financial services) with audit, risk, and compliance requirements. + Solid understanding of networking and security fundamentals (TCP/IP, firewalls, TLS, certificates, PKI as it relates to identity). + Excellent communication skills and ability to translate technical identity risks and solutions for non-technical stakeholders. Desired Qualifications: + Experience with IAM platforms such as Okta, Ping, ForgeRock, SailPoint, or similar. + Experience with AWS IAM and/or GCP IAM and integrating them with corporate identity. + Background with PAM solutions (CyberArk, Delinea/Thycotic, BeyondTrust, Hashi, etc.). + Relevant certifications: Microsoft Certified: Identity and Access Administrator Associate, Azure Administrator, Security Engineer, or equivalent. ## Description We are seeking a Senior Directory Services analyst to modernize our enterprise identity platform across on-prem Active Directory, LDAP's, and other cloud-based directories and stores. The role is focused on securing employee, partner, and application access in a highly-regulated financial services environment and will partner closely with security, infrastructure, and application teams. If you are passionate about identity security and thrive in high-stakes environments, this role offers the chance to make a measurable impact on the security posture of a global enterprise., + **Lead architecture, engineering, and operations for Active Directory forests, domains, and Group Policy** in a multi-site, highly regulated environment. + **Design and drive adoption of hybrid identity solutions** integrating on-prem and cloud-based services. + **Implement and optimize authentication and authorization controls:** SSO, MFA, Conditional Access, identity protection, and modern protocols (SAML, OAuth2, OIDC). + **Define and enforce standards for identity lifecycle** : joiner/mover/leaver processes, automated provisioning/deprovisioning, access reviews, and role-based access control (RBAC). + **Partner with stakeholders** and business teams to implement least-privilege, privileged access management (PAM), and Zero Trust-aligned identity controls. + **Lead and support AD and identity-related projects** : domain/forest consolidation, mergers/acquisitions, cloud migrations, and re-platforming. + **Enhance monitoring, alerting, and reporting** for directory and identity health, security posture, and compliance (audit trails, SOX, GLBA, PCI, etc.) + **Develop and maintain scripts and automation** (primarily PowerShell) to drive consistency, efficiency, and security in identity operations. + **Serve as a senior SME and escalation point** for complex identity incidents, outages, and security events. + **Produce and maintain technical documentation** , runbooks, standards, and architecture diagrams for AD and cloud identity services. + Mentor and guide **junior engineers, analysts, and admins** and contribute to identity and access strategy and roadmap., Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates. View your **"Know your Rights (https://www.eeoc.gov/sites/default/files/2023-06/22-088\_EEOC\_KnowYourRights6.12.pdf) "** poster. View the LA County Fair Chance Ordinance (https://dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf) . ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [The Best Job Search Websites of 2025](https://www.wearedevelopers.com/magazine/368-the-best-job-search-websites-of-2025) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Best Companies to Work For in Berlin: Top 14 Companies in 2023 ](https://www.wearedevelopers.com/magazine/188-best-companies-to-work-for-in-berlin-top-14-companies-in-2023) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)