Active Directory Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+16 more
Job description
-
Operationalize automated data discovery, classification, and inventory; apply sensitivity labels and consistent taxonomy across data stores, pipelines, and collaboration systems.
-
Engineer DSPM capabilities with tools (e.g., Securiti, BigID) to surface data posture risks (overexposure, shadow data, stale sensitive data) and drive remediation workflows.
-
Implement and support encryption, tokenization, masking, anonymization/pseudonymization for data at rest and in transit; integrate with cloud key management systems and enforce approved cryptographic standards; define crypto baselines and policy-as-code guardrails.
-
Configure and govern access controls with RBAC/ABAC and purpose-based authorization; perform least-privilege and fine-grained access reviews across data platforms.
-
Deploy, tune, and operate DLP and DAM solutions (e.g., Microsoft Purview DLP, Imperva/Guardium); build detections for PII/PCI/PHI and reduce false positives with policy and context improvements.
-
Integrate and tune UEBA and Insider Risk signals to detect anomalous data access and exfiltration, partner on response workflows and preventive control changes.
-
Integrate data protection telemetry with SIEM/SOAR; build detections, correlation rules, and automated response playbooks for data-related threats and policy violations.
-
Implement data minimization and retention/ROT enforcement patterns; automate monitoring of lifecycle actions (archive, delete, redact) aligned to policy and legal holds.
-
Implement DSAR (data subject access request) orchestration and fulfillment with SLA monitoring; automate data collection, redaction, and secure delivery with audit trails.
-
Contribute to cookie/tag governance and catalog assurance; validate consent signals, storage durations, and vendor script behavior against policy.
-
Support privacy platform capabilities and integrate with identity, ticketing, data catalogs/lineage, and evidence repositories.
-
Embed data protection and privacy-by-design controls into services and CI/CD (pre-commit/CI privacy code scanning, secret scanning, schema checks for sensitive fields, data egress policies).
-
Produce compliance evidence and reports for GDPR/CCPA/CPRA, PCI DSS, HIPAA, and internal audits; maintain controls health dashboards, regulatory tracking, and program KPIs.
-
Investigate data-related incidents and privacy events in partnership with IR/SOC/Privacy Office. Collect artifacts, support forensics, document findings, and drive preventive engineering fixes.
-
Conduct platform hardening and vulnerability remediation for data control tooling (misconfigurations, exposed buckets, weak crypto, excessive permissions).
-
Participate in red teaming/tabletop exercises for data scenarios (insider misuse, public link exposures, unintended AI training data); translate findings into control improvements.
-
Partner with Cybersecurity, Privacy Office, Enterprise Data, Legal, and product/platform teams to align designs and deliver privacy- and data protection-by-design outcomes.
-
Document engineering patterns, runbooks, and reference architectures; create training and technical guidance that strengthen secure data handling practices across teams.
-
Communicate clearly and concisely with technical and non-technical audiences - summarize incidents, risks, and recommended actions with accurate, complete context.
Requirements
- 3-7 years of hands-on experience in:
- Active Directory administration/engineering
- Microsoft Entra ID (Azure AD)
- Azure AD Connect / hybrid identity environments
- Experience with:
- AD security hardening
- Identity-related attack techniques (privilege escalation, lateral movement)
- Attack path analysis or remediation activities
- Strong working knowledge of:
- Tier 0 concepts and identity as a control plane
- Authentication protocols (Kerberos, NTLM, SAML, OAuth)
Preferred Experience
- Exposure to:
- CyberArk or other PAM tools
- Saviynt or similar IGA platforms
- Ping Identity or federation solutions
- HashiCorp Vault, Keyfactor, or PKI environments
- Experience supporting AD forest recovery exercises
- Familiarity with Zero Trust principles
Key Traits for Success
- Strong execution and delivery focus
- Security and resiliency mindset
- Ability to quickly identify and remediate risks
- Works effectively in a cross-functional cybersecurity environment
- Comfortable working in fast-paced, project-driven (contract) engagements
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Everything a Developer Needs to Know About MCP with Neo4j
9 Ways to Make Money Hacking
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again