> Markdown version of [/jobs/ext/2642659-active-directory-engineer](https://www.wearedevelopers.com/jobs/ext/2642659-active-directory-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Active Directory Engineer - **Company:** Apetan Consulting - **Location:** New York, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Active Directory, Authentication Protocols, Cyber Security, Continuous Integration, Data Control, Data Discovery, Data Security, Data Stores, Kerberos (Protocol), Key Management, Metadata Repositories, Network Control, NT LAN Manager, OAuth, PCI Data Security Standards, Ping (Networking Utility), Public Key Infrastructure, Role-Based Access Control, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Information and Event Management, Software Vulnerability Management, Enterprise Data Management, Policy as Code, Cyberark, Hashicorp, Data Management - **Published:** August 25, 2026 - **Apply:** https://www.dice.com/job-detail/1c6401ca-994d-444a-b588-a9eb9707cb0b ## About the Role * 3-7 years of hands-on experience in: + Active Directory administration/engineering + Microsoft Entra ID (Azure AD) + Azure AD Connect / hybrid identity environments * Experience with: + AD security hardening + Identity-related attack techniques (privilege escalation, lateral movement) + Attack path analysis or remediation activities * Strong working knowledge of: + Tier 0 concepts and identity as a control plane + Authentication protocols (Kerberos, NTLM, SAML, OAuth) Preferred Experience * Exposure to: + CyberArk or other PAM tools + Saviynt or similar IGA platforms + Ping Identity or federation solutions + HashiCorp Vault, Keyfactor, or PKI environments * Experience supporting AD forest recovery exercises * Familiarity with Zero Trust principles Key Traits for Success * Strong execution and delivery focus * Security and resiliency mindset * Ability to quickly identify and remediate risks * Works effectively in a cross-functional cybersecurity environment * Comfortable working in fast-paced, project-driven (contract) engagements ## Description * Operationalize automated data discovery, classification, and inventory; apply sensitivity labels and consistent taxonomy across data stores, pipelines, and collaboration systems. * Engineer DSPM capabilities with tools (e.g., Securiti, BigID) to surface data posture risks (overexposure, shadow data, stale sensitive data) and drive remediation workflows. * Implement and support encryption, tokenization, masking, anonymization/pseudonymization for data at rest and in transit; integrate with cloud key management systems and enforce approved cryptographic standards; define crypto baselines and policy-as-code guardrails. * Configure and govern access controls with RBAC/ABAC and purpose-based authorization; perform least-privilege and fine-grained access reviews across data platforms. * Deploy, tune, and operate DLP and DAM solutions (e.g., Microsoft Purview DLP, Imperva/Guardium); build detections for PII/PCI/PHI and reduce false positives with policy and context improvements. * Integrate and tune UEBA and Insider Risk signals to detect anomalous data access and exfiltration, partner on response workflows and preventive control changes. * Integrate data protection telemetry with SIEM/SOAR; build detections, correlation rules, and automated response playbooks for data-related threats and policy violations. * Implement data minimization and retention/ROT enforcement patterns; automate monitoring of lifecycle actions (archive, delete, redact) aligned to policy and legal holds. * Implement DSAR (data subject access request) orchestration and fulfillment with SLA monitoring; automate data collection, redaction, and secure delivery with audit trails. * Contribute to cookie/tag governance and catalog assurance; validate consent signals, storage durations, and vendor script behavior against policy. * Support privacy platform capabilities and integrate with identity, ticketing, data catalogs/lineage, and evidence repositories. * Embed data protection and privacy-by-design controls into services and CI/CD (pre-commit/CI privacy code scanning, secret scanning, schema checks for sensitive fields, data egress policies). * Produce compliance evidence and reports for GDPR/CCPA/CPRA, PCI DSS, HIPAA, and internal audits; maintain controls health dashboards, regulatory tracking, and program KPIs. * Investigate data-related incidents and privacy events in partnership with IR/SOC/Privacy Office. Collect artifacts, support forensics, document findings, and drive preventive engineering fixes. * Conduct platform hardening and vulnerability remediation for data control tooling (misconfigurations, exposed buckets, weak crypto, excessive permissions). * Participate in red teaming/tabletop exercises for data scenarios (insider misuse, public link exposures, unintended AI training data); translate findings into control improvements. * Partner with Cybersecurity, Privacy Office, Enterprise Data, Legal, and product/platform teams to align designs and deliver privacy- and data protection-by-design outcomes. * Document engineering patterns, runbooks, and reference architectures; create training and technical guidance that strengthen secure data handling practices across teams. * Communicate clearly and concisely with technical and non-technical audiences - summarize incidents, risks, and recommended actions with accurate, complete context. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [Securing Secrets in the GitOps era](https://www.wearedevelopers.com/videos/546-securing-secrets-in-the-gitops-era) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)