Senior Active Directory Engineer

M&T Bank
Buffalo, NY, United States
about 1 month ago
Apply on mtb.wd5.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$97,100.0 - $161,800.0
Working hours
Shift work

Tech stack

Active Directory User Authentication Cloud Computing Cyber Security Data Centers Disaster Recovery Domain Name System (DNS) Identity and Access Management Name Server PCI Data Security Standards Windows PowerShell Role-Based Access Control
+7 more
Azure Active Directory Zero Trust Network Access Runbook Systems Integration Data Logging Low Latency Integration Frameworks

Job description

Responsible for designing, securing, and operating Microsoft Active Directory Domain Services (AD DS) in regulated, high-availability environments. Acts as knowledge resource for and trains less experienced engineers. Completes day-to-day support activities and special projects., Enterprise Active Directory Architecture

  • Proven expertise supporting large-scale, Tier-1 identity infrastructures with strict uptime, latency, and change-control requirements
  • Strong experience with:
  • Multi-domain and multi-forest designs aligned to business units, regions, or regulatory boundaries
  • Forest and external trusts supporting M&A, joint ventures, and third-party integrations
  • FSMO role placement optimized for resilience and auditability
  • Advanced understanding of Active Directory-integrated DNS, split-brain DNS, and secure name resolution models

Hybrid Identity & Microsoft Entra ID (Azure AD)

  • Extensive experience integrating on-prem AD with Microsoft Entra ID in regulated financial environments
  • Hands-on implementation of:
  • Entra Connect (Cloud Sync and Traditional)
  • Password Hash Sync, Pass-through Authentication, and Federation
  • Strong experience with:
  • Conditional Access aligned to regulatory and risk-based controls
  • Hybrid Join, Entra ID Join, and legacy device coexistence
  • Understanding of identity lifecycle controls to support joiners, movers, leavers, and separation-of-duties requirements

Security, Compliance & Risk Controls

  • Expert-level knowledge of Active Directory security hardening in financial services, including:
  • Tiered administrative model (Tier 0/1/2)
  • Dedicated admin forests or hardened admin boundaries (where applicable)
  • Privileged Access Workstations (PAWs) / Secure Admin Workstations
  • Experience enforcing least privilege, role separation, and dual-control models
  • Deep familiarity with threats targeting financial institutions:
  • Credential theft, Kerberoasting, Pass-the-Hash/Ticket
  • Delegation and ACL abuse
  • Hands-on experience with:
  • Privileged Identity Management (PIM)
  • Regular access reviews and entitlement recertification
  • Strong alignment with Zero Trust and defense-in-depth identity strategies, * Acts as technical authority and escalation point for all directory and identity services
  • Defines and enforces:
  • Enterprise identity standards
  • Secure configuration baselines
  • Operational runbooks and procedures
  • Partners closely with:
  • Information Security and IAM teams
  • Risk, audit, and compliance stakeholders
  • Infrastructure, cloud, and application teams
  • Mentors engineers and reviews designs from a security and risk-first perspective

Requirements

  • Demonstrated experience supporting audits and controls for financial regulations and frameworks, such as:
  • SOX, GLBA, PCI DSS, SOC 2
  • Internal risk management and model governance requirements
  • Ability to design AD environments that support:
  • Strong logging and traceability
  • Tamper-resistant audit logs
  • Evidence generation for internal and external auditors

Automation & PowerShell

  • Advanced PowerShell expertise for:
  • Controlled, auditable administrative changes
  • Automated provisioning/deprovisioning aligned to compliance workflows
  • Identity reporting for risk, security, and audit teams
  • Experience building automation that integrates with:
  • Change management processes
  • IAM, ticketing, and security tooling

Operations, Resilience & Recovery

  • Deep experience managing:
  • AD replication topology across data centers and regions
  • SYSVOL (DFSR) health and recovery
  • Latency-sensitive authentication dependencies
  • Strong understanding of:
  • AD backup, recovery, and authoritative restore procedures
  • Identity disaster recovery scenarios with defined RTO/RPO
  • Experience implementing monitoring and alerting with a focus on early risk detection, * Bachelor’s degree and a minimum of 3 years’ relevant work experience, or in lieu of a degree, a combined minimum of 7 years’ higher education and/or work experience

Education and Experience Preferred:

  • Intermediate understanding of the security system development and infrastructure lifecycle and architecture, and systems design
  • Proven experience with the tools utilized in assigned Cybersecurity function
  • Experience translating architecture into technical requirements.
  • Proficient level of critical thinking and problem solving
  • Excellent written and verbal communication skills
  • Proven experience collaborating with leaders to execute results.
  • Prior experience seeking buy-in of others to align on processes.
  • Ability to analyze and draw conclusions based on quantitative data from multiple sources.

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $97,100.00 - $161,800.00 (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on mtb.wd5.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:15 min

Scaling IT operations for a major finance cloud

Linda Linda +1 · World Congress 2024

1:35 min

Translating domain names to server IP addresses

Shem Magnezi Shem Magnezi · World Congress 2025

1:46 min

Understanding how Pathway ensures low latency data processing

Bobur Umurzokov · LIVE

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

2:42 min

Handling AWS naming restrictions with Terraform built-in functions

Thomas Hartenstein · LIVE

5:48 min

Balancing delivery latency with stream reliability and scale

Phil Cluff · LIVE

Videos

See all

Related articles

See all