Must be a US Citizen or Green Card Holder
Must be able to work hybrid from Buffalo, NY or Wilmington, DE or Bridgeport, CT
Job Summary: The Directory Services Engineer will be responsible for designing, implementing, and maintaining our Active Directory and Entra ID (Azure AD) environments. This role requires a deep understanding of directory services, identity management, and security protocols to support our banking operations.
Key Responsibilities:
- Design, build, and maintain Active Directory and Entra ID environments.
- Manage multiple Active Directory forests and domains, ensuring high availability and performance.
- Implement and manage security measures to protect directory services and related infrastructure.
- Execute integrations of new domains arising from mergers and acquisitions.
- Develop and maintain documentation for directory services configurations, processes, and service records.
- Collaborate with IT security teams to establish and maintain security baselines and respond to security incidents.
- Develop and execute PowerShell scripts for automation of tasks, system management, and troubleshooting.
- Manage relevant licensing for directory services systems, ensuring compliance with legal and contractual obligations.
- Support migration of PKI from Windows CA to KeyFactor.
- Implement and manage OIDC/SAML authentication for systems and application access with SSO.
Qualifications:
- Bachelor's degree in Computer Science, Information Technology, or a related field.
- Minimum of 5 years of experience in directory services administration and engineering.
- Strong experience with Active Directory, Entra ID (Azure AD), ADFS, Group Policy, OIDC/SAML, and PKI technologies.
- Proficiency in using Azure DevOps/JIRA, Splunk, and PowerShell for system management.
- Knowledge of ITIL practices and NIST cybersecurity standards.
- Excellent problem-solving skills and the ability to work in a fast-paced environment.
- Strong communication and collaboration skills.
** Knowledge of EntraID or Any Identity Providers (Ping, Opta)**
** Knowledge of Open SSO protocol**
** General IAM experience**