AD Security & Authentication Engineer

Cloudicagroup

United States

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Opportunity to work with modern technologies
Training and development in Microsoft solutions
Sports package and private medical care

Job summary

A technology solutions provider is seeking an Active Directory Security & Trust Engineer for a U.S.-based project. This role focuses on enhancing Active Directory security through hardening, trust remediation, and implementing best practices. The ideal candidate will have extensive experience with enterprise Active Directory and strong skills in security management and PowerShell automation. This opportunity offers a collaborative environment and exposure to modern technologies.

Qualifications

  • 4 years of experience in enterprise Active Directory engineering with a focus on security.
  • Practical experience interpreting reports and Splunk logs.
  • Strong understanding of authentication protocols including Kerberos and NTLM.

Responsibilities

  • Analyze multi-source security data to improve Active Directory security.
  • Implement and tune tiering policies and restrictive GPOs.
  • Manage Active Directory trust relationships.

Skills

Active Directory engineering
Security hardening
Authentication management
PowerShell proficiency
Strong communication skills

Tools

Splunk
CrowdStrike
PingCastle

Job description

Overview

We’re seeking an Active Directory Security & Trust Engineer for a US-based project focused on AD hardening and trust remediation in large, multi-forest enterprise environments. You’ll strengthen authentication, apply tiering models, and implement modern security controls to align with best practices and CIS standards.

Responsibilities
  • Analyze multi-source security data (Splunk) to assess and execute Active Directory domain hardening and trust/security improvements.
  • Implement and tune tiering policies (Tier-0/1/2) and restrictive GPOs; remediate risky privileged access, cross-tier logons, and privileged group exposures.
  • Manage and optimize Active Directory trust relationships, including mapping cross-domain usage, identifying app/service dependencies, and implementing trust removals or conversions to one-way/selective authentication.
  • Align Domain Controllers with CIS baseline security standards, including encryption protocols and authentication methods; migrate away from legacy encryption (e.g., RC4) and reduce NTLMv1 usage.
  • Collaborate with domain and application owners to assess risks, plan change windows, validate remediation and trust changes, including fallback plans if needed.
  • Produce clear, actionable remediation plans and reports, track progress in SIEM and spreadsheets, and support verification and change management processes.
Qualifications
  • 4 years of experience in enterprise Active Directory engineering with strong focus on security hardening and trust/authentication management in multi-forest environments (over 50,000 identities).
  • Practical experience interpreting reports, Splunk logs and trust authentication paths.
  • In-depth knowledge of GPO, OU, privileged access models (Tier-0/1/2).
  • Strong understanding and working knowledge of authentication protocols including Kerberos, NTLM, encryption modes (RC4 vs AES), selective authentication, SID filtering, and constrained delegation.
  • PowerShell proficiency for querying, reporting, and automation of AD tasks.
  • Excellent communication skills to liaise effectively with technical teams, application owners, and management.

Nice to have: Hands-on experience with PingCastle and CrowdStrike tools.

What we offer
  • Opportunity to work with modern technologies.
  • A friendly work environment within a team of professionals.
  • Training and development in Microsoft solutions and security systems.
  • Growth through collaboration with a U.S.-based client and exposure to enterprise-scale security operations.
  • Hands-on learning of advanced tools such as CrowdStrike and PingCastle.
  • A rewarding and transparent commission system.
  • Sports package and private medical care.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Windows Active Directory Architect
Windows Active Directory Architect

PRI Technology • New York (NY)

On-site
USD 120,000 - 180,000
App Sec Engineer - Charlotte, Nc
App Sec Engineer - Charlotte, Nc

Motion Recruitment Partners LLC • Charlotte (NC)

On-site
USD 110,000 - 150,000
Medical Insurance
Dental Benefits
Vision Benefits
+2
App Sec Engineer - Charlotte, Nc
App Sec Engineer - Charlotte, Nc

Motion Recruitment • Charlotte (NC)

On-site
USD 100,000 - 150,000
Medical Insurance
Dental Benefits
Vision Benefits
+2
Identity Engineer
Identity Engineer

ManpowerGroup Global, Inc. • Spring (TX)

On-site
USD 90,000 - 120,000
Active Directory Engineer
Active Directory Engineer

Perennial Resources International • New York (NY)

On-site
USD 120,000 - 150,000
Active Directory Engineer
Active Directory Engineer

Arctiq: Intelligent Architecture • Duluth (GA)

On-site
USD 90,000 - 130,000
AD Security Automation Engineer - BACJP00221956
AD Security Automation Engineer - BACJP00221956

Insight Global • Chandler (AZ)

On-site
USD 100,000 - 130,000
Active Directory Specialist
Active Directory Specialist

Compunnel, Inc. • Richmond (VA)

On-site
USD 100,000 - 130,000
AD Security & Trust Engineer: Identity Hardening & Compliance
AD Security & Trust Engineer: Identity Hardening & Compliance

Cloudicagroup • United States

Remote
USD 100,000 - 130,000
Senior Automation Developer
Senior Automation Developer

XMS Solutions • Washington

On-site
USD 140,000 - 170,000