Senior Active Directory Engineer

mtb

Buffalo (NY)

Hybrid

USD 97,000 - 162,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

M&T Bank is recruiting for a senior Active Directory architect to design, secure, and operate AD DS in regulated, high-availability environments in Buffalo, NY. The role includes mentoring engineers and delivering complex identity projects in a highly controlled setting.

The candidate will work four days onsite at Seneca One Buffalo with one day of remote work weekly, focusing on hybrid identity, Entra ID, and security best practices. Strong regulatory experience is required.

Qualifications

  • Bachelor's degree and 3+ years in AD engineering, or 7+ years combined education/experience.
  • Proven expertise in large-scale AD, multi-domain/forest designs.
  • Experience with Entra ID integration and hybrid identity security.

Responsibilities

  • Design, secure, and operate AD DS in regulated, high-availability environments.
  • Lead and mentor engineers on directory services and security.
  • Implement automations with PowerShell for provisioning and audits.
  • Ensure controls for regulatory frameworks (SOX, PCI DSS, SOC 2) through logging and audit readiness.

Skills

Active Directory
Azure AD
Security hardening
PowerShell
Regulatory compliance
Zero Trust

Education

Bachelor's degree / 7+ years experience

Tools

Entra Connect
Privileged Identity Management (PIM)
DNS tooling

Job description

This role is four days onsite at our Seneca One Buffalo, NY location, with the flexibility to work from home one day per week

Overview

Responsible for designing, securing, and operating Microsoft Active Directory Domain Services (AD DS) in regulated, high-availability environments. Acts as knowledge resource for and trains less experienced engineers. Completes day-to-day support activities and special projects.

Primary Responsibilities
  • Enterprise Active Directory Architecture
    • Proven expertise supporting large-scale, Tier‑1 identity infrastructures with strict uptime, latency, and change‑control requirements
    • Strong experience with:
    • Multi-domain and multi-forest designs aligned to business units, regions, or regulatory boundaries
    • Forest and external trusts supporting M&A, joint ventures, and third-party integrations
    • FSMO role placement optimized for resilience and auditability
    • Advanced understanding of Active Directory-integrated DNS , split‑brain DNS, and secure name resolution models
  • Hybrid Identity & Microsoft Entra ID (Azure AD)
    • Extensive experience integrating on-prem AD with Microsoft Entra ID in regulated financial environments
    • Hands‑on implementation of:
    • Entra Connect (Cloud Sync and Traditional)
    • Password Hash Sync, Pass‑through Authentication, and Federation
    • Strong experience with:
    • Conditional Access aligned to regulatory and risk-based controls
    • Hybrid Join, Entra ID Join, and legacy device coexistence
    • Understanding of identity lifecycle controls to support joiners, movers, leavers, and separation‑of‑duties requirements
  • Security, Compliance & Risk Controls
    • Expert‑level knowledge of Active Directory security hardening in financial services, including:
    • Tiered administrative model (Tier 0/1/2)
    • Dedicated admin forests or hardened admin boundaries (where applicable)
    • Privileged Access Workstations (PAWs) / Secure Admin Workstations
    • Experience enforcing least privilege , role separation, and dual‑control models
    • Deep familiarity with threats targeting financial institutions:
    • Credential theft, Kerberoasting, Pass‑the‑Hash/Ticket
    • Delegation and ACL abuse
    • Hands‑on experience with:
    • Privileged Identity Management (PIM)
    • Regular access reviews and entitlement recertification
    • Strong alignment with Zero Trust and defense‑in‑depth identity strategies
  • Regulatory & Audit Readiness
    • Demonstrated experience supporting audits and controls for financial regulations and frameworks, such as:
    • SOX, GLBA, PCI DSS, SOC 2
    • Internal risk management and model governance requirements
    • Ability to design AD environments that support:
    • Strong logging and traceability
    • Tamper‑resistant audit logs
    • Evidence generation for internal and external auditors
  • Automation & PowerShell
    • Advanced PowerShell expertise for:
    • Controlled, auditable administrative changes
    • Automated provisioning/deprovisioning aligned to compliance workflows
    • Identity reporting for risk, security, and audit teams
    • Experience building automation that integrates with:
    • Change management processes
    • IAM, ticketing, and security tooling
  • Operations, Resilience & Recovery
    • Deep experience managing:
    • AD replication topology across data centers and regions
    • SYSVOL (DFSR) health and recovery
    • Latency‑sensitive authentication dependencies
    • Strong understanding of:
    • AD backup, recovery, and authoritative restore procedures
    • Identity disaster recovery scenarios with defined RTO/RPO
    • Experience implementing monitoring and alerting with a focus on early risk detection
  • Leadership & Governance
    • Acts as technical authority and escalation point for all directory and identity services
    • Defines and enforces:
    • Enterprise identity standards
    • Secure configuration baselines
    • Operational runbooks and procedures
    • Partners closely with:
    • Information Security and IAM teams
    • Risk, audit, and compliance stakeholders
    • Infrastructure, cloud, and application teams
    • Mentors engineers and reviews designs from a security and risk‑first perspective
Education and Exp erience Required
  • Bachelor's degree and a minimum of 3 years' relevant work experience, or in lieu of a degree, a combined minimum of 7 years' higher education and/or work experience
Education and Experience Preferred
  • Intermediate understanding of the security system development and infrastructure lifecycle and architecture, and systems design
  • Proven experience with the tools utilized in assigned Cybersecurity function
  • Experience translating architecture into technical requirements.
  • Proficient level of critical thinking and problem solving
  • Excellent written and verbal communication skills
  • Proven experience collaborating with leaders to execute results.
  • Prior experience seeking buy‑in of others to align on processes.
  • Ability to analyze and draw conclusions based on quantitative data from multiple sources.

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $97,100.00 - $161,800.00 (USD). The successful candidate's particular combination of knowledge, skills, a

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Active Directory Engineer
Senior Active Directory Engineer

M&T Bank • Buffalo (NY)

Hybrid
USD 97,000 - 162,000
Identity & Access Management Specialist (Active Directory • Microsoft Entra ID • CyberArk) - Hybrid
Identity & Access Management Specialist (Active Directory • Microsoft Entra ID • CyberArk) - Hybrid

M&T Bank • Buffalo (NY)

Hybrid
USD 62,000 - 104,000
Principal Cybersecurity Infrastructure Engineer
Principal Cybersecurity Infrastructure Engineer

M&T Bank • Buffalo (NY)

Hybrid
USD 140,000 - 233,000
Senior PAM Engineer
Senior PAM Engineer

M&T Bank • Buffalo (NY)

Hybrid
USD 97,000 - 162,000
Sr. Systems Engineer (Active Directory)
Sr. Systems Engineer (Active Directory)

Berkley Technology Services • Urbandale (IA)

On-site
USD 107,000 - 198,000
Senior Active Directory & Identity Security Engineer
Senior Active Directory & Identity Security Engineer

M&T Bank • Buffalo (NY)

Hybrid
USD 97,000 - 162,000
Sr. Systems Engineer (Active Directory)
Sr. Systems Engineer (Active Directory)

Berkley Technology Services • Wilmington (DE)

On-site
USD 107,000 - 198,000
Health insurance
Dental coverage
Vision plan
+4
Sr. Systems Engineer (Active Directory)
Sr. Systems Engineer (Active Directory)

Berkley Technology Services • Manassas (VA)

On-site
USD 107,000 - 198,000
CISO Technical Lead Directory Services Engineer (DS)
CISO Technical Lead Directory Services Engineer (DS)

Tata Consultancy Services • Jacksonville (FL)

On-site
USD 100,000 - 130,000
Principal Identity Security Engineer - AD & MS Entra ID
Principal Identity Security Engineer - AD & MS Entra ID

MathWorks • Natick (MA)

Hybrid
USD 136,900 - 219,000