Job Description A technology-forward enterprise in Charlotte, NC is hiring for an Active Directory Security (AD Sec) Engineer to advance and secure its enterprise authentication and directory services infrastructure. As an AD Sec Engineer, you will be responsible for the end-to-end lifecycle of Active Directory security operations, helping ensure robust access control and compliance for a diverse and dynamic user base.
In this position, you will engineer and support secure AD and Azure AD environments, manage privileged identities, lead hardening efforts, and design policies that prevent unauthorized access. You will drive incident response for directory-based attacks, work hands-on with authentication protocols, oversee the integration of security tools, and automate security tasks for both on-prem and cloud-connected domains. Responsibilities will also include maintaining technical documentation, supporting audits, and identifying opportunities to enhance identity governance controls.
Required Skills & Experience - Strong expertise in Active Directory and Azure Active Directory security
- Background implementing and managing identity governance solutions and privileged access management (PAM)
- Skilled in authentication and authorization protocols (Kerberos, NTLM, LDAP, OAuth, SAML)
- Hands-on experience with security hardening, access reviews, and incident response for directory attacks
- Proficient with PowerShell or equivalent scripting for automation
- Bachelor's degree in information security, Computer Science, or related field or equivalent experience
Desired Skills & Experience - Hands-on integration of security monitoring and SIEM solutions (e.g., Splunk, Sentinel)
- Familiarity with regulatory requirements and audits related to directory services
- Experience deploying Zero Trust and least-privilege access models
- Relevant certifications such as Microsoft Certified: Security, Compliance, and Identity Fundamentals
What You Will Be Doing Daily Responsibilities
100% Hands On
- Monitor, analyze, and respond to security events within Active Directory and Azure AD
- Engineer improvements to directory hardening, object protection, and delegation controls
- Manage identity lifecycle, including onboarding, changes, and offboarding for privileged and sensitive accounts
- Automate routine security tasks, access reviews, and reporting via scripts and orchestration tools
- Partner with internal teams on security integration projects, GPO enforcement, and multifactor authentication
- Document technical standards, configurations, and remediation processes
The Offer Bonus OR Commission eligible
You will receive the following benefits
- Medical Insurance
- Dental Benefits
- Vision Benefits
- Paid Time Off (PTO)
- 401(k) {including match - if applicable}
Applicants must be currently authorized to work in the US on a full-time basis now and in the future