Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
Jersey City, NJ, United States
Posted
Yesterday
RESTAzureVaultOAuthSAMLActive DirectoryHIPAAGDPRPCI DSSEncryptionPKIZero Trust
Job Description
Role: Active Directory Engineer
Remote
Description:
- Operationalize automated data discovery, classification, and inventory; apply sensitivity labels and consistent taxonomy across data stores, pipelines, and collaboration systems.
- Engineer DSPM capabilities with tools (e.g., Securiti, BigID) to surface data posture risks (overexposure, shadow data, stale sensitive data) and drive remediation workflows.
- Implement and support encryption, tokenization, masking, anonymization/pseudonymization for data at rest and in transit; integrate with cloud key management systems and enforce approved cryptographic standards; define crypto baselines and policy-as-code guardrails.
- Configure and govern access controls with RBAC/ABAC and purpose-based authorization; perform least-privilege and fine-grained access reviews across data platforms.
- Deploy, tune, and operate DLP and DAM solutions (e.g., Microsoft Purview DLP, Imperva/Guardium); build detections for PII/PCI/PHI and reduce false positives with policy and context improvements.
- Integrate and tune UEBA and Insider Risk signals to detect anomalous data access and exfiltration, partner on response workflows and preventive control changes.
- Integrate data protection telemetry with SIEM/SOAR; build detections, correlation rules, and automated response playbooks for data-related threats and policy violations.
- Implement data minimization and retention/ROT enforcement patterns; automate monitoring of lifecycle actions (archive, delete, redact) aligned to policy and legal holds.
- Implement DSAR (data subject access request) orchestration and fulfillment with SLA monitoring; automate data collection, redaction, and secure delivery with audit trails.
- Contribute to cookie/tag governance and catalog assurance; validate consent signals, storage durations, and vendor script behavior against policy.
- Support privacy platform capabilities and integrate with identity, ticketing, data catalogs/lineage, and evidence repositories.
- Embed data protection and privacy-by-design controls into services and CI/CD (pre-commit/CI privacy code scanning, secret scanning, schema checks for sensitive fields, data egress policies).
- Produce compliance evidence and reports for GDPR/CCPA/CPRA, PCI DSS, HIPAA, and internal audits; maintain controls health dashboards, regulatory tracking, and program KPIs.
- Investigate data-related incidents and privacy events in partnership with IR/SOC/Privacy Office. Collect artifacts, support forensics, document findings, and drive preventive engineering fixes.
- Conduct platform hardening and vulnerability remediation for data control tooling (misconfigurations, exposed buckets, weak crypto, excessive permissions).
- Participate in red teaming/tabletop exercises for data scenarios (insider misuse, public link exposures, unintended AI training data); translate findings into control improvements.
- Partner with Cybersecurity, Privacy Office, Enterprise Data, Legal, and product/platform teams to align designs and deliver privacy- and data protection-by-design outcomes.
- Document engineering patterns, runbooks, and reference architectures; create training and technical guidance that strengthen secure data handling practices across teams.
- Communicate clearly and concisely with technical and non‑technical audiences - summarize incidents, risks, and recommended actions with accurate, complete context.
Required Skills & Experience
- 3–7 years of hands-on experience in:
- Active Directory administration/engineering
- Microsoft Entra ID (Azure AD)
- Azure AD Connect / hybrid identity environments
- Experience with:
- AD security hardening
- Identity-related attack techniques (privilege escalation, lateral movement)
- Attack path analysis or remediation activities
- Strong working knowledge of:
- Tier 0 concepts and identity as a control plane
- Authentication protocols (Kerberos, NTLM, SAML, OAuth)
Preferred Experience
- Exposure to:
- CyberArk or other PAM tools
- Saviynt or similar IGA platforms
- Ping Identity or federation solutions
- HashiCorp Vault, Keyfactor, or PKI environments
- Experience supporting AD forest recovery exercises
- Familiarity with Zero Trust principles
Key Traits for Success
- Strong execution and delivery focus
- Security and resiliency mindset
- Ability to quickly identify and remediate risks
- Works effectively in a cross-functional cybersecurity environment
- Comfortable working in fast-paced, project-driven (contract) engagements
Similar jobs
- RI
Technical Support Engineer
NewRPA Infotech Digital Inc.
Chicago, IL🇺🇸On-siteYesterdaySQLShellAWS+8Technology - FB
Database Engineer III
First-Citizens Bank & Trust Company
Morristown, NJ🇺🇸Hybrid3 weeks agoMicroservicesOracleSQL+14Technology - BI
Senior All Source Analyst (Object Based Intelligence)
BigBear.ai
Washington, DC🇺🇸Hybrid7 weeks agoTechnology - FB
Cyber Security Analyst III - App Security and Vulnerability (Remote)
NewFirst-Citizens Bank & Trust Company
Austin, TX🇺🇸RemoteYesterdayAWSOWASPSOC 2+9Technology - FB
Business Systems Analyst III
NewFirst-Citizens Bank & Trust Company
Atlanta, GA🇺🇸HybridYesterdayAgileComplianceJava+3Technology - GT
Senior Principal Solution Architect
NewGainwell Technologies LLC
Kansas City, MO🇺🇸$138.8k - $198.3k/yrRemoteYesterdayTechnology