Haystack
← Back to Jobs
Technology
AC

Active Directory Engineer

Apetan ConsultingJersey City, NJ🇺🇸United StatesPosted 24 Aug 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Jersey City, NJ, United States
Posted
Yesterday
RESTAzureVaultOAuthSAMLActive DirectoryHIPAAGDPRPCI DSSEncryptionPKIZero Trust

Job Description

Role: Active Directory Engineer

Remote

 

Description:

 

  • Operationalize automated data discovery, classification, and inventory; apply sensitivity labels and consistent taxonomy across data stores, pipelines, and collaboration systems.  
  • Engineer DSPM capabilities with tools (e.g., Securiti, BigID) to surface data posture risks (overexposure, shadow data, stale sensitive data) and drive remediation workflows.  
  • Implement and support encryption, tokenization, masking, anonymization/pseudonymization for data at rest and in transit; integrate with cloud key management systems and enforce approved cryptographic standards; define crypto baselines and policy-as-code guardrails.  
  • Configure and govern access controls with RBAC/ABAC and purpose-based authorization; perform least-privilege and fine-grained access reviews across data platforms.  
  • Deploy, tune, and operate DLP and DAM solutions (e.g., Microsoft Purview DLP, Imperva/Guardium); build detections for PII/PCI/PHI and reduce false positives with policy and context improvements.  
  • Integrate and tune UEBA and Insider Risk signals to detect anomalous data access and exfiltration, partner on response workflows and preventive control changes.  
  • Integrate data protection telemetry with SIEM/SOAR; build detections, correlation rules, and automated response playbooks for data-related threats and policy violations.  
  • Implement data minimization and retention/ROT enforcement patterns; automate monitoring of lifecycle actions (archive, delete, redact) aligned to policy and legal holds.  
  • Implement DSAR (data subject access request) orchestration and fulfillment with SLA monitoring; automate data collection, redaction, and secure delivery with audit trails.  
  • Contribute to cookie/tag governance and catalog assurance; validate consent signals, storage durations, and vendor script behavior against policy.  
  • Support privacy platform capabilities and integrate with identity, ticketing, data catalogs/lineage, and evidence repositories.  
  • Embed data protection and privacy-by-design controls into services and CI/CD (pre-commit/CI privacy code scanning, secret scanning, schema checks for sensitive fields, data egress policies).  
  • Produce compliance evidence and reports for GDPR/CCPA/CPRA, PCI DSS, HIPAA, and internal audits; maintain controls health dashboards, regulatory tracking, and program KPIs.  
  • Investigate data-related incidents and privacy events in partnership with IR/SOC/Privacy Office. Collect artifacts, support forensics, document findings, and drive preventive engineering fixes.  
  • Conduct platform hardening and vulnerability remediation for data control tooling (misconfigurations, exposed buckets, weak crypto, excessive permissions).  
  • Participate in red teaming/tabletop exercises for data scenarios (insider misuse, public link exposures, unintended AI training data); translate findings into control improvements.  
  • Partner with Cybersecurity, Privacy Office, Enterprise Data, Legal, and product/platform teams to align designs and deliver privacy- and data protection-by-design outcomes.  
  • Document engineering patterns, runbooks, and reference architectures; create training and technical guidance that strengthen secure data handling practices across teams. 
  • Communicate clearly and concisely with technical and non‑technical audiences - summarize incidents, risks, and recommended actions with accurate, complete context. 

 

Required Skills & Experience

  • 3–7 years of hands-on experience in:
    • Active Directory administration/engineering
    • Microsoft Entra ID (Azure AD)
    • Azure AD Connect / hybrid identity environments
  • Experience with:
    • AD security hardening
    • Identity-related attack techniques (privilege escalation, lateral movement)
    • Attack path analysis or remediation activities
  • Strong working knowledge of:
    • Tier 0 concepts and identity as a control plane
    • Authentication protocols (Kerberos, NTLM, SAML, OAuth)

 

Preferred Experience

  • Exposure to:
    • CyberArk or other PAM tools
    • Saviynt or similar IGA platforms
    • Ping Identity or federation solutions
    • HashiCorp Vault, Keyfactor, or PKI environments
  • Experience supporting AD forest recovery exercises
  • Familiarity with Zero Trust principles

 

Key Traits for Success

  • Strong execution and delivery focus
  • Security and resiliency mindset
  • Ability to quickly identify and remediate risks
  • Works effectively in a cross-functional cybersecurity environment
  • Comfortable working in fast-paced, project-driven (contract) engagements

 

Similar jobs