🌍 Global Remote Network: Over 120,085+ verified remote jobs with transparent salaries & visa sponsorship. Browse Remote Jobs →
T

Senior Actice Directory Engineer

📍 Chicago, IL 🕒
Work Model
📍 Chicago, IL
Employment
💼 Full-Time Direct
Recruitment Type
🛡️ Direct to HR Pipeline
🛡️
Human-Verified Opening: Inspected by Sarah Jenkins, CIPD • RemoteVault Editorial Team. Authenticated directly from TEKsystems's hiring pipeline • Zero recruiter markups or candidate fees. Verification Standards →

📋 Role Overview & Responsibilities

Sr Active Directory (IAM) Engineer

Not available for C2C, must be able to work without sponsorship.

Top Skills' Details

It is more important this person have AD experience (see requirements) than IAM experience, we can train on IAM, not AD.Very little training will be provided, as this candidate should come in with Sr level AD Engineering knowledge.Experience with Linux/Unix, Windows, SQL, LDAP, and web service.Mid level to Expert level with scripting (PowerShell is a must), -It is not expected that this hire develop, rather build out an environment, based off of an already developed system, thus why PowerShell scripting is important.

Team Info

Two engineers in total, including this role (AD focused) Five Operations Analysts (strictly IAM focused) This role will report into the IAM Manager This team sits in the Information Technology - Information Security Team

Summary Overall Of Team Function

The Engineers for the Identity & Access Management (IAM) function are responsible for identifying, delivering and supporting the technology used to deliver overall Identity & Access Management program, which is designed to ensure the user identities, accounts, credentials and system access are fully and completely managed for all system users. The Engineers are responsible for the current technology in place (Okta Verify/SSO, Microsoft/Azure AD, CyberArk, etc) and ensuring successful operations, interoperability and general well-being. S/he works proactively with IAM Manager, IAM technical staff and various IT and business departments to implement services that meet current and future IAM needs.

The AD Engineer is a proven technologist and a hands on problem solver, as well as, an effective internal consultant, who will regularly advise others on access and security/risk related issues. S/he must possess domain competencies in a number of related disciplines, including security, risk, access control, overseeing Active Directory (on premises and Cloud based) authentication, multi factor authentication and entitlements reviews.

Duties And Responsibilities Of Team Overall

Work with the IAM Manager to build out and oversee the IAM function’s technical controls and its related activities including planning, testing, reporting and delivering IAM services. Oversee the implementation of all current solutions to ensure they are configured appropriately and are delivering maximum value. Review current documentation such as Procedures, run books, and Knowledge Base Articles used by the Service Desk. Review and/or establish Best Practices where applicable Engage and interact with other IT Departmental Engineers to ensure future efforts (ours and their’s) result in continued uninterrupted delivery of all IAM services. Demonstrate extensive understanding of IAM concepts such as directory services, SSO, federation, MFA, provisioning, access certification, roles and SOD. The analysis, design, implementation, and maintenance of all layers of IAM applications, including Authorization / Authentication and Account Creation / Management / Provisioning / Retirement in data repositories. Including; strategy, organizational design, process re-engineering and technology implementation. Drive technology discussion and strategy in line with business needs to develop technology roadmap, including presentation of complex technical materials in simplified terms for non-technical audience. Functional areas and work experience should include; fine-grained access control, policy driven security, Identity Governance, Access Management, and Privileged access management, user provisioning/de-provisioning, and federation. Provide support with respect to requirements gathering, project management and delivery of one or more Identity platforms, such as SailPoint (Identity IQ), Okta, and Saviynt. Serve as the central point of contact for information security and IAM policy and process related issues. Address Vulnerabilities, Pentest findings and audit issues in a timely manner. Support Governance, Risk & Compliance (GRC) and Disaster Recovery (DR) efforts and initiatives. Stay abreast of industry trends, solution landscape and market conditions and update peers and management accordingly. Other duties, as assigned.

Required (must Have)

AD Migration of Domain Controllers to 2019AD Security Audit Items RemediationAD & Azure AD AdministrationAD /Azure AD Integrations with 3rd party productsResolve Azure AD Sync issuesAD Monitoring via 3rd party tools (Tenable / Crowdstrike)AD/SSO TroubleshootingAD / ARS Integration troubleshooting / planningAD Password Policy ModificationsAD Domain Controller Replication monitoringWindows Time Service monitoringWindows DNS Server administrationAD related Group Policy ConfigurationAD Domain Controller database ADRM tool backup monitoringAD Support for account related issues (lockouts)Public Key Infrastructure for on prem Sub CA’s

Soft Skills

Candidate must be great with autonomy and independent work This person must have a pro-active work style, and be a "go-getter” This team depends heavily on this resource to communicate issues and important AD matters to the rest of the IAM team, thus they must be a strong communicator. This role should require very little oversight. Strong organizational skills Strong attention to detail Good judgment Strong analytical and problem solving skills Able to work harmoniously and effectively with others Able to preserve confidentiality and exercise discretion Able to work under pressure Able to manage multiple projects with competing deadlines and priorities

Pluses

Experience with one or more programming languages such as Java, C#, C/C++, Python, or JavaScript Experience initiating new technologies and delivery high level services Experience interacting with executive members and presenting material in a simple straight forward manner Industry specific training or certification

About TEKsystems

We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company.

The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.

Frequently Asked Questions

How do I apply for the Senior Actice Directory Engineer position at TEKsystems?

Click the “Apply for this Position” button on this page to submit your application directly to TEKsystems without recruitment intermediary fees.

Is this position eligible for remote work or visa sponsorship?

This position is located in Chicago, IL with potential relocation and sponsorship assistance depending on candidate qualifications.

Are there any candidate fees on Hirely?

No. Hirely is completely free for candidates. We never charge registration fees or placement fees.

🛡️ Job Seeker Safety Advisory

Legitimate employers will never ask you to transfer funds, purchase equipment from unauthorized vendors, or pay application/visa fees. Hirely rigorously monitors listings, but always verify communication is from official corporate email domains.

Learn how to protect yourself against employment fraud →
← Explore Other Roles