Directory Services Security Engineer

Pinnacle

  • Fort Worth, TX
  • 11 days ago
  • $65–$70 Per Hour

Highlights

Deploy, tune, and operate DLP and DAM solutions (e.g., Microsoft Purview DLP, Imperva/Guardium); build detections for PII/PCI/PHI and reduce false positives with policy and context improvements. Engineer DSPM capabilitieswith tools(e.g.,Securiti,BigID) to surface data posture risks (overexposure, shadow data, stale sensitive data) and drive remediation workflows.

Numbers & Facts

LocationFort Worth, TX
Salary$65–$70 Per Hour

Description

Position - Security Engineer
Location - Fort Worth, TX (Hybrid)

Job ID - 178604

Position Overview
We are seeking a Directory Services Engineer to support critical cybersecurity initiatives focused on identity infrastructure security, Tier 0 protection, and resiliency. This role is hands-on and execution-focused, working across Active Directory, Microsoft Entra ID (Azure AD), and hybrid identity environments.
The engineer will play a key role in hardening identity systems, identifying attack paths, and implementing remediation actions to reduce enterprise risk.
________________________________________
Key Responsibilities
Identity Engineering & Operations
• Administer and support Active Directory (AD) and Microsoft Entra ID (Azure AD) environments.
• Implement and manage Azure AD Connect / Entra Connect for hybrid identity synchronization.
• Support domain controllers, forests, trusts, and authentication services.
• Execute identity-related changes, configurations, and deployments.
________________________________________
Security Hardening & Tier 0 Protection
• Implement security controls for Tier 0 assets (AD, Entra ID, domain controllers).
• Perform system hardening in alignment with cybersecurity standards.
• Support initiatives for privileged access restrictions and identity protection.
• Remediate identified security gaps and misconfigurations.
________________________________________
Attack Path Identification & Remediation
• Analyze and identify identity-based attack paths across on-prem and cloud environments.
• Support remediation efforts to eliminate:
o Privilege escalation paths
o Excessive permissions
o Identity misconfigurations
• Partner with cybersecurity teams to reduce identity attack surface.
________________________________________
Resiliency & Recovery Support
• Implement and validate Active Directory forest recovery procedures.
• Support backup, restore, and testing activities for identity systems.
• Assist in improving resiliency and recoverability of Tier 0 infrastructure.
________________________________________
Integration Support
• Assist in integration and configuration of identity with:
o MFA / Conditional Access
o PAM (e.g., CyberArk)
o IGA (e.g., Saviynt)
o Secrets and certificate platforms (e.g., HashiCorp, Keyfactor)
• Support identity governance and access control initiatives.
________________________________________
Automation & Execution
• Use PowerShell and scripting to automate identity tasks and remediation.
• Execute predefined engineering tasks, runbooks, and operational procedures.
• Document configurations, changes, and implementation steps.

Job Description:
  • Operationalize automated data discovery, classification, and inventory; apply sensitivity labels andconsistenttaxonomy across data stores, pipelines, and collaboration systems.
  • Engineer DSPM capabilitieswith tools(e.g.,Securiti,BigID) to surface data posture risks (overexposure, shadow data, stale sensitive data) and drive remediation workflows.
  • Implement and support encryption, tokenization, masking, anonymization/pseudonymization for data at rest and in transit; integrate with cloudkey management systemsand enforce approved cryptographic standards;define crypto baselines and policy-as-code guardrails.
  • Configure andgovernaccess controls with RBAC/ABAC and purpose-based authorization; perform least-privilege and fine-grained access reviews across data platforms.
  • Deploy, tune, and operate DLP and DAM solutions (e.g., Microsoft Purview DLP, Imperva/Guardium); build detections for PII/PCI/PHI and reduce false positives with policy and context improvements.
  • Integrate and tune UEBA and Insider Risk signals to detect anomalous data access andexfiltration,partner on response workflows and preventive control changes.
  • Integrate data protection telemetry with SIEM/SOAR; build detections, correlation rules, and automated response playbooks for data-related threats and policy violations.
  • Implement data minimization and retention/ROT enforcement patterns; automatemonitoring oflifecycle actions (archive, delete, redact) aligned to policy and legal holds.
  • Implement DSAR (data subject access request) orchestration and fulfillment with SLA monitoring; automate data collection, redaction, and secure delivery with audit trails.
  • Contribute to cookie/tag governance and catalog assurance; validate consent signals, storage durations, and vendor script behavior against policy.
  • Support privacy platform capabilities and integrate with identity, ticketing, data catalogs/lineage, and evidence repositories.
  • Embeddata protection andprivacy-by-design controls into services and CI/CD (pre-commit/CI privacy code scanning, secret scanning, schema checks for sensitive fields, data egress policies).
  • Produce compliance evidence and reports for GDPR/CCPA/CPRA, PCI DSS, HIPAA, and internal audits; maintaincontrolshealth dashboards, regulatory tracking, and program KPIs.
  • Investigate data-related incidents and privacy events in partnership with IR/SOC/Privacy Office. Collectartifacts, support forensics, document findings, and drive preventive engineering fixes.
  • Conduct platform hardening and vulnerability remediation for data control tooling (misconfigurations, exposed buckets, weak crypto, excessive permissions).
  • Participate in red teaming/tabletop exercises for data scenarios (insider misuse, public link exposures, unintended AI training data); translate findings into control improvements.
  • Partner with Cybersecurity, Privacy Office, Enterprise Data, Legal, and product/platform teams to align designs and deliver privacy- and data protection-by-design outcomes.
  • Document engineering patterns, runbooks, and reference architectures; create training and technical guidance that strengthen secure data handling practices across teams.
  • Communicate clearly and concisely with technical and non?technical audiences - summarize incidents, risks, and recommended actions with accurate, complete context.

Required Skills & Experience

  • 3–7 years of hands-on experience in:
    • Active Directory administration/engineering
    • Microsoft Entra ID (Azure AD)
    • Azure AD Connect / hybrid identity environments
  • Experience with:
    • AD security hardening
    • Identity-related attack techniques (privilege escalation, lateral movement)
    • Attack path analysis or remediation activities
  • Strong working knowledge of:
    • Tier 0 concepts and identity as a control plane
    • Authentication protocols (Kerberos, NTLM, SAML, OAuth)
Preferred Experience
  • Exposure to:
    • CyberArk or other PAM tools
    • Saviynt or similar IGA platforms
    • Ping Identity or federation solutions
    • HashiCorp Vault, Keyfactor, or PKI environments
  • Experience supportingAD forest recovery exercises
  • Familiarity withZero Trust principles
Key Traits for Success
  • Strongexecution and delivery focus
  • Security and resiliency mindset
  • Ability to quickly identify and remediate risks
  • Works effectively in across-functional cybersecurity environment
  • Comfortable working infast-paced, project-driven (contract) engagements

Pay Range: $65- $70/Hr

The specific compensation for this position will be determined by a number of factors, including the scope, complexity and location of the role as well as the cost of labor in the market; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. Our full-time consultants have access to benefits including medical, dental, vision and 401K contributions as well as any other PTO, sick leave, and other benefits mandated by appliable state or localities where you reside or work.




#LI-SA4

Similar Jobs

See more jobs