Schedule: Full-time | Hybrid (minimum 3 days in office per week)Salary Range: $118,900 – $169,000We are seeking an IAM Engineer to join our team in Chicago. This role focuses on the design, installation, configuration, and management of Active Directory environments across Windows Desktop and Server systems, including both on‑premises and cloud‑based environments .This is a highly technical backend role responsible for maintaining the health, performance, and security of directory services across multiple environments.This is a full‑time position requiring regular attendance and collaboration with the team. While employees are expected to work onsite, this role offers flexibility with a minimum of three days per week in the office .The team typically works onsite on Tuesdays for team meetings , and it is preferred that Tuesday be one of the onsite days when possible.Additional hours may occasionally be required during periods of heavy workload.This role also participates in a 24x7x365 on‑call rotation , alternating primary and secondary coverage with another team member on a bi‑weekly basis.Key Responsibilities Maintain Active Directory health, topology, replication, and security baselinesDesign and implement domain and forest configurationsPromote and manage Domain ControllersTroubleshoot and manage DNS, DHCP, Group Policy, and trust relationshipsPlan and execute directory migrations and disaster recovery testingManage directory services across multiple Windows Server environments (physical and virtual)Support automation and process improvement within Active Directory workflowsRequired Experience Candidates must have hands‑on experience managing and architecting Active Directory environments , not just provisioning or access administration.Experience installing and architecting Active DirectoryPromoting Domain Controllers and configuring domains and forestsManaging directory services across multiple Windows Server environmentsStrong experience with DNS, DHCP, WINS, DFS, ADFS, PKI, and Group PolicyExperience with directory migrations, recovery, security, and capacity managementExperience improving or automating Active Directory processesNice to Have Experience across the Microsoft ecosystem , including Windows Server, SCCM, or SharePointExperience managing multiple domains or forestsScripting or automation experience (PowerShell)CI pipelines for infrastructure changesTeam Structure This role reports to the IAM Manager and will work alongside a growing team that currently includes:2 IAM Analysts2 Senior IAM Analysts1 Senior IAM Specialist1 IAM Engineer (recently hired)Additional Information This position requires a self‑sufficient engineer who can independently manage Active Directory environments while collaborating within a dynamic and evolving security team. The role involves minimal direct interaction with firm clients and focuses primarily on backend infrastructure.Why Join the Team Collaborative environment with high trust and autonomyOpportunity to help strengthen and expand a growing security and identity teamLong‑standing organization with 150+ years of stability and proven resilience#J-18808-Ljbffr