Senior Directory Security Engineer
Capital One
2021-12-03 08:53:38
Cambridge, Massachusetts, United States
Job type: fulltime
Job industry: I.T. & Communications
Job description
West Creek 4 (12074), United States of America, Richmond, Virginia
Senior Directory Security EngineerDo you have expert level experience securing Active Directory, Azure Active Directory, AWS Microsoft AD, Google Cloud Directory, LDAP or other directory platforms? Do you have a desire to learn and work on exciting leading edge technologies and design solutions for complex on-premises and cloud-based Directory security challenges? If so, then this opportunity might be for you.
Capital One is seeking an expert level Senior Directory Security Engineer within the Identity and Access Management organization to be a senior engineer on a team responsible for securing Capital One's enterprise Directory Services environment that includes Active Directory, Azure Active Directory, AWS Microsoft Active Directory, and Google Cloud Domain Directory.
Candidates for this role should have expert level knowledge and experience in securing complex enterprise level Active Directory environments and have a passion for risk assessment and mitigation, learning new cloud based technologies, and driving automated and efficient solutions to complex problems.
Responsibilities:
Be one of several senior engineers on a team responsible for the security of Capital One's enterprise Active Directory environment including on-premise and cloud environments from AWS, Microsoft Azure, and Google Cloud
Provide technical leadership during the analysis, troubleshooting, and investigation of security related events within the Active Directory platforms
Evaluate and recommend information security products, technologies, and procedures by proactively identifying problems and evaluating industry trends
Provide input so the Active Directory roadmap aligns with security initiatives, business needs, and forward looking requirements
Manage quarterly security audits and ensure the Active Directory environment adheres to security and compliance settings
Be the project lead or participate as a team member on various projects within or across technology and business teams
Manage the engineering and implementation of solutions that will secure and protect Capital One's Active Directory environment
Manage vulnerability assessments and security testing to proactively identify and close security risks within the Active Directory environment
Architect, engineer, and deploy third-party security monitoring tools to protect the environment and monitor for security breaches, intrusions and irregular system behavior
Partner with CyberSecurity engineers to implement technology solutions
Participate in disaster recovery, capacity planning, performance monitoring and maintenance to ensure high availability of security monitoring systems
Participate in the evaluation, development, and implementation of security standards and best practices for Active Directory and recommend security enhancements to management as needed
Evaluate, test, and select new security, compliance, and audit tools
Educate team members on information security through training and increased awareness
Partner with CyberSecurity teams to support forensic investigations and ensure integration with enterprise SIEM systems
Key Terms: Active Directory, Windows, Microsoft, Azure, AzureAD, AWS, Google Cloud, Powershell, IAM, Directory Services, LDAP. Security, Compliance
Basic Qualifications:
High school diploma, GED or equivalent certification.
At least 5 years of experience with Active Directory
At least 3 years of experience securing Active Directory environments
At least 3 years of experience preventing Active Directory credential theft attacks using Pass the Hash, Golden Ticket or Lateral Movement
At least 3 years of experience with Group Policy Objects, Security Log Analysis and Delegation of Permissions
At least 3 years of experience developing scripts or queries to generate reports against Active Directory
At least 3 years of experience monitoring and analyzing logs from Active Directory
At least 3 years of experience with Security Information and Event Management (SIEM) and Log aggregation platforms using Splunk, Snowflake, Quest, or StealthBits
Preferred Qualifications:
Bachelor's Degree
4+ years of experience developing scripts for automated solutions with PowerShell, VBScript, JavaScript, or Python
3+ years of experience supporting Active Directory in a cloud hosted environment from AWS, Microsoft, or Google
3+ years of experience with Windows Server 2012, 2016 and 2019 Active Directory
CISSP, CISM, or CEH security certification
At this time, Capital One will not sponsor a new applicant for employment authorization for this position.
No agencies please. Capital One is an Equal Opportunity Employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex, race, color, age, national origin, religion, physical and mental disability, genetic information, marital status, sexual orientation, gender identity/assignment, citizenship, pregnancy or maternity, protected veteran status, or any other status prohibited by applicable national, federal, state or local law. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1- or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).