Job Description
Azure Security Engineer Sr.
Summary - Our client's, CISO group, seeks a qualified Active Directory/Azure Administrator to manage the administration, implementation, and maintenance of Active Directory and Azure infrastructures. This position provides 24x7x365 operational support for 7,000+ banking and non-banking branch users across the Bank. On call responsibilities include evenings and weekends to support all described infrastructure.
As the subject matter expert for AD/Azure, the person in this position provides non-supervisory technical leadership for the team and ensures that all new and existing AD/Azure technologies are successfully deployed and maintained.
Responsibilities include but are not limited to the following:
- Active Directory Administration
- Manage operation, health, and security of a multi-site domain.
- Manage on-prem active directory environment and associated services like DNS, certificate services, etc.
- Administer and support FHN Azure Identity Management platform.
- Azure AD Administration
- Administer and maintain the hybrid and cloud-only identities across multiple Azure AD tenants.
- Create and maintain Conditional Access Policies.
- Support SAML and OAuth application configurations.
- Active Directory Security
- Manage Group Policy Objects (GPOs).
- Support on-prem, hybrid, and cloud identity and access management.
- Support identity and asset lifecycle management.
- Assist with potential compromised account investigations.
- Create and tune DLP and AIP policies.
- Special Data Requests
- Handle access investigation requests as required.
- Respond to data access and loss investigations.
- General Administration
- Perform troubleshooting, root cause analysis, and performance benchmarking.
- Respond to help desk tickets.
- Generate and distribute monthly statistical reporting.
- Provide support for issues ranging from single-user issues to system-wide problems.
- Assist with periodic testing of disaster preparedness for the Azure Cloud Platform, TN and TX FHN Data Centers.
- And other assigned duties.
The person in this position reports to the DCIO SICO Dist. Work hours are 8:00 AM - 5:00 PM, Monday - Friday plus on-call responsibilities as scheduled.
Skills and Abilities: Knowledge of: advanced level administrative knowledge of Microsoft Active Directory, Azure Active Directory, and hybrid identities; and familiarity with creating and tuning data loss prevention policies and data classification policies.
Skills in : managing and monitoring user activity and risk for on-prem, cloud only, and hybrid identities.
Ability to: to create and manage on-prem, cloud only, and hybrid identities across multiple tenants either through the GUI or programmatically using PowerShell; utilize configuration management to meet the goals of security and compliance; create and manage Azure Conditional Access Policies to meet organizational access and security objectives; work efficiently and effectively with little oversight; manage a mature operation based on repeatable processes and appropriate metrics; communicate effectively with both technical and non-technical stakeholders at all levels; diagnose issues and apply appropriate trouble-shooting analysis; prepare and present facts clearly and concisely in both written and oral form; evaluate and document processes and record keeping methods; and contribute to process improvements.
Minimum Education and Experience Requirements
Bachelor's degree in computer science or another related information technology field and four (4) years of IT related work experience; or an equivalent combination of education and experience.
Management recommends that candidates have five (5) years of directly related experience in Windows Active Directory and three (3) years of directly related experience to Azure Active Directory Administration within an enterprise environment.
Management prefers candidates with:
- experience with PowerShell tool scripting.
- cloud services management experience, preferably Azure and AWS.
- IAM experience within multi domain and cloud tenant environments.
- experience writing complex search queries in response to security incidents.
- experience configuring custom monitoring KPIs.
- knowledge of common security standards such as PCI, FERPA, and NIST.
Benefit Highlights - Medical with wellness incentives, dental, and vision
- HSA with company match
- Maternity and parental leave
- Tuition reimbursement
- Mentor program
- 401(k) with 6% match
Job Tags
Work experience placement, Afternoon shift, Monday to Friday,