At OxyChem, our chemistry makes modern life possible, and it is our people who make the difference. We are a safety-first, purpose-driven team committed to innovation, environmental responsibility, and doing things the right way. If you are ready to contribute, elevate your skills, and take ownership of your career, OxyChem offers the opportunity to make a difference every day.
OxyChem, a Berkshire Hathaway company, is a leading producer of essential chemistry with operations in the U.S., Canada and Latin America. OxyChem’s products play an essential role in everyday life, supporting critical applications in water treatment, pharmaceuticals, healthcare, manufacturing, automotive, personal hygiene, and residential and commercial construction. OxyChem actively participates in the Occupational Safety and Health Administration Voluntary Protection Program, underscoring our commitment to safety. Headquartered in Dallas, Texas, OxyChem is a top three U.S. manufacturer of polyvinyl chloride, chlor-alkali and chlorinated organic chemicals, and calcium chloride. Visit oxychem.com for more information.
In a fast-paced industry that demands precision, we create a supportive workplace where the safety and well-being of our employees are paramount. We are committed to rewarding top performers, offering very competitive pay and benefits, and providing tremendous career development opportunities.
We are seeking a Senior Enterprise Active Directory & Identity Architect to lead the design, implementation, and governance of enterprise identity platforms with a primary focus on Active Directory (AD) and related identity services. This role combines enterprise AD architecture with identity and access management (IAM) responsibilities, ensuring secure, scalable, and compliant solutions across the organization. You will define architecture roadmaps, patterns, and standards for AD and IAM platforms while collaborating with IT teams and business units to safeguard systems and manage user access.
Key Responsibilities:
Active Directory & Identity Management
- Design and maintain enterprise Active Directory architecture, including forests, domains, OU structure, and Group Policy Objects (GPOs).
- Manage identity provisioning, de-provisioning, and role-based access controls across AD and integrated IAM platforms.
- Implement and maintain secure authentication mechanisms, including MFA, Kerberos, and privileged access management.
- Monitor AD health, replication, and security posture; troubleshoot and resolve directory-related issues.
- Ensure compliance with internal security policies and external regulations (e.g., MTSA, GDPR) for AD and IAM environments.
- Support audits and risk assessments related to AD and IAM; implement controls based on findings.
- Evaluate AD-integrated IAM tools and recommend enhancements for efficiency and security.
- Provide guidance and training on secure AD and IAM practices to stakeholders.
Governance & Collaboration
- Partner with enterprise and solution architects to drive adoption of AD and IAM platform patterns.
- Collaborate with cloud and security teams to assess implications of hybrid identity solutions (Azure AD/Entra ID).
- Provide business-friendly language for complex AD and identity architecture concepts.
- Mentor junior security and solution architects.
Skills & Competencies
- Technical Expertise: Deep knowledge of Active Directory architecture, including DNS integration, replication, GPOs, and AD hardening best practices.
- Strong experience with IAM platforms (SailPoint, CyberArk, Azure Entra ID, Intune).
- Familiarity with cybersecurity principles and frameworks (NIST, ISO 27001).
- Risk & Compliance: Ability to ensure adherence to regulatory requirements and internal policies.
- Analytical & Problem-Solving: Skilled in identifying risks and implementing effective mitigation strategies.
- Soft Skills: Excellent communication and collaboration skills for cross-functional engagement.
- High ethical standards and attention to detail.
Qualifications:
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field will consider relevant experience in lieu of education.
- 7+ years of experience in Active Directory architecture, identity and access management, or cybersecurity leadership.
- Preferred certifications: CISSP, CISA, Microsoft Certified: Identity and Access Administrator Associate.
- Vendor certifications from AWS, Microsoft Azure, or Google Cloud Platform preferred.
Preferred Attributes:
- Experience with hybrid identity solutions (on-prem AD + Azure AD).
- Knowledge of automation tools for AD and IAM processes (PowerShell scripting).
- Familiarity with cybersecurity incident response and architecture.
- Ability to mentor and lead technical teams.
Fraud Statement:
It has come to our attention that various individuals and/or organizations are contacting people falsely pretending to recruit on behalf of OxyChem. Please be aware that these recruiting scams and communications do not originate, nor are they associated with our recruitment process. All OxyChem job postings and offers will require a completed application through our company website.
OxyChem does not charge a fee at any stage of the recruiting process. We will never:
• Ask you to pay for applications, interviews, meetings, processing, training or for any other fees
• Use recruiting or placement agencies that charge candidates an advance fee of any kind or
• Request personal information such as passport and bank account details at an early stage of our recruitment process.
We recommend against responding to unsolicited business propositions or offers from people you don't know. Do not disclose your personal or financial details. If you believe you have been the victim of a recruiting scam, please contact your local police department.
Skills Required
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field (or relevant experience in lieu of degree)
- 7+ years of experience in Active Directory architecture, identity and access management, or cybersecurity leadership
- Deep knowledge of Active Directory architecture including DNS integration, replication, OU/GPO structure, and AD hardening best practices
- Strong experience with IAM platforms such as SailPoint, CyberArk, Azure Entra ID (Azure AD), and Intune
- Familiarity with authentication technologies and privileged access management (MFA, Kerberos, PIM)
- Familiarity with cybersecurity principles and frameworks (NIST, ISO 27001)
- Preferred certifications: CISSP, CISA, Microsoft Certified: Identity and Access Administrator Associate
- Vendor cloud certifications (AWS, Microsoft Azure, or Google Cloud Platform)
- Experience with hybrid identity solutions (on-prem AD + Azure AD)
- Knowledge of automation tools and scripting for AD/IAM processes (PowerShell)
- Ability to mentor and lead junior security and solution architects
- High ethical standards and strong attention to detail
What We Do
Occidental Petroleum Corporation (Oxy) is an international energy company focused on exploring for and producing oil and natural gas, with operations and assets in the United States, the Middle East, Africa, and Latin America. It also operates a petrochemical manufacturing business, applying technology and operational expertise to produce energy and serve industrial markets worldwide through its global business portfolio.

.png)






