IT Systems Engineer Sr – Active Directory

Posted 2 Days Ago
Be an Early Applicant
Streeterville, IL, USA
In-Office
94K-154K Annually
Senior level
Healthtech • Kids + Family • Social Impact
The Role
Lead design, hardening, and modernization of enterprise Active Directory and hybrid identity (Azure AD/Entra ID). Implement AD tiering, GPO governance, PKI, privileged access, AAD Connect, and automation via PowerShell. Troubleshoot authentication, replication, DNS, and LDAP across multisite environments, report on identity health and risk, support audit remediation, mentor staff, participate in projects, and assume on-call responsibilities.
Summary Generated by Built In

Ann & Robert H. Lurie Children’s Hospital of Chicago provides superior pediatric care in a setting that offers the latest benefits and innovations in medical technology, research and family-friendly design. As the largest pediatric provider in the region with a 140-year legacy of excellence, kids and their families are at the center of all we do. Ann & Robert H. Lurie Children’s Hospital of Chicago is ranked in all 10 specialties by the U.S. News & World Report.

Location

680 Lake Shore Drive

Job Description

The Active Directory Engineer is the enterprise lead for designing, securing, and modernizing the hospital’s identity infrastructure across on‑prem Active Directory and Azure AD (Entra ID). Responsible for engineering, and maintenance of AD forests, GPOs, PKI, privileged access, and hybrid identity services in alignment with security, audit, and IAM standards. The engineer leads identity remediation efforts, partners with security teams to strengthen controls, reports on identity risk and health, and mentors staff while advancing secure authentication and directory stability across the organization.

Essential Job Functions:

  • Design, maintain, and upgrade Active Directory forests, domains, trusts, sites, and services, ensuring scalable and resilient identity infrastructure.

  • Implement and enforce AD Tiering (Tier 0/1/2) and privileged access boundaries, ensuring secure administrative practices.

  • Own the engineering, deployment, optimization, and governance of Group Policy Objects (GPOs)—including secure baseline enforcement, lifecycle management, troubleshooting of processing issues, and cross‑team coordination to ensure reliable, conflict‑free configuration across the enterprise.

  • Develop PowerShell scripts to automate user lifecycle management, privileged access workflows, and routine AD operational tasks.

  • Manage synchronization between on‑premises AD and Azure Active Directory (Entra ID), including hybrid identity, AAD Connect, and authentication flows.

  • Lead high-level troubleshooting for authentication, replication, DNS, and LDAP issues across multisite environments.

  • Generate reports on system health, performance, and security, including privileged access, stale objects, replication status, and GPO compliance.

  • Prepare and interpret technical documentation, including architecture diagrams, system configurations, runbooks, and operational procedures.

  • Develops and manages complex projects related to network and server technologies, including desktop technology and deployments where indicated.

  • Mentors junior technical staff and/or IM Applications and other IM team members.

  • Participate in other department or organizational project tasks as required.

  • Partner with the Authentication team leader and technology SMEs to drive adoption of compliant, enterprise-wide authentication solutions aligned to IAM standards.

  • Harden AD infrastructure, monitor security events, manage PKI/certificate services, and ensure compliance with security baselines and regulatory requirements.

  • Apply industry best practices and proactively identify and remediate identity and authentication gaps to continuously strengthen enterprise controls.

  • Partners with IAM Governance and policy teams to measure, report, and improve authentication controls, and support audit remediation and sustainability.

  • Provide transparent reporting to leadership on identity posture, risks, and mitigation strategies.

  • Assumes on-call responsibility for data center equipment operations, per the schedule.

  • Performs other duties as assigned.

Knowledge, Skills and Abilities:

  • Education: Bachelor’s Degree in Information Systems/Technology/Computer Science preferred (or equivalent work experience)

  • 3–5+ years of hands-on experience engineering and supporting Active Directory in complex enterprise environments, including authentication, replication, GPOs, and directory security.

  • Deep expertise in Active Directory architecture and services, including forests, domains, trusts, sites, replication, DNS integration, and Group Policy design, processing, and troubleshooting.

  • Strong knowledge of identity and authentication principles and protocols, including Kerberos, NTLM, LDAP, SAML, OAuth, OpenID Connect, and modern authentication frameworks.

  • Expertise in PKI and certificate lifecycle management, including certificate-based authentication.

  • Experience with hybrid identity and cloud directory services, including Microsoft Entra ID, AAD Connect, SSO, and federation.

  • Strong understanding of security best practices across identity and core infrastructure, including servers, networks, and application security.

  • Hands-on experience with identity and access management (IAM) and privileged access management (PAM) solutions, including MFA, vaulting, and service integrations (e.g., Ping Identity, OpenLDAP, OpenDJ).

  • Experience working across Windows, Linux, and cloud-based identity platforms.

  • Demonstrated ability to lead and deliver complex technical projects in both individual contributor and team leadership roles.

  • Strong analytical, problem-solving, and troubleshooting skills, with the ability to operate independently and make decisions under pressure.

  • Excellent communication, documentation, and interpersonal skills, with a focus on collaboration and customer service.

Education

Bachelor's Degree

Pay Range

$93,600.00-$154,440.00 Salary

At Lurie Children’s, we are committed to competitive and fair compensation aligned with market rates and internal equity, reflecting individual contributions, experience, and expertise. The pay range for this job indicates minimum and maximum targets for the position. Ranges are regularly reviewed to stay aligned with market conditions. In addition to base salary, Lurie Children’s offer a comprehensive rewards package that may include differentials for some hourly employees, leadership incentives for select roles, health and retirement benefits, and wellbeing programs. For more details on other compensation, consult your recruiter or click the following link to learn more about our benefits.

Benefit Statement


For full time and part time employees who work 20 or more hours per week we offer a generous benefits package that includes:

Medical, dental and vision insurance

Employer paid group term life and disability

Employer contribution toward Health Savings Account

Flexible Spending Accounts

Paid Time Off (PTO), Paid Holidays and Paid Parental Leave

403(b) with a 5% employer match


Various voluntary benefits:

  • Supplemental Life, AD&D and Disability
  • Critical Illness, Accident and Hospital Indemnity coverage
  • Tuition assistance
  • Student loan servicing and support
  • Adoption benefits
  • Backup Childcare and Eldercare
  • Employee Assistance Program, and other specialized behavioral health services and resources for employees and family members
  • Discount on services at Lurie Children’s facilities
  • Discount purchasing program

There’s a Place for You with Us


At Ann & Robert H. Lurie Children’s Hospital of Chicago and its affiliates (collectively “Lurie Children’s”), we embrace and celebrate diversity and equity in a serious way. We are committed to building a team with a variety of backgrounds, skills, and viewpoints — recognizing that diverse identities strengthen our workplace and the care we can provide to the Chicago community and beyond. We treat everyone fairly, appreciate differences, and make meaningful connections that foster belonging and allyship. This is a place where you can be your best, so we can give our best to the patients and families who trust us with their care.  


Lurie Children’s and its affiliates are equal employment opportunity employers.  We value diversity and are committed to creating an inclusive environment for all employees.  All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity or expression, religion, national origin, ancestry, age, disability, marital status, pregnancy, protected veteran status, order of protection status, protected genetic information, or any other characteristic protected by law. 


For questions about how to request an accommodation please contact: [email protected]


AI Notice 


Lurie Children’s utilizes certain AI-enabled features within our recruiting platform to support candidate engagement and assist recruiters in identifying and prioritizing applicants whose experience aligns with job requirements. All employment decisions are made by individuals.


It is a civil rights violation with respect to recruitment, hiring, promotion, or employment for an employer to use artificial intelligence that has the effect of subjecting employees to discrimination on the basis of protected classes under the Illinois Human Rights Act or to use zip codes as a proxy for protected classes.


For questions about the use of artificial intelligence in this process or any additional support, please contact: [email protected]

Skills Required

  • 3-5+ years hands-on experience engineering and supporting Active Directory in complex enterprise environments
  • Deep expertise in Active Directory architecture and services (forests, domains, trusts, replication, DNS, GPO design and troubleshooting)
  • Experience with hybrid identity and cloud directory services, including Microsoft Entra ID and AAD Connect
  • PowerShell scripting to automate user lifecycle, privileged access workflows, and routine AD operational tasks
  • Expertise in PKI and certificate lifecycle management, including certificate-based authentication
  • Strong knowledge of identity and authentication protocols (Kerberos, NTLM, LDAP, SAML, OAuth, OpenID Connect)
  • Hands-on experience with IAM and PAM solutions, MFA, vaulting, and related service integrations (e.g., Ping Identity)
  • Experience working across Windows, Linux, and cloud-based identity platforms
  • Demonstrated ability to lead and deliver complex technical projects and mentor junior staff
  • Bachelor's Degree in Information Systems/Technology/Computer Science or equivalent work experience
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
4,000 Employees
Year Founded: 1882

What We Do

Ann & Robert H. Lurie Children’s Hospital of Chicago is a nonprofit organization committed to providing access to exceptional care for every child. It is the only independent, research-driven children's hospital in Illinois, nationally ranked and offering comprehensive pediatric specialties.

Similar Jobs

Caterpillar Logo Caterpillar

Digital Operations Support Analyst; Self-Service & AI

Artificial Intelligence • Cloud • Internet of Things • Software • Cybersecurity • Industrial
Hybrid
Peoria, IL, USA
100000 Employees
98K-158K Annually

Caterpillar Logo Caterpillar

Digital Content Author

Artificial Intelligence • Cloud • Internet of Things • Software • Cybersecurity • Industrial
Hybrid
Chicago, IL, USA
100000 Employees
81K-122K Annually

Caterpillar Logo Caterpillar

Business Intelligence and Applications Specialist

Artificial Intelligence • Cloud • Internet of Things • Software • Cybersecurity • Industrial
Hybrid
Peoria, IL, USA
100000 Employees
113K-169K Annually

Caterpillar Logo Caterpillar

Senior Software Engineer

Artificial Intelligence • Cloud • Internet of Things • Software • Cybersecurity • Industrial
Hybrid
Chicago, IL, USA
100000 Employees
113K-183K Annually

Similar Companies Hiring

Playground (tryplayground.com) Thumbnail
Kids + Family • Payments • Social Impact • Software
New York City, New York
80 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account