Senior Active Directory Engineer

Posted 25 Days Ago
Be an Early Applicant
Buffalo, NY, USA
In-Office
97K-162K Annually
Senior level
Fintech
The Role
Designs, secures, operates, and governs enterprise Active Directory and hybrid Microsoft Entra ID environments in regulated, high-availability financial services settings. Responsibilities include identity architecture, security hardening, compliance and audit readiness, PowerShell automation, replication and disaster recovery, monitoring, technical escalation, standards development, and mentoring engineers. The role partners with security, IAM, infrastructure, audit, risk, cloud, and application teams.
Summary Generated by Built In

This role is four days onsite at our Seneca One Buffalo, NY location, with the flexibility to work from home one day per week

Overview:   

Responsible for designing, securing, and operating Microsoft Active Directory Domain Services (AD DS) in regulated, high-availability environments. Acts as knowledge resource for and trains less experienced engineers. Completes day-to-day support activities and special projects.

Primary Responsibilities:

Enterprise Active Directory Architecture

  • Proven expertise supporting large-scale, Tier‑1 identity infrastructures with strict uptime, latency, and change‑control requirements

  • Strong experience with:

    • Multi-domain and multi-forest designs aligned to business units, regions, or regulatory boundaries

    • Forest and external trusts supporting M&A, joint ventures, and third-party integrations

    • FSMO role placement optimized for resilience and auditability

  • Advanced understanding of Active Directory–integrated DNS, split‑brain DNS, and secure name resolution models

Hybrid Identity & Microsoft Entra ID (Azure AD)

  • Extensive experience integrating on-prem AD with Microsoft Entra ID in regulated financial environments

  • Hands-on implementation of:

    • Entra Connect (Cloud Sync and Traditional)

    • Password Hash Sync, Pass-through Authentication, and Federation

  • Strong experience with:

    • Conditional Access aligned to regulatory and risk-based controls

    • Hybrid Join, Entra ID Join, and legacy device coexistence

  • Understanding of identity lifecycle controls to support joiners, movers, leavers, and separation-of-duties requirements

Security, Compliance & Risk Controls

  • Expert-level knowledge of Active Directory security hardening in financial services, including:

    • Tiered administrative model (Tier 0/1/2)

    • Dedicated admin forests or hardened admin boundaries (where applicable)

    • Privileged Access Workstations (PAWs) / Secure Admin Workstations

  • Experience enforcing least privilege, role separation, and dual‑control models

  • Deep familiarity with threats targeting financial institutions:

    • Credential theft, Kerberoasting, Pass-the-Hash/Ticket

    • Delegation and ACL abuse

  • Hands-on experience with:

    • Privileged Identity Management (PIM)

    • Regular access reviews and entitlement recertification

  • Strong alignment with Zero Trust and defense-in-depth identity strategies

Regulatory & Audit Readiness

  • Demonstrated experience supporting audits and controls for financial regulations and frameworks, such as:

    • SOX, GLBA, PCI DSS, SOC 2

    • Internal risk management and model governance requirements

  • Ability to design AD environments that support:

    • Strong logging and traceability

    • Tamper-resistant audit logs

    • Evidence generation for internal and external auditors

Automation & PowerShell

  • Advanced PowerShell expertise for:

    • Controlled, auditable administrative changes

    • Automated provisioning/deprovisioning aligned to compliance workflows

    • Identity reporting for risk, security, and audit teams

  • Experience building automation that integrates with:

    • Change management processes

    • IAM, ticketing, and security tooling

Operations, Resilience & Recovery

  • Deep experience managing:

    • AD replication topology across data centers and regions

    • SYSVOL (DFSR) health and recovery

    • Latency-sensitive authentication dependencies

  • Strong understanding of:

    • AD backup, recovery, and authoritative restore procedures

    • Identity disaster recovery scenarios with defined RTO/RPO

  • Experience implementing monitoring and alerting with a focus on early risk detection

Leadership & Governance

  • Acts as technical authority and escalation point for all directory and identity services

  • Defines and enforces:

    • Enterprise identity standards

    • Secure configuration baselines

    • Operational runbooks and procedures

  • Partners closely with:

    • Information Security and IAM teams

    • Risk, audit, and compliance stakeholders

    • Infrastructure, cloud, and application teams

  • Mentors engineers and reviews designs from a security and risk-first perspective

Education and Experience Required:
  • Bachelor's degree and a minimum of 3 years’ relevant work experience, or in lieu of a degree, a combined minimum of 7 years’ higher education and/or work experience
Education and Experience Preferred:
  • Intermediate understanding of the security system development and infrastructure lifecycle and architecture, and systems design
  • Proven experience with the tools utilized in assigned Cybersecurity function
  • Experience translating architecture into technical requirements.
  • Proficient level of critical thinking and problem solving
  • Excellent written and verbal communication skills
  • Proven experience collaborating with leaders to execute results.
  • Prior experience seeking buy-in of others to align on processes.
  • Ability to analyze and draw conclusions based on quantitative data from multiple sources.

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $97,100.00 - $161,800.00 (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.LocationBuffalo, New York, United States of America

Skills Required

  • Bachelor’s degree and at least 3 years of relevant work experience, or 7 combined years of higher education and/or work experience
  • Advanced experience supporting large-scale, Tier-1 Active Directory identity infrastructures
  • Experience with multi-domain, multi-forest architectures, trusts, FSMO roles, and Active Directory-integrated DNS
  • Extensive experience integrating on-premises Active Directory with Microsoft Entra ID in regulated environments
  • Hands-on experience with Entra Connect, Cloud Sync, Password Hash Synchronization, Pass-through Authentication, and Federation
  • Experience implementing Conditional Access, Hybrid Join, Entra ID Join, and identity lifecycle controls
  • Expertise in Active Directory security hardening, tiered administration, privileged access workstations, least privilege, and role separation
  • Experience with Privileged Identity Management, access reviews, entitlement recertification, and Zero Trust strategies
  • Experience supporting SOX, GLBA, PCI DSS, SOC 2, and internal risk or model governance requirements
  • Advanced PowerShell expertise for auditable administrative changes, provisioning, deprovisioning, and identity reporting
  • Experience managing Active Directory replication, SYSVOL/DFSR health, backup, authoritative recovery, and identity disaster recovery
  • Experience implementing monitoring and alerting for identity services
  • Ability to define identity standards, secure configuration baselines, runbooks, and operating procedures
  • Experience mentoring engineers and serving as a technical authority or escalation point
  • Intermediate understanding of security system development, infrastructure lifecycle, architecture, and systems design
  • Experience with tools used in assigned cybersecurity functions
  • Experience translating architecture into technical requirements
  • Strong critical thinking, problem-solving, written communication, verbal communication, collaboration, and quantitative analysis skills

M&T Bank Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about M&T Bank and has not been reviewed or approved by M&T Bank.

  • Retirement Support — Retirement benefits are positioned as a strong pillar, including a 401(k) match and the possibility of an additional employer contribution, plus access to an employee stock purchase plan.
  • Leave & Time Off Breadth — Time-off offerings are framed as competitive, with a flexible PTO approach and paid volunteer time called out as a meaningful add-on to standard leave.
  • Wellbeing & Lifestyle Benefits — Wellbeing support appears comparatively robust, highlighted by mental-health therapy/coaching sessions and broader wellness programming alongside community-oriented perks.

M&T Bank Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Buffalo, NY
21,590 Employees
Year Founded: 1856

What We Do

M&T Bank is a multi-state community-focused bank serving New York, Maryland, New Jersey, Pennsylvania, Delaware, Connecticut, Virginia, West Virginia and Washington, D.C. Founded in 1856, the company provides banking, investment, insurance and mortgage financial services to more than 3.6 million consumer, business and government clients.

Similar Jobs

Hybrid
New York, NY, USA
289097 Employees
Hybrid
New York, NY, USA
289097 Employees

Snap Inc. Logo Snap Inc.

Technical Program Manager

Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
Hybrid
4 Locations
5000 Employees
162K-284K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account