Security Engineer - Directory Services
Job Description
Join an office-centric, full-time Security Engineering role focused on protecting directory services and closely related platforms. You will help design and implement cybersecurity solutions that strengthen critical assets while supporting secure design, governance, and reliable operations. The work blends threat modeling, hands-on security testing, production integrations, and incident response support, with a strong emphasis on reusable fixes, knowledge sharing, and team collaboration.
What you’ll be doing
- Design and implement cybersecurity solutions for the job area, contributing to technical design and implementation approaches while following established strategies and patterns.
- Conduct threat modeling, security testing, and penetration testing for in-scope platforms and services to identify and remediate significant vulnerabilities.
- Integrate and configure information security technologies in production environments, improving configuration patterns and automation, and completing handoff steps for assigned systems or services.
- Act as a technical escalation point for challenging security issues by investigating root causes and developing practical, reusable fixes that improve team workflows.
- Evaluate security threats, tools, and design options, providing input that informs technical plans, priorities, and goals for the job area.
- Partner with product and engineering teammates to apply security architecture guidance, secure-by-design practices, and governance controls during day-to-day development.
- Develop and maintain security baselines, guardrails, and control implementations to support regulatory and policy compliance.
- Lead technical execution of incident response and basic forensic activities for services in scope, using playbooks, coordinating tasks with teammates, and improving procedures and tooling.
- Provide guidance, coaching, and informal training through design and code reviews and knowledge sharing sessions.
- Lead significant security engineering workstreams or end-to-end processes within the job area, coordinating contributions from lower-level professionals and reviewing outputs for quality and alignment.
Required qualifications
- Bachelor’s degree or equivalent education, training, and work-related experience.
- Minimum of 5 years of experience in security engineering or related cybersecurity roles.
- Advanced knowledge of cybersecurity principles, theories, and concepts.
- Proven experience applying security practices across the software development lifecycle.
- Advanced knowledge of threat modeling, security testing, and penetration testing.
- Experience implementing and managing complex information security technologies.
Technology environment
You will work across common enterprise directory and identity technologies, including Microsoft Active Directory Domain Services, Microsoft Active Directory Federation Services (ADFS), Microsoft Active Directory Certificate Services, Microsoft DHCP, Microsoft DNS, Microsoft Distributed File System (DFS), Microsoft Key Management Services (KMS), Microsoft Identity Manager (MIM), and Microsoft Remote Desktop Licensing (RDL), alongside Quest product suite and Hewlett Packard Enterprise and Dell physical servers. Windows Server operating systems are in scope (Windows Server 2025 through Windows Server 2012 R2), with scripting and infrastructure skills including PowerShell scripting, networking, and firewall rule sets.
Benefits
Eligible teammates working 20 hours or more per week (excluding temporary or contingent workers) may qualify for benefits. Plans can vary by division offering the position.
- Medical, dental, vision
- Life insurance, disability, accidental death and dismemberment
- Tax-preferred savings accounts and a 401k plan
- No less than 10 days of vacation in the first year (prorated based on hire date and full-time or part-time status)
- 10 sick days (also prorated)
- Paid holidays
- Defined benefit pension plan (depending on position and division)
- Restricted stock units and/or a deferred compensation plan (depending on position and division)
General benefit details for eligible employees are available on the company’s Benefits site, and additional specifics are shared as you move through the hiring process.
Location and type
Raleigh, NC (onsite), full-time.
Preferred qualifications
- Bachelor’s degree and six years of experience, or an equivalent combination of education and work experience.
- Banking or financial services experience.
- Certification strongly preferred: ServiceNow Certified System Administrator (CSA).
- Preferred knowledge and experience with the listed Microsoft and Quest systems and platforms, plus PowerShell scripting and networking/firewall rulesets.