Engineer (Directory Services)
About the Role
Our client, a leading airline, is seeking an Engineer (Directory Services) to join their cybersecurity team. This hands-on role focuses on securing enterprise identity infrastructure across Active Directory and Microsoft Entra ID environments. The engineer will support identity security initiatives, Tier 0 protection, attack path remediation, and resiliency efforts while partnering with cross-functional cybersecurity teams to reduce enterprise risk.
Contract: 4 months (08/03/2026 – 12/31/2026)
Location: Fort Worth, TX
Schedule: Hybrid – onsite three days per week
Responsibilities
- Administer and support Active Directory and Microsoft Entra ID (Azure AD) environments, including hybrid identity synchronization using Azure AD Connect
- Implement security hardening initiatives for Tier 0 assets, including domain controllers, Active Directory, and Microsoft Entra ID
- Analyze identity attack paths and remediate privilege escalation risks, excessive permissions, and identity misconfigurations
- Support Active Directory forest recovery, backup, restore, resiliency testing, and disaster recovery initiatives
- Integrate identity platforms with MFA, Conditional Access, Privileged Access Management (PAM), Identity Governance and Administration (IGA), and secrets management solutions
- Automate identity administration and remediation tasks using PowerShell while documenting configurations, runbooks, and implementation procedures
- Collaborate with cybersecurity teams to improve identity security posture, reduce attack surface, and support enterprise security initiatives
Requirements
- 3+ years of hands-on experience administering and engineering Active Directory environments
- Experience supporting Microsoft Entra ID (Azure AD) and hybrid identity environments using Azure AD Connect
- Experience implementing Active Directory security hardening and identity security best practices
- Knowledge of identity attack techniques, including privilege escalation, lateral movement, and attack path remediation
- Strong understanding of Tier 0 security concepts and identity as a control plane
- Working knowledge of authentication protocols such as Kerberos, NTLM, SAML, and OAuth
- Experience automating administrative tasks using PowerShell scripting
Preferred Qualifications
- Experience with Privileged Access Management (PAM) solutions such as CyberArk
- Experience with Identity Governance and Administration (IGA) platforms such as Saviynt
- Familiarity with Ping Identity or other federation technologies
- Experience with HashiCorp Vault, Keyfactor, PKI, or certificate management environments
- Experience supporting Active Directory forest recovery exercises
- Familiarity with Zero Trust security principles
- Experience working within enterprise cybersecurity programs
Skills
- Strong execution and delivery mindset with the ability to drive technical initiatives
- Security-focused approach with an emphasis on resiliency and risk reduction
- Ability to identify, analyze, and remediate identity security risks
- Effective collaboration within cross-functional cybersecurity and infrastructure teams
- Comfortable working in a fast-paced, project-driven contract environment
Benefits
- Medical, Dental, & Vision Insurance Plans
- Employee-Owned Profit Sharing (ESOP)
- 401(k) offered
Pay
The approximate pay range for this position is up to $65.00 per hour. Final compensation may vary based on factors including but not limited to background, knowledge, skills, and location.
Schedule
Hybrid – onsite three days per week