IT Systems Engineer Sr – Active Directory
Ann & Robert H. Lurie Children's Hospital of Chicago · Streeterville, IL · Yesterday
Information Technology$94k–$154k/yrFull-time
About the role
The Active Directory Engineer is the enterprise lead for designing, securing, and modernizing the hospital’s identity infrastructure across on-prem Active Directory and Azure AD (Entra ID).
Responsibilities
- Design, maintain, and upgrade Active Directory forests, domains, trusts, sites, and services, ensuring scalable and resilient identity infrastructure.
- Implement and enforce AD Tiering (Tier 0/1/2) and privileged access boundaries, ensuring secure administrative practices.
- Own the engineering, deployment, optimization, and governance of Group Policy Objects (GPOs)—including secure baseline enforcement, lifecycle management, troubleshooting of processing issues, and cross-team coordination to ensure reliable, conflict-free configuration across the enterprise.
- Develop PowerShell scripts to automate user lifecycle management, privileged access workflows, and routine AD operational tasks.
- Manage synchronization between on-premises AD and Azure Active Directory (Entra ID), including hybrid identity, AAD Connect, and authentication flows.
- Generate reports on system health, performance, and security, including privileged access, stale objects, replication status, and GPO compliance.
- Prepare and interpret technical documentation, including architecture diagrams, system configurations, runbooks, and operational procedures.
- Develops and manages complex projects related to network and server technologies, including desktop technology and deployments where indicated.
- Mentors junior technical staff and/or IM Applications and other IM team members.
- Participate in other department or organizational project tasks as required.
- Partner with the Authentication team leader and technology SMEs to drive adoption of compliant, enterprise-wide authentication solutions aligned to IAM standards.
- Harden AD infrastructure, monitor security events, manage PKI/certificate services, and ensure compliance with security baselines and regulatory requirements.
- Partners with IAM Governance and policy teams to measure, report, and improve authentication controls, and support audit remediation and sustainability.
- Provide transparent reporting to leadership on identity posture, risks, and mitigation strategies.
- Assumes on-call responsibility for data center equipment operations, per the schedule.
- Performs other duties as assigned.
Requirements
- Bachelor’s Degree in Information Systems/Technology/Computer Science preferred (or equivalent work experience)
- 3–5+ years of hands-on experience engineering and supporting Active Directory in complex enterprise environments, including authentication, replication, GPOs, and directory security.
- Deep expertise in Active Directory architecture and services, including forests, domains, trusts, sites, replication, DNS integration, and Group Policy design, processing, and troubleshooting.
- Strong knowledge of identity and authentication principles and protocols, including Kerberos, NTLM, LDAP, SAML, OAuth, OpenID Connect, and modern authentication frameworks.
- Expertise in PKI and certificate lifecycle management, including certificate-based authentication.
- Experience with hybrid identity and cloud directory services, including Microsoft Entra ID, AAD Connect, SSO, and federation.
- Strong understanding of security best practices across identity and core infrastructure, including servers, networks, and application security.
- Hands-on experience with identity and access management (IAM) and privileged access management (PAM) solutions, including MFA, vaulting, and service integrations (e.g., Ping Identity, OpenLDAP, OpenDJ).
- Experience working across Windows, Linux, and cloud-based identity platforms.
- Demonstrated ability to lead and deliver complex technical projects in both individual contributor and team leadership roles.
- Strong analytical, problem-solving, and troubleshooting skills, with the ability to operate independently and make decisions under pressure.
- Excellent communication, documentation, and interpersonal skills, with a focus on collaboration and customer service.
Qualifications
- Education: Bachelor’s Degree in Information Systems/Technology/Computer Science preferred (or equivalent work experience)
- Experience: 3–5+ years of hands-on experience engineering and supporting Active Directory in complex enterprise environments, including authentication, replication, GPOs, and directory security.
- Skills: Deep expertise in Active Directory architecture and services, including forests, domains, trusts, sites, replication, DNS integration, and Group Policy design, processing, and troubleshooting; Strong knowledge of identity and authentication principles and protocols, including Kerberos, NTLM, LDAP, SAML, OAuth, OpenID Connect, and modern authentication frameworks; Expertise in PKI and certificate lifecycle management, including certificate-based authentication; Experience with hybrid identity and cloud directory services, including Microsoft Entra ID, AAD Connect, SSO, and federation; Strong understanding of security best practices across identity and core infrastructure, including servers, networks, and application security; Hands-on experience with identity and access management (IAM) and privileged access management (PAM) solutions, including MFA, vaulting, and service integrations (e.g., Ping Identity, OpenLDAP, OpenDJ); Experience working across Windows, Linux, and cloud-based identity platforms; Demonstrated ability to lead and deliver complex technical projects in both individual contributor and team leadership roles; Strong analytical, problem-solving, and troubleshooting skills, with the ability to operate independently and make decisions under pressure; Excellent communication, documentation, and interpersonal skills, with a focus on collaboration and customer service.
Skills
- PowerShell scripting
- Group Policy Objects (GPOs)
- PKI and certificate lifecycle management
- Hybrid identity and cloud directory services
- Identity and access management (IAM) and privileged access management (PAM) solutions
- Windows, Linux, and cloud-based identity platforms
Benefits
At Lurie Children’s, we offer a comprehensive rewards package that may include differentials for some hourly employees, leadership incentives for select roles, health and retirement benefits, and wellbeing programs. For more details on other compensation, consult your recruiter or click the following link to learn more about our benefits.
- Medical, dental and vision insurance
- Employer paid group term life and disability
- Employer contribution toward Health Savings Account
- Paid Time Off (PTO), Paid Holidays and Paid Parental Leave
- 403(b) with a 5% employer match
- Voluntary benefits such as supplemental life, AD&D and disability, critical illness, accident and hospital indemnity coverage, tuition assistance, student loan servicing and support, adoption benefits, backup childcare and eldercare, employee assistance program, and specialized behavioral health services and resources for employees and family members
- Discount on services at Lurie Children’s facilities
- Discount purchasing program
Pay
$93,600.00 - $154,440.00