Job Description:
At Bank of America we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients teammates communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace attracting and developing exceptional talent supporting our teammates physical emotional and financial wellness recognizing and rewarding performance and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
At Bank of America you can build a successful career with opportunities to learn grow and make an impact. Join us!
Job Description:
This job is responsible for tool and service designs within a technical domain that enable business strategies in accordance with architectural governance standards and policies. Key responsibilities include creating infrastructure tools and their integration as a service facilitating deployment of technical solutions by developing templates playbooks and automation used during implementation. Job expectations include looking for opportunities to improve efficiency when implementing and maintaining tools/services and embracing a culture of innovation and continuous improvement.
The Active Directory Security & GPO Engineering team is seeking an AD Security Engineer responsible for analysis design implementation coordination and 4th level escalation support of complex enterprise level Active Directory solutions specifically pertaining to security. The individual will work within the engineering organization interacting with peer teams and partner groups scaling and deploying improvement consolidation and migration efforts within the enterprise. The candidate must be able to operate and function well in a multi-cultural geographically dispersed virtual team environment.
Responsibilities:
Provides subject matter expertise and consulting services on a range of technologies and assists Technical Analysts and Infrastructure Engineers to ensure that technology solutions comply with enterprise system design and engineering standards
Assists with translating business requirements into technical definitions reference models blueprints and playbooks for deployment in compliance with architecture standards and policies
Assists in the evaluation of reference models blueprints and playbooks to ensure they are fit for purpose
Develops software solutions to address manual and repeatable work or inefficient processes
Conducts on-site evaluations of third-party products being considered for firm adoption
Promotes an inclusive and healthy working environment and helps to resolve organizational impediments/blockers
Contributes to the creation/selection of functional and non-functional product evaluation requirements within and across domains
Analysis design capacity planning and implementation of Active Directory Security Translate business needs into workable technology solutions that meet the requirements of internal customers and peer Active Directory Engineering and Operations teams
Responsible for developing standards target states roadmaps effectively socializing and obtaining consensus across architecture engineering and operations teams
Independently manage and perform engineering role for large scale Active Directory efforts and initiatives
Perform various functions and duties in support of audit and compliance deliverables verification/remittance of directory security evidence
Develop detailed architecture standards design and implementation documentation
Analyze current Active Directory environment to identify both technical and operational challenges while making recommendations and developing solutions for improvement
Participate in or lead complex or high severity troubleshooting and incident/problem resolutions with other infrastructure teams
Required Qualifications:
At least 5-10 years of dedicated Active Directory engineering and architecture experience that includes designing implementing and maintaining complex enterprise level (50K objects) Active Directory solutions and security models
Overarching broad and deep technical experience with Active Directory Security Extensive experience and advanced knowledge implementing Windows security concepts and policies least-privilege design principles
Extensive knowledge of AD Security best-practices latest security threats/trends and mitigation thereof
Experience with best practices for Active Directory disaster recovery object management security models and trust creation
Granular ACE permissions models meeting functional and technical requirements
Advanced PowerShell scripting experience and capabilities
Strong working knowledge of Windows Server operating systems platforms DNS networks DMZs firewalls network security zones and IPv6
Deep in-depth working knowledge of Kerberos (Microsoft and MIT/Heimdal) and NTLM authentication MFA SSO and federation technologies
Extensive and deep knowledge of Group Policy Objects (GPOs) engineering implementing and 3rd party management solutions thereof
Strong knowledge of LDAP and ability to comfortably construct queries
Experience performing large scale upgrades migrations transitions and consolidation of Active Directory domains and forests
Experience and confidence to be the subject matter expert (SME) in an environment of this size and scale in order to coordinate technical efforts and resolve issues across multiple teams
Working knowledge of Certificate/CA/PKI infrastructure Excellent communication skills including proven experience effectively communicating technical challenges and solutions to peers customers and senior management.
Demonstrable expertise in DevOps methodologies.
Ability to automate process via orchestration products such as Jenkins Terraform Ansible REST API Chef etc. Extensive expertise scripting via PowerShell python or similar.
Skills:
Analytical Thinking
Application Development
Automation
Production Support
Risk Management
Adaptability
Business Acumen
DevOps Practices
Solution Delivery Process
Solution Design
Architecture
Collaboration
Innovative Thinking
Stakeholder Management
Technical Strategy Development
Shift:
1st shift (United States of America)Hours Per Week:
40Required Experience:
IC
What would you like the power to do? At Bank of America, our purpose is to help make financial lives better through the power of every connection.