waypointjobs

Compunnel Inc.

Principal IAM/AD Engineer -- DAVDC5693168

natick, MA

Check who can apply and the requirements below before continuing.

About this opportunity

Compunnel Inc. lists this Principal IAM/AD Engineer -- DAVDC5693168 opportunity in natick, Massachusetts. Review the employer’s description below for duties, qualifications and application requirements.

Job description

Direct message the job poster from Compunnel Inc.

Senior Technical Recruiter @ Compunnel Inc.

Job Description:

Are you an IAM / AD Engineer with Architect-level knowledge? Our Natick, MA client is looking to bring on a Senior IAM / AD Engineer to help deliver hardened directory services across the organization. This will include modern authentication, ITDR, and Zero Trust controls. This person will provide SME guidance as well as hands on duties such as operating on-prem AD, patching / replication / monitoring / and more. This is a full-time, direct hire position.

Must haves

10+ years enterprise Experience

Active Directory

MS EntraID

PowerShell

Client JD

Do you design secure, resilient Active Directory at scale and enjoy automating identity operations? Join our Security Operations IAM team responsible for enterprise identity foundations across on‑prem Active Directory and Microsoft Entra ID. We partner with Security Engineering, IT, and Compliance to deliver hardened directory services, modern authentication, ITDR capabilities and Zero Trust controls that enable the business.

Responsibilities

Operate and maintain on‑premises Active Directory: domain controller health, patching, promotion/demotion, replication, sites/subnets, time services, SYSVOL/GPO health, and capacity monitoring.

Implement and manage Entra ID capabilities: Conditional Access, Identity Protection risk policies, PIM, and app registrations/service principals.

Monitor, troubleshoot, and optimize directory synchronization and identity lifecycle flows.

Partner with our SOC to drive a successful TDR program. Help build and tune detections to identify threats such as DCSync, Golden/Silver Ticket, Kerberoasting, pass‑the‑hash/ticket, risky sign‑ins, and impossible travel.

Harden AD and Entra ID: apply baselines, admin tiering, PAW usage, secure delegation, privileged workflow controls, regular access reviews, and identity threat hunting.

Automate identity operations and ITDR tasks with PowerShell and APIs (Graph/Entra): alert enrichment, response runbooks, access certifications, reporting, and drift remediation.

Lead complex troubleshooting and incident response for identity (Kerberos/NTLM, replication, DCSync/Golden/Silver Ticket detections, Conditional Access failures); drive root cause and preventive actions.

Produce runbooks, standards, and change records; mentor team members and collaborate with stakeholders to align IAM operations with business needs.

Minimum Qualifications

A bachelor's degree and 10 years of professional work experience (or equivalent experience) is required.

Additional Qualifications

A successful candidate for this role will have a combination of some or all of the following skills/experience:

7+ years in enterprise Active Directory operations and hardening including DC lifecycle management, sites/services, replication, BCDR, and observability.

Hands‑on experience with Microsoft Entra ID: Conditional Access, MFA, Identity Protection, PIM, app registration and service principal governance.

Experience operating Azure AD Connect or Cloud Sync in hybrid identity environments.

Identity Governance and Administration experience for provisioning, role/entitlement models, and access certifications.

Proficiency with PowerShell, Python and Microsoft Graph/Entra APIs for automation.

Experience with privileged access models and administrative tiering.

Ability to support after‑hours maintenance and incident response as needed.

SSO/Federation: SAML/OIDC/OAuth; SCIM provisioning to SaaS apps.

AD security: trusts, LDAP/LDAPS, constrained delegation, GPO hardening.

PKI and certificates: AD CS, CRL/OCSP, auto enrollment, renewal automation for workloads and service principals/certs.

Backup/Recovery: authoritative restore, forest recovery planning and drills.

IaC/automation: DSC, GPO as Code, Git workflows; CI/CD familiarity for scripts/policies.

Compliance familiarity: CMMC, NIST CSF/800‑53/171, ISO 27001

Seniority level

Director

Employment type

Contract

Job function

Finance and Information Technology

Industries

IT Services and IT Consulting and Financial Services

Referrals increase your chances of interviewing at Compunnel Inc. by 2x

Get notified about new Active Directory Specialist jobs in Natick, MA .

#J-18808-Ljbffr

Worksite address

natick, MA, 01760, US

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Ready for your next step?Apply on the official website
Apply on WhatJobs ↗

Explore related searches

Current related jobs

Annapurna Labs (u.s.) Inc.

WhatJobs

PD Engineer, Annapurna Labs

cupertino, CA

Salary not specified

As a member of the Cloud-Scale Machine Learning Acceleration team you'll be responsible for the design and optimization of Hardware in our data c…

Last received from source 2026-10-07View job

Amazon.com Services Llc - A57

WhatJobs

Senior Automation Engineer

suffolk, VA

Salary not specified

Operations is at the heart of Amazon's business. We are known for our speed, accuracy, and exceptional service. Our buildings deliver tens of tho…

Last received from source 2026-10-07View job

Annapurna Labs (u.s.) Inc.

WhatJobs

DFT Design Engineer, Machine Learning Acceleration

austin, TX

Salary not specified

Custom SoCs (System on Chip) are at the heart of AWS Machine Learning servers. As a member of the Cloud-Scale Machine Learning Acceleration team,…

Last received from source 2026-10-07View job