
Security Engineer, Purview
Posted Jul 25

Posted Jul 25
This is a fully remote position, open to applicants in Texas.
• Evaluate the existing configuration of the client's Active Directory and Azure/Entra ID setup, encompassing forest design, site design, domain design, security group structure, deployment architecture, organizational unit (“OU”) structure, authentication methods, and group policy design.
• Oversee the migration of enterprise data governance and compliance frameworks to Microsoft Purview, ensuring secure data management and adherence to regulatory standards.
• Execute PowerShell queries on the client's AD to gather pertinent statistics about current AD and Azure objects, including users, accounts, groups, organizational units (OUs), computer objects, and associated identity objects.
• Generate SailPoint out-of-the-box reports regarding AD connectivity to deliver insights on group and account ownership and membership.
• Examine AD configurations, processes, and documentation to gain an understanding of the client's ongoing deployment and operational model.
• Identify gaps in configuration and operations within the client's AD domains, infrastructure, architecture, and deployment.
• Rank identified gaps based on their significance and associated risks.
• Offer recommendations to mitigate critical gaps and risks across AD and Entra ID environments.
• Investigate and evaluate existing procedures for AD group management, AD group policy management, and AD account management.
• Recommend adjustments and enhancements to current processes and develop new processes as necessary.
• Assess the resources and skills required to carry out remediation efforts and meet established milestones.
• Provide a projected budget for remediation activities as discussed during the assessment phases.
• Utilize client tools such as ADUC (Active Directory Users & Computers), ManageEngine, StealthAUDIT, or other AD scanning utilities as needed to perform data-gathering tasks.
• Extensive experience as an Active Directory Architect, including domain consolidation, AD evaluation, and enterprise identity infrastructure analysis.
• Practical knowledge of Active Directory forest, site, domain, OU, security group, authentication methods, and group policy design.
• Experience in evaluating Azure/Entra ID deployments and hybrid identity environments.
• Proficient in executing and interpreting PowerShell queries against AD domains to collect data on users, accounts, groups, OUs, computer objects, and related AD/Azure entities.
• Familiarity with SailPoint reports for analyzing AD group and account ownership and membership.
• Skill in identifying configuration and operational deficiencies and prioritizing them according to their significance and risk.
• Experience in reviewing AD configurations, workflows, and documentation.
• Knowledge of tools like ADUC, ManageEngine, StealthAUDIT, and other AD scanning utilities.
• Ability to provide actionable recommendations, inputs for remediation planning, resource assessments, skill requirements, and budget projections.
• Excellent communication skills to document insights, recommendations, risks, and remediation strategies for stakeholders.
• Health insurance
• 401(k)
• Paid time off
• Flexible work arrangements
• Professional development opportunities
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.