This role is four days onsite at our Seneca One Buffalo, NY location, with the flexibility to work from home one day per weekOverview: Responsible for designing, securing, and operating Microsoft Active Directory Domain Services (AD DS) in regulated, high-availability environments. Acts as knowledge resource for and trains less experienced engineers. Completes day-to-day support activities and special projects.Primary Responsibilities:Enterprise Active Directory ArchitectureProven expertise supporting large-scale, Tier‑1 identity infrastructures with strict uptime, latency, and change‑control requirementsStrong experience with: Multi-domain and multi-forest designs aligned to business units, regions, or regulatory boundariesForest and external trusts supporting M&A, joint ventures, and third-party integrationsFSMO role placement optimized for resilience and auditabilityAdvanced understanding of Active Directory–integrated DNS, split‑brain DNS, and secure name resolution modelsHybrid Identity & Microsoft Entra ID (Azure AD)Extensive experience integrating on-prem AD with Microsoft Entra ID in regulated financial environmentsHands-on implementation of: Entra Connect (Cloud Sync and Traditional)Password Hash Sync, Pass-through Authentication, and FederationStrong experience with: Conditional Access aligned to regulatory and risk-based controlsHybrid Join, Entra ID Join, and legacy device coexistenceUnderstanding of identity lifecycle controls to support joiners, movers, leavers, and separation-of-duties requirementsSecurity, Compliance & Risk ControlsExpert-level knowledge of Active Directory security hardening in financial services, including: Tiered administrative model (Tier 0/1/2)Dedicated admin forests or hardened admin boundaries (where applicable)Privileged Access Workstations (PAWs) / Secure Admin WorkstationsExperience enforcing least privilege, role separation, and dual‑control modelsDeep familiarity with threats targeting financial institutions: Credential theft, Kerberoasting, Pass-the-Hash/TicketDelegation and ACL abuseHands-on experience with: Privileged Identity Management (PIM)Regular access reviews and entitlement recertificationStrong alignment with Zero Trust and defense-in-depth identity strategiesRegulatory & Audit ReadinessDemonstrated experience supporting audits and controls for financial regulations and frameworks, such as: SOX, GLBA, PCI DSS, SOC 2Internal risk management and model governance requirementsAbility to design AD environments that support: Strong logging and traceabilityTamper-resistant audit logsEvidence generation for internal and external auditorsAutomation & PowerShellAdvanced PowerShell expertise for: Controlled, auditable administrative changesAutomated provisioning/deprovisioning aligned to compliance workflowsIdentity reporting for risk, security, and audit teamsExperience building automation that integrates with: Change management processesIAM, ticketing, and security toolingOperations, Resilience & RecoveryDeep experience managing: AD replication topology across data centers and regionsSYSVOL (DFSR) health and recoveryLatency-sensitive authentication dependenciesStrong understanding of: AD backup, recovery, and authoritative restore proceduresIdentity disaster recovery scenarios with defined RTO/RPOExperience implementing monitoring and alerting with a focus on early risk detectionLeadership & GovernanceActs as technical authority and escalation point for all directory and identity servicesDefines and enforces: Enterprise identity standardsSecure configuration baselinesOperational runbooks and proceduresPartners closely with: Information Security and IAM teamsRisk, audit, and compliance stakeholdersInfrastructure, cloud, and application teamsMentors engineers and reviews designs from a security and risk-first perspectiveEducation and Experience Required:Bachelor's degree and a minimum of 5 years’ relevant work experience, or in lieu of a degree, a combined minimum of 9 years’ higher education and/or work experienceEducation and Experience Preferred:Advanced understanding of the security system development and infrastructure lifecycle and architecture, and systems designProven experience with the development and customization of tools utilized in assigned Cybersecurity functionDemonstrated ability to translate architecture into technical requirementsProficient level of critical thinking and problem solving abilityExcellent communication and interpersonal skillsExperience partnering with leaders to design solutions to business needs.Proficient persuasive communication skills to gain buy-in of othersStrong ability to analyze and draw reliable conclusions based on large volumes of quantitative data from diverse sourcesAbility effectively serves in indirect leadership role#LI-JB3 #HybridM&T Bank is committed to fair, competitive, and market-informed pay for our employees.
The pay range for this position is $116,400.00 - $194,000.00 Annual (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.LocationBuffalo, New York, United States of AmericaSummaryLocation: Buffalo, NYType: Full time
Lead Active Directory Engineer in buffalo at Unknown Company
This position is listed as full time and able to be worked remotely.