×
Register Here to Apply for Jobs or Post Jobs. X

IT Systems Engineer Sr – Active Directory

Job in Chicago, Cook County, Illinois, 60290, USA
Listing for: 10 HOSP Ann & Robert H. Lurie Children's Hospital of Chicago
Full Time position
Listed on 2026-07-23
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer
Salary/Wage Range or Industry Benchmark: 93600 - 154440 USD Yearly USD 93600.00 154440.00 YEAR
Job Description & How to Apply Below

Job Summary

Ann & Robert H. Lurie Children's Hospital of Chicago provides superior pediatric care in a setting that offers the latest benefits and innovations in medical technology, research and family‑friendly design. The Active Directory Engineer is the enterprise lead for designing, securing, and modernizing the hospital's identity infrastructure across on‑prem Active Directory and Azure AD (Entra ).

Location:

680 Lake Shore Drive

Essential Job Functions
  • Design, maintain, and upgrade Active Directory forests, domains, trusts, sites, and services, ensuring scalable and resilient identity infrastructure.
  • Implement and enforce AD Tiering (Tier 0/1/2) and privileged access boundaries, ensuring secure administrative practices.
  • Own the engineering, deployment, optimization, and governance of Group Policy Objects (GPOs) — including secure baseline enforcement, lifecycle management, troubleshooting of processing issues, and cross‑team coordination.
  • Develop Power Shell scripts to automate user lifecycle management, privileged access workflows, and routine AD operational tasks.
  • Manage synchronization between on‑premises AD and Azure Active Directory (Entra ), including hybrid identity, AAD Connect, and authentication flows.
  • Lead high‑level troubleshooting for authentication, replication, DNS, and LDAP issues across multisite environments.
  • Generate reports on system health, performance, and security, including privileged access, stale objects, replication status, and GPO compliance.
  • Prepare and interpret technical documentation, including architecture diagrams, system configurations, runbooks, and operational procedures.
  • Develop and manage complex projects related to network and server technologies, including desktop technology and deployments.
  • Mentor junior technical staff and/or IM Applications and other IM team members.
  • Participate in other department or organizational project tasks as required.
  • Partner with the Authentication team leader and technology SMEs to drive adoption of compliant, enterprise‑wide authentication solutions aligned to IAM standards.
  • Harden AD infrastructure, monitor security events, manage PKI/certificate services, and ensure compliance with security baselines and regulatory requirements.
  • Apply industry best practices and proactively identify and remediate identity and authentication gaps to continuously strengthen enterprise controls.
  • Partner with IAM Governance and policy teams to measure, report, and improve authentication controls, and support audit remediation and sustainability.
  • Provide transparent reporting to leadership on identity posture, risks, and mitigation strategies.
  • Assume on‑call responsibility for data center equipment operations, per the schedule.
  • Perform other duties as assigned.
Knowledge, Skills & Abilities
  • 3–5+ years of hands‑on experience engineering and supporting Active Directory in complex enterprise environments, including authentication, replication, GPOs, and directory security.
  • Deep expertise in Active Directory architecture and services, including forests, domains, trusts, sites, replication, DNS integration, and Group Policy design, processing, and troubleshooting.
  • Strong knowledge of identity and authentication principles and protocols, including Kerberos, NTLM, LDAP, SAML, OAuth, OpenID Connect, and modern authentication frameworks.
  • Expertise in PKI and certificate lifecycle management, including certificate‑based authentication.
  • Experience with hybrid identity and cloud directory services, including Microsoft Entra , AAD Connect, SSO, and federation.
  • Strong understanding of security best practices across identity and core infrastructure, including servers, networks, and application security.
  • Hands‑on experience with identity and access management (IAM) and privileged access management (PAM) solutions, including MFA, vaulting, and service integrations (e.g., Ping Identity, OpenLDAP, OpenDJ).
  • Experience working across Windows, Linux, and cloud‑based identity platforms.
  • Demonstrated ability to lead and deliver complex technical projects in both individual contributor and team leadership roles.
  • Strong analytical, problem‑solving, and troubleshooting skills, with the…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary