More jobs:
IT Systems Engineer Sr – Active Directory
Job in
Chicago, Cook County, Illinois, 60290, USA
Listed on 2026-07-24
Listing for:
Lurie Children's
Full Time
position Listed on 2026-07-24
Job specializations:
-
IT/Tech
Systems Engineer, Cybersecurity
Job Description & How to Apply Below
You may choose to display a cookie banner on the external site. You must specify the message in the cookie banner and may add a link to a relevant policy. If you are unfamiliar with these requirements, please seek the advice of legal counsel.#IT Systems Engineer Sr – Active Directory page is loaded## IT Systems Engineer Sr – Active Directory Apply locations:
Streeterville, Chicago, ILtime type:
Full time posted on:
Posted Todayjob requisition :
JRAnn & Robert H. Lurie Children’s Hospital of Chicago provides superior pediatric care in a setting that offers the latest benefits and innovations in medical technology, research and family-friendly design. As the largest pediatric provider in the region with a 140-year legacy of excellence, kids and their families are at the center of all we do. Ann & Robert H. Lurie Children’s Hospital of Chicago is ranked in all 10 specialties by the U.S. News & World Report.
** Location
* * 680 Lake Shore Drive
** Job Description
** The
** Active Directory Engineer
** is the enterprise lead for designing, securing, and modernizing the hospital’s identity infrastructure across on‐prem Active Directory and Azure AD (Entra ). Responsible for engineering, and maintenance of AD forests, GPOs, PKI, privileged access, and hybrid identity services in alignment with security, audit, and IAM standards. The engineer leads identity remediation efforts, partners with security teams to strengthen controls, reports on identity risk and health, and mentors staff while advancing secure authentication and directory stability across the organization.
*
* Essential Job Functions:
*** Design, maintain, and upgrade Active Directory forests, domains, trusts, sites, and services, ensuring scalable and resilient identity infrastructure.
* Implement and enforce AD Tiering (Tier 0/1/2) and privileged access boundaries, ensuring secure administrative practices.
* Own the engineering, deployment, optimization, and governance of Group Policy Objects (GPOs)—including secure baseline enforcement, lifecycle management, troubleshooting of processing issues, and cross‐team coordination to ensure reliable, conflict‐free configuration across the enterprise.
* Develop Power Shell scripts to automate user lifecycle management, privileged access workflows, and routine AD operational tasks.
* Manage synchronization between on‐premises AD and Azure Active Directory (Entra ), including hybrid identity, AAD Connect, and authentication flows.
* Lead high-level troubleshooting for authentication, replication, DNS, and LDAP issues across multisite environments.
* Generate reports on system health, performance, and security, including privileged access, stale objects, replication status, and GPO compliance.
* Prepare and interpret technical documentation, including architecture diagrams, system configurations, runbooks, and operational procedures.
* Develops and manages complex projects related to network and server technologies, including desktop technology and deployments where indicated.
* Mentors junior technical staff and/or IM Applications and other IM team members.
* Participate in other department or organizational project tasks as required.
* Partner with the Authentication team leader and technology SMEs to drive adoption of compliant, enterprise-wide authentication solutions aligned to IAM standards.
* Harden AD infrastructure, monitor security events, manage PKI/certificate services, and ensure compliance with security baselines and regulatory requirements.
* Apply industry best practices and proactively identify and remediate identity and authentication gaps to continuously strengthen enterprise controls.
* Partners with IAM Governance and policy teams to measure, report, and improve authentication controls, and support audit remediation and sustainability.
* Provide transparent reporting to leadership on identity posture, risks, and mitigation strategies.
* Assumes on-call responsibility for data center equipment operations, per the schedule.
* Performs other duties as assigned.
*
* Knowledge, Skills and Abilities:
**
* Education:
Bachelor’s Degree in Information…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×