×
Register Here to Apply for Jobs or Post Jobs. X

Directory Services Security Engineer

Job in Fort Worth, Tarrant County, Texas, 76107, USA
Listing for: Pinnacle Technical Resources
Full Time position
Listed on 2026-08-03
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Systems Engineer
Job Description & How to Apply Below
Position
- Security Engineer Location
- Fort Worth, TX (Hybrid) Job  - 178604

Position Overview We are seeking a Directory Services Engineer to support critical cybersecurity initiatives focused on identity infrastructure security, Tier 0 protection, and resiliency. This role is hands-on and execution-focused, working across Active Directory, Microsoft Entra  (Azure AD), and hybrid identity environments. The engineer will play a key role in hardening identity systems, identifying attack paths, and implementing remediation actions to reduce enterprise risk.

________________________________________

Key Responsibilities Identity Engineering & Operations
• Administer and support Active Directory (AD) and Microsoft Entra  (Azure AD) environments.
• Implement and manage Azure AD Connect / Entra Connect for hybrid identity synchronization.
• Support domain controllers, forests, trusts, and authentication services.
• Execute identity-related changes, configurations, and deployments. ________________________________________ Security Hardening & Tier 0 Protection
• Implement security controls for Tier 0 assets (AD, Entra , domain controllers).
• Perform system hardening in alignment with cybersecurity standards.
• Support initiatives for privileged access restrictions and identity protection.
• Remediate identified security gaps and misconfigurations. ________________________________________ Attack Path Identification & Remediation
• Analyze and identify identity-based attack paths across on-prem and cloud environments.
• Support remediation efforts to eliminate: o Privilege escalation paths o Excessive permissions o Identity misconfigurations
• Partner with cybersecurity teams to reduce identity attack surface. ________________________________________ Resiliency & Recovery Support
• Implement and validate Active Directory forest recovery procedures.
• Support backup, restore, and testing activities for identity systems.
• Assist in improving resiliency and recoverability of Tier 0 infrastructure. ________________________________________ Integration Support
• Assist in integration and configuration of identity with: o MFA / Conditional Access o PAM (e.g., Cyber Ark) o IGA (e.g., Saviynt) o Secrets and certificate platforms (e.g., Hashi Corp, Keyfactor)
• Support identity governance and access control initiatives. ________________________________________ Automation & Execution
• Use Power Shell and scripting to automate identity tasks and remediation.
• Execute predefined engineering tasks, runbooks, and operational procedures.
• Document configurations, changes, and implementation steps.

Job Description:

Operationalize automated data discovery, classification, and inventory; apply sensitivity labels and consistent taxonomy across data stores, pipelines, and collaboration systems. Engineer DSPM capabilities with tools (e.g., Securiti, BigID) to surface data posture risks (overexposure, shadow data, stale sensitive data) and drive remediation workflows. Implement and support encryption, tokenization, masking, anonymization/pseudonymization for data at rest and in transit; integrate with cloud key management systems and enforce approved cryptographic standards;

define crypto baselines and policy-as-code guardrails. Configure and govern access controls with RBAC/ABAC and purpose-based authorization; perform least-privilege and fine-grained access reviews across data platforms. Deploy, tune, and operate DLP and DAM solutions (e.g., Microsoft Purview DLP, Imperva/Guardium); build detections for PII/PCI/PHI and reduce false positives with policy and context improvements. Integrate and tune UEBA and Insider Risk signals to detect anomalous data access and exfiltration, partner on response workflows and preventive control changes.

Integrate data protection telemetry with SIEM/SOAR; build detections, correlation rules, and automated response playbooks for data-related threats and policy violations. Implement data minimization and retention/ROT enforcement patterns; automate monitoring of lifecycle actions (archive, delete, redact) aligned to policy and legal holds. Implement DSAR (data subject access request)…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary