Relomote
Remote JobsRelocation Jobs
Add companySaved
Relomote

Relomote is a job board for remote, hybrid, and relocation jobs — every listing AI-classified for the countries it actually hires from, or the visa and relocation support it offers.

LinkedInCrunchbase

Remote jobs by category

  • Remote Engineering & Development jobs
  • Remote Customer Support jobs
  • Remote Design jobs
  • Remote Marketing jobs
  • Remote Sales jobs
  • Remote Product jobs
  • Remote Data & Analytics jobs
  • Remote People & Talent jobs
  • Remote Writing & Content Creation jobs
  • Remote Finance jobs
  • Remote Legal & Compliance jobs
  • Remote Operations & Admin jobs
  • Remote Data Entry jobs
  • Remote Virtual Assistant jobs
  • Remote Education & Training jobs
  • Remote Healthcare & Nursing jobs
  • Remote Other jobs

Remote jobs by location

  • Work from anywhere jobs
  • Remote jobs in Africa
  • Remote jobs in Asia
  • Remote jobs in Europe
  • Remote jobs in Latin America
  • Remote jobs in Middle East
  • Remote jobs in North America
  • Remote jobs in Oceania
  • All remote jobs →

Relocation & visa sponsorship

  • Visa sponsorship jobs
  • Relocation package jobs
  • Relocate to Europe
  • Relocate to Germany
  • Relocate to Netherlands
  • Relocate to Spain
  • Relocate to Portugal
  • Relocate to Greece
  • Relocate to United Kingdom
  • Relocate to Canada
  • Relocate to Australia
  • Relocate to Sweden
  • Relocate to Switzerland
  • Relocate to Japan
  • Relocate to United Arab Emirates
  • All relocation jobs →

© 2026 RelomoteAboutPrivacyTermsLogos provided by Logo.dev

Contact mahmoud@relomote.com · Built by Mahmoud

Relomote
Remote JobsRelocation Jobs
Add companySaved
Mtb logo

Senior Active Directory Engineer

Mtb
Posted 4 hours ago
🇺🇸United States🏢Hybrid💰$97.1K–$161.8K📁Engineering & Development
Is this job info correct?

This role is four days onsite at our Seneca One Buffalo, NY location, with the flexibility to work from home one day per week Overview: Responsible for designing, securing, and operating Microsoft Active Directory Domain Services (AD DS) in regulated, high-availability environments. Acts as knowledge resource for and trains less experienced engineers. Completes day-to-day support activities and special projects. Primary Responsibilities: Enterprise Active Directory Architecture Proven expertise supporting large-scale, Tier‑1 identity infrastructures with strict uptime, latency, and change‑control requirements Strong experience with: Multi-domain and multi-forest designs aligned to business units, regions, or regulatory boundaries Forest and external trusts supporting M&A, joint ventures, and third-party integrations FSMO role placement optimized for resilience and auditability Advanced understanding of Active Directory–integrated DNS , split‑brain DNS, and secure name resolution models Hybrid Identity & Microsoft Entra ID (Azure AD) Extensive experience integrating on-prem AD with Microsoft Entra ID in regulated financial environments Hands-on implementation of: Entra Connect (Cloud Sync and Traditional) Password Hash Sync, Pass-through Authentication, and Federation Strong experience with: Conditional Access aligned to regulatory and risk-based controls Hybrid Join, Entra ID Join, and legacy device coexistence Understanding of identity lifecycle controls to support joiners, movers, leavers, and separation-of-duties requirements Security, Compliance & Risk Controls Expert-level knowledge of Active Directory security hardening in financial services, including: Tiered administrative model (Tier 0/1/2) Dedicated admin forests or hardened admin boundaries (where applicable) Privileged Access Workstations (PAWs) / Secure Admin Workstations Experience enforcing least privilege , role separation, and dual‑control models Deep familiarity with threats targeting financial institutions: Credential theft, Kerberoasting, Pass-the-Hash/Ticket Delegation and ACL abuse Hands-on experience with: Privileged Identity Management (PIM) Regular access reviews and entitlement recertification Strong alignment with Zero Trust and defense-in-depth identity strategies Regulatory & Audit Readiness Demonstrated experience supporting audits and controls for financial regulations and frameworks, such as: SOX, GLBA, PCI DSS, SOC 2 Internal risk management and model governance requirements Ability to design AD environments that support: Strong logging and traceability Tamper-resistant audit logs Evidence generation for internal and external auditors Automation & PowerShell Advanced PowerShell expertise for: Controlled, auditable administrative changes Automated provisioning/deprovisioning aligned to compliance workflows Identity reporting for risk, security, and audit teams Experience building automation that integrates with: Change management processes IAM, ticketing, and security tooling Operations, Resilience & Recovery Deep experience managing: AD replication topology across data centers and regions SYSVOL (DFSR) health and recovery Latency-sensitive authentication dependencies Strong understanding of: AD backup, recovery, and authoritative restore procedures Identity disaster recovery scenarios with defined RTO/RPO Experience implementing monitoring and alerting with a focus on early risk detection Leadership & Governance Acts as technical authority and escalation point for all directory and identity services Defines and enforces: Enterprise identity standards Secure configuration baselines Operational runbooks and procedures Partners closely with: Information Security and IAM teams Risk, audit, and compliance stakeholders Infrastructure, cloud, and application teams Mentors engineers and reviews designs from a security and risk-first perspective Education and Exp erience Required: Bachelor's degree and a minimum of 3 years’ relevant work experience, or in lieu of a degree, a combined minimum of 7 years’ higher education and/or work experience Education and Experience Preferred: Intermediate understanding of the security system development and infrastructure lifecycle and architecture, and systems design Proven experience with the tools utilized in assigned Cybersecurity function Experience translating architecture into technical requirements. Proficient level of critical thinking and problem solving Excellent written and verbal communication skills Proven experience collaborating with leaders to execute results. Prior experience seeking buy-in of others to align on processes. Ability to analyze and draw conclusions based on quantitative data from multiple sources. M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $97,100.00 - $161,800.00 (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation. Location Buffalo, New York, United States of America

Similar jobs

Similar jobs

Coupa Software, Inc. logo

Lead Site Reliability Engineer - Active Directory

Coupa Software, Inc.

🇺🇸United States2 weeks ago
CB5 Solutions logo

Sr Active Directory Engineer

CB5 Solutions

🇺🇸United States3 weeks ago
Xperteks logo

L3 Systems Engineer (Microsoft, Azure, Active Directory

Xperteks

🇺🇸United StatesMay 28, 2026, 10:20 AM UTC
Icanbwell logo

Senior Backend Engineer - Provider Directory

Icanbwell

🇺🇸United StatesJun 23, 2026, 6:55 AM UTC
Ahu Technologies Inc logo

Senior Directory Infrastructure engineer with 10Yrs experience

Ahu Technologies Inc

🇺🇸United StatesMay 27, 2026, 10:10 PM UTC
Ahu Technologies Inc logo

Senior Directory Infrastructure engineer

Ahu Technologies Inc

🇺🇸United StatesMay 27, 2026, 10:10 PM UTC