Senior Directory Security Engineer

Capital One
Richmond, Virginia
Dec 29, 2021
Jan 27, 2022
Full Time
West Creek 4 (12074), United States of America, Richmond, Virginia

Senior Directory Security Engineer

Do you have expert level experience securing Active Directory, Azure Active Directory, AWS Microsoft AD, Google Cloud Directory, LDAP or other directory platforms? Do you have a desire to learn and work on exciting leading edge technologies and design solutions for complex on-premises and cloud-based Directory security challenges? If so, then this opportunity might be for you.

Capital One is seeking an expert level Senior Directory Security Engineer within the Identity and Access Management organization to be a senior engineer on a team responsible for securing Capital One's enterprise Directory Services environment that includes Active Directory, Azure Active Directory, AWS Microsoft Active Directory, and Google Cloud Domain Directory.

Candidates for this role should have expert level knowledge and experience in securing complex enterprise level Active Directory environments and have a passion for risk assessment and mitigation, learning new cloud based technologies, and driving automated and efficient solutions to complex problems.


  • Be one of several senior engineers on a team responsible for the security of Capital One's enterprise Active Directory environment including on-premise and cloud environments from AWS, Microsoft Azure, and Google Cloud
  • Provide technical leadership during the analysis, troubleshooting, and investigation of security related events within the Active Directory platforms
  • Evaluate and recommend information security products, technologies, and procedures by proactively identifying problems and evaluating industry trends
  • Provide input so the Active Directory roadmap aligns with security initiatives, business needs, and forward looking requirements
  • Manage quarterly security audits and ensure the Active Directory environment adheres to security and compliance settings
  • Be the project lead or participate as a team member on various projects within or across technology and business teams
  • Manage the engineering and implementation of solutions that will secure and protect Capital One's Active Directory environment
  • Manage vulnerability assessments and security testing to proactively identify and close security risks within the Active Directory environment
  • Architect, engineer, and deploy third-party security monitoring tools to protect the environment and monitor for security breaches, intrusions and irregular system behavior
  • Partner with CyberSecurity engineers to implement technology solutions
  • Participate in disaster recovery, capacity planning, performance monitoring and maintenance to ensure high availability of security monitoring systems
  • Participate in the evaluation, development, and implementation of security standards and best practices for Active Directory and recommend security enhancements to management as needed
  • Evaluate, test, and select new security, compliance, and audit tools
  • Educate team members on information security through training and increased awareness
  • Partner with CyberSecurity teams to support forensic investigations and ensure integration with enterprise SIEM systems

Key Terms: Active Directory, Windows, Microsoft, Azure, AzureAD, AWS, Google Cloud, Powershell, IAM, Directory Services, LDAP. Security, Compliance

Basic Qualifications:
  • High school diploma, GED or equivalent certification.
  • At least 5 years of experience with Active Directory
  • At least 3 years of experience securing Active Directory environments
  • At least 3 years of experience preventing Active Directory credential theft attacks using Pass the Hash, Golden Ticket or Lateral Movement
  • At least 3 years of experience with Group Policy Objects, Security Log Analysis and Delegation of Permissions
  • At least 3 years of experience developing scripts or queries to generate reports against Active Directory
  • At least 3 years of experience monitoring and analyzing logs from Active Directory
  • At least 3 years of experience with Security Information and Event Management (SIEM) and Log aggregation platforms using Splunk, Snowflake, Quest, or StealthBits

Preferred Qualifications:
  • Bachelor's Degree
  • 4+ years of experience developing scripts for automated solutions with PowerShell, VBScript, JavaScript, or Python
  • 3+ years of experience supporting Active Directory in a cloud hosted environment from AWS, Microsoft, or Google
  • 3+ years of experience with Windows Server 2012, 2016 and 2019 Active Directory
  • CISSP, CISM, or CEH security certification

At this time, Capital One will not sponsor a new applicant for employment authorization for this position.

No agencies please. Capital One is an Equal Opportunity Employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex, race, color, age, national origin, religion, physical and mental disability, genetic information, marital status, sexual orientation, gender identity/assignment, citizenship, pregnancy or maternity, protected veteran status, or any other status prohibited by applicable national, federal, state or local law. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

For technical support or questions about Capital One's recruiting process, please send an email to

Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.

Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).

Similar jobs