Vacancy expired!
Senior Active Directory Engineer Job Description
COMPANY OVERVIEW: Founded in 1987, CoStar Group is the leading provider of commercial real estate information, analytics, and online marketplaces. Our suite of online services enables clients to analyze, interpret and gain unmatched insight on commercial property values, market conditions and current availability. Behind some of the most well-known brands in the industry, CoStar Group includes CoStar, the largest provider of CRE research and real-time data; LoopNet, the most heavily trafficked mobile and online real estate marketplace; Apartments.com, the premier rental home resource for renters, property managers and owners; STR, the leading provider of performance benchmarking and comparative analytics to the hotel industry; BizBuySell, the largest online marketplace for businesses-for-sales; and Lands of America, the leading operator of online marketplaces for rural real estate.Headquartered in Washington, DC, CoStar Group maintains offices throughout the U.S. and in Europe, Canada, and Asia with a staff of over 5,000 worldwide. RESPONSIBILITIES:- Be the subject matter expert for Active Directory least privilege operations
- Manage & delegate secrets using Thycotic Secret Server, CyberArk and Hashi C orp Vault
- Creates complex scripts, functions and modules using PowerShell and Python
- Troubleshoots domain controller issues such as high CPU, replication and object issues
- Enhances, supports, and tests our Active Directory disaster recovery environment
- Manage IT Operations access to a very large fleet of Windows and Linux servers
- Troubleshoot MFA and Single-Sign on issues with Duo, Ping, Azure AD
- Supports AWS managed Active Directory
- Manages Zero Trust remote access tools
- Implement IAM tools and policies on our Windows and Linux fleet
- Work with the Security Team to remediate critical security findings
- Bachelor's Degree
- 5+ years managing complex Active Directory environments , including DNS and Group Policy
- 3+ years managing Azure AD in a hybrid environment
- 3-5 years managing MFA solutions for large organizations ( PingID , Microsoft Authenticator, Duo, etc.)
- 2+ years writing PowerShell or Python scripts from scratch
- One or more certifications: Microsoft Certified Solutions Associate (MCSA) , MCSE: Core Infrastructure
- 5+ years managing Windows and Linux operating systems
- Strong knowledge of Active Directory architecture and functionality, including design, networking, protocols, and operations.
- Strong knowledge of Active Directory security architecture, design, and best practices
- Experience with tools like Bloodhound, Mimikatz , Password Spray, rainbow tables, cryptography, etc.
- Knowledge of Azure Active Directory and Azure Active Directory Domain Services operations and best practices.
- Knowledge of multi-factor implementations, such as Duo, Okta, PingID , Microsoft Authenticator, Windows Hello for Business, and Google Authenticator.
- Demonstrated experience automating common operational tasks, web service/API integration, and deployment activities in scripting/programming languages ( e.g. PowerShell, Python, Perl, etc.)
- Understanding of LDAP directory architecture and other products such as OpenLDAP , and RadiantLogic .
- Understanding of HashiCorp Terraform language for deployment of resources into cloud providers.
- Understanding of zero-trust architecture (ZTA) concepts and best practices.
- Comprehensive healthcare coverage: Medical / Vision / Dental / Prescription Drug
- Life, legal, and supplementary insurance
- Commuter and parking benefits
- 401(K) retirement plan with matching contributions
- Employee stock purchase plan
- Paid time off
- Tuition reimbursement
- On-site fitness center and/or reimbursed fitness center membership costs (location dependent), with yoga studio, Pelotons, personal training, group exercise classes, as well as Segways and bikes available for use during the day
- Complimentary gourmet coffee, tea, hot chocolate, prepared foods, fresh fruit, and other healthy snacks
Vacancy expired!