Capital One Financial Corporation
Richmond, VASenior Directory Security Engineer
Senior Directory Security Engineer
At Capital One, we’re building a leading information-based technology company. Still founder-led by Chairman and Chief Executive Officer Richard Fairbank, Capital One is on a mission to help our customers succeed by bringing ingenuity, simplicity, and humanity to banking. We measure our efforts by the success our customers enjoy and the advocacy they exhibit. We are succeeding because they are succeeding.
Guided by our shared values, we thrive in an environment where collaboration and openness are valued. We believe that innovation is powered by perspective and that teamwork and respect for each other lead to superior results. We elevate each other and obsess about doing the right thing. Our associates serve with humility and a deep respect for their responsibility in helping our customers achieve their goals and realize their dreams. Together, we are on a quest to change banking for good.
Do you have expert level experience securing Active Directory, Azure Active Directory, AWS Microsoft AD, Google Cloud Directory, LDAP or other directory platforms? Do you have a desire to learn and work on exciting leading edge technologies and design solutions for complex on-premises and cloud-based Directory security challenges? If so, then this opportunity might be for you.
Capital One is seeking an expert level Senior Directory Security Engineer within the Identity and Access Management organization to be a senior engineer on a team responsible for securing Capital One’s enterprise Directory Services environment that includes Active Directory, Azure Active Directory, AWS Microsoft Active Directory, and Google Cloud Domain Directory.
Candidates for this role should have expert level knowledge and experience in securing complex enterprise level Active Directory environments and have a passion for risk assessment and mitigation, learning new cloud based technologies, and driving automated and efficient solutions to complex problems.
Responsibilities:
-
Be one of several senior engineers on a team responsible for the security of Capital One’s enterprise Active Directory environment including on-premise and cloud environments from AWS, Microsoft Azure, and Google Cloud
-
Provide technical leadership during the analysis, troubleshooting, and investigation of security related events within the Active Directory platforms
-
Evaluate and recommend information security products, technologies, and procedures by proactively identifying problems and evaluating industry trends
-
Provide input so the Active Directory roadmap aligns with security initiatives, business needs, and forward looking requirements
-
Manage quarterly security audits and ensure the Active Directory environment adheres to security and compliance settings
-
Be the project lead or participate as a team member on various projects within or across technology and business teams
-
Manage the engineering and implementation of solutions that will secure and protect Capital One’s Active Directory environment
-
Manage vulnerability assessments and security testing to proactively identify and close security risks within the Active Directory environment
-
Architect, engineer, and deploy third-party security monitoring tools to protect the environment and monitor for security breaches, intrusions and irregular system behavior
-
Partner with CyberSecurity engineers to implement technology solutions
-
Participate in disaster recovery, capacity planning, performance monitoring and maintenance to ensure high availability of security monitoring systems
-
Participate in the evaluation, development, and implementation of security standards and best practices for Active Directory and recommend security enhancements to management as needed
-
Evaluate, test, and select new security, compliance, and audit tools
-
Educate team members on information security through training and increased awareness
-
Partner with CyberSecurity teams to support forensic investigations and ensure integration with enterprise SIEM systems
Basic Qualifications:
-
High school diploma, GED or equivalent certification
-
At least 5 years of experience with Active Directory
-
At least 3 years of experience securing enterprise level Active Directory environments
-
At least 3 years of experience preventing Active Directory credential theft attacks (Pass the Hash, Golden Ticket or lateral movement)
-
At least 3 years of experience with Group Policy Objects, Security Log Analysis and Delegation of Permissions
-
At least 3 years of experience developing scripts or queries to generate reports against Active Directory
-
At least 3 years of experience monitoring and analyzing logs from Active Directory
-
At least 3 years of experience using Security Information and Event Management (SIEM) and Log aggregation platforms including, Splunk, Snowflake, Quest, or StealthBits
Preferred Qualifications:
-
Bachelor’s or Master’s degree in Computer Science, Information Systems, or Engineering
-
4+ years of experience developing complex scripts in PowerShell, VBScript, JavaScript, Python or other languages to develop automated solutions
-
3+ years of experience supporting Active Directory in a cloud hosted environment from AWS, Microsoft, or Google
-
3+ years of experience with Windows Server 2012, 2016 and 2019 Active Directory
-
CISSP, CISM, or CEH security certification.
A t this time, Capital One will not sponsor a new applicant for employment authorization for this position.