Project/Client:Banking
Location:Baltic States (remote)
Start Date:ASAP
Duration:Until 2026-12-31 with possible extension
Seniority:Senior
Language:English
We are looking for a Senior Security Engineer to join a bankingsector Security Engineering team. The engagement is centered around an Active DirectoryHygiene Initiative, focused on remediating security, configuration, and architectural issues within an enterprise Active Directoryenvironment. The consultants will collaborate closely with Security Engineering and Infrastructure teams to analyze, design, improve, and secure the Active Directoryenvironment, ensuring alignment with modern identity & access management, compliance, and operational standards. The role requires strong hands-on expertise in Active Directoryarchitecture, security hardening, Microsoft Entra IDhybrid integration, and PKIservices.
Key Responsibilities:
Analyze, design, and improve the enterprise Active Directoryarchitecture, including Forest and Domain Management
Implement Active Directory Security Hardeningpractices including Tiering, ESAE/Red Forest, and PAMmodels
Manage and optimize Identity & Access Managementprocesses and policies
Drive Microsoft Entra IDhybrid integration and Active Directory Federation Services (ADFS)configurations
Design, govern, and maintain Group Policyframeworks across the environment
Manage Active Directory Replicationand DNS Architectureto ensure stability and performance
Oversee PKIAD Certificate Servicesintegration and lifecycle management
Administer and troubleshoot Kerberosand authentication flows
Develop and maintain PowerShellautomation and scripting for operational efficiency
Plan and execute Active Directory Disaster Recovery, backup, and restore procedures
Lead or contribute to Active Directory Migration & Consolidationusing ADMT
Ensure compliance with NISTand DORAaligned auditing and governance standards
Must-Have Requirements:
Proven expertise in Active Directory Architecture & Designin large-scale enterprise environments
Hands-on experience with Forest and Domain Management
Deep knowledge of Active Directory Security Hardening— Tiering, ESAE/Red Forest, PAM
Strong background in Identity & Access Management
Experience with Microsoft Entra IDhybrid integration
Proficiency with Active Directory Federation Services (ADFS)
Solid experience in Group Policydesign and governance
Knowledge of Active Directory Replicationand DNS Architecture
Hands-on experience with PKIAD Certificate Servicesintegration
Strong understanding of Kerberosand authentication flows
Proficiency in PowerShellautomation and scripting
Experience with Active Directory Disaster Recoveryand backup/restore procedures
Familiarity with Active Directory Migration & Consolidationusing ADMT
Knowledge of NISTand DORAcompliance and auditing frameworks
Solid networking fundamentals and strong troubleshooting and analytical skills
Fluent English(spoken and written)
Nice to Have:
Expertise in Microsoft AzureEntra IDcloud-native capabilities
Hands-on experience with AWS
Background in the bankingor financial servicesindustry
📩 Ready to Join?
We look forward to receiving your application and welcoming you to our team!

BONAPOLIA is a staffing company offering augmentation and recruitment services to place the right people with the right jobs in the USA, Europe, and Scandinavia. Whether you are looking to hire new staff or find a new job, we’re happy to offer you our services. Contact us up to arrange an appointment. We’ll have your hiring or job-seeking needs met in no time by one of our professional team members.