Principal, Cyber Security: Active Directory Security Architect
Wabash Bldg-Chgo, IL
Northern Trust
About Northern Trust:
Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889.
Northern Trust is proud to provide innovative financial services and guidance to the world’s most successful individuals, families, and institutions by remaining true to our enduring principles of service, expertise, and integrity. With more than 130 years of financial experience and over 22,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.
We are seeking a highly skilled Active Directory Security Architect with deep expertise in architecting, designing secure, resilient, and compliant Active Directory (AD) and Azure AD environments. As part of the Strategic Security Architecture team, you will focus on the security architecture of hybrid-joined AD environments, multi-tenant Azure AD configurations, and identity governance frameworks. This role is critical to defining and implementing the security strategies that protect our identity infrastructure.
Responsibilities:
1.) Architect secure Active Directory and Azure AD solutions, focusing on hybrid-joined environments where on-premises Active Directory is integrated with cloud services, ensuring security best practices are adhered to.
2.) Design and manage a multi-tenant Azure AD architecture, ensuring that identity and access management (IAM) solutions are secure, scalable, and aligned with organizational policies and regulatory compliance requirements.
3.) Lead the architectural design of identity and access management (IAM) frameworks, focusing on security best practices, including Multi-Factor Authentication (MFA), Single Sign-On (SSO), and conditional access policies.
4.) Define the security architecture for privileged access management (PAM), incorporating Privileged Identity Management (PIM), Just-in-Time (JIT) access, and other security controls to mitigate risks associated with elevated permissions.
5.) Collaborate with cross-functional teams (including IT, security operations, and DevOps) to ensure that the AD and Azure AD environments align with the broader security architecture, supporting zero trust, identity governance, and automation goals.
6.) Develop the strategic roadmap for AD and Azure AD security enhancements, ensuring continuous improvement, scalability, and alignment with evolving cybersecurity threats and organizational growth.
7.) Guide and advise on the security configuration of Group Policy Objects (GPOs), RBAC, and security groups within both on-premises AD and Azure AD environments, without direct responsibility for day-to-day management.
8.) Architect and manage hybrid identity environments that combine on-premises AD with Azure AD, ensuring that authentication, authorization, and identity management are securely handled across both platforms.
9.) Conduct security assessments and threat modeling to identify potential risks within the Active Directory infrastructure and hybrid cloud environments, recommending and driving the implementation of mitigation strategies.
10.) Provide security architecture oversight during the onboarding of new applications and services that leverage AD and Azure AD for authentication and authorization, ensuring compliance with security standards.
11.) Advise on the integration and use of security monitoring tools like Microsoft Defender for Identity and Microsoft Sentinel, ensuring AD and Azure AD-related security events are effectively captured and responded to as part of the broader incident response strategy.
12.) Collaborate on cloud security initiatives, ensuring the secure integration of AD with Azure services and providing guidance on identity governance for multi-tenant Azure AD environments.
13.) Develop architectural standards and documentation that guide the secure deployment and management of both on-premises and cloud-based identity environments.
14.) Stay informed on emerging security threats, trends, and regulatory changes affecting Active Directory, Azure AD, and hybrid identity services, advising leadership on strategic responses to these challenges.
Qualifications:
1.) Extensive experience in Active Directory security architecture, including hybrid identity environments with Azure AD and multi-tenant Azure AD architecture.
2.) Strong knowledge of authentication protocols (e.g., Kerberos, LDAP, OAuth, OpenID Connect, SAML) and expertise in hybrid Active Directory environments that integrate on-premises AD with cloud-based Azure AD.
3.) Experience in designing privileged access management (PAM) frameworks and architecting identity governance solutions, including PIM and JIT access.
4.) Proven ability to develop and document security architecture standards for both AD and Azure AD environments, ensuring consistency and alignment with cybersecurity policies.
5.) Expertise in security risk assessment, threat modeling, and designing mitigation strategies for hybrid identity and cloud environments.
6.) Familiarity with security monitoring tools (e.g., Microsoft Defender for Identity, Microsoft Sentinel) and their role in detecting security incidents within AD and Azure AD environments.
7.) Proficiency in PowerShell scripting is required for automating architectural tasks, creating templates, and supporting automation initiatives.
8.) Microsoft Certified: Identity and Access Administrator Associate or similar certifications are a plus.
9.) Strong communication and leadership skills to work with cross-functional teams, stakeholders, and executive leadership, translating complex security architecture concepts into actionable strategies.
10.) Ability to think strategically and design security architectures that support long-term enterprise goals while addressing immediate cybersecurity challenges.
Working with Us:
As a Northern Trust partner, greater achievements await. You will be part of a flexible and collaborative work culture in an organization where financial strength and stability is an asset that emboldens us to explore new ideas.
Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to assisting the communities we serve! Join a workplace with a greater purpose.
We’d love to learn more about how your interests and experience could be a fit with one of the world’s most admired and sustainable companies! Build your career with us and apply today. #MadeForGreater
Reasonable accommodation
Northern Trust is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at MyHRHelp@ntrs.com.
We hope you’re excited about the role and the opportunity to work with us. We value an inclusive workplace and understand flexibility means different things to different people.
Apply today and talk to us about your flexible working requirements and together we can achieve greater.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Active Directory Automation Azure Cloud Compliance DevOps Governance IAM Incident response Kerberos LDAP Monitoring OpenID PowerShell Risk assessment SAML Scripting Security assessment Sentinel SSO Strategy Zero Trust
Perks/benefits: Flex hours Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.