Senior Security Engineer
Project/Client: Banking
Location: Baltic States (remote)
Start Date: ASAP
Duration: Until 2026-12-31 with possible extension
Seniority: Senior
Language: English
Role Overview:
We are looking for a Senior Security Engineer to join a banking sector Security Engineering team. The engagement is centered around an Active Directory Hygiene Initiative, focused on remediating security, configuration, and architectural issues within an enterprise Active Directory environment. The consultants will collaborate closely with Security Engineering and Infrastructure teams to analyze, design, improve, and secure the Active Directory environment, ensuring alignment with modern identity & access management, compliance, and operational standards. The role requires strong hands-on expertise in Active Directory architecture, security hardening, Microsoft Entra ID hybrid integration, and PKI services.
Key Responsibilities:
Analyze, design, and improve the enterprise Active Directory architecture, including Forest and Domain Management
Implement Active Directory Security Hardening practices including Tiering, ESAE/Red Forest, and PAM models
Manage and optimize Identity & Access Management processes and policies
Drive Microsoft Entra ID hybrid integration and Active Directory Federation Services (ADFS) configurations
Design, govern, and maintain Group Policy frameworks across the environment
Manage Active Directory Replication and DNS Architecture to ensure stability and performance
Oversee PKI / AD Certificate Services integration and lifecycle management
Administer and troubleshoot Kerberos and authentication flows
Develop and maintain PowerShell automation and scripting for operational efficiency
Plan and execute Active Directory Disaster Recovery, backup, and restore procedures
Lead or contribute to Active Directory Migration & Consolidation using ADMT
Ensure compliance with NIST and DORA aligned auditing and governance standards
Must-Have Requirements:
Proven expertise in Active Directory Architecture & Design in large-scale enterprise environments
Hands-on experience with Forest and Domain Management
Deep knowledge of Active Directory Security Hardening — Tiering, ESAE/Red Forest, PAM
Strong background in Identity & Access Management
Experience with Microsoft Entra ID hybrid integration
Proficiency with Active Directory Federation Services (ADFS)
Solid experience in Group Policy design and governance
Knowledge of Active Directory Replication and DNS Architecture
Hands-on experience with PKI / AD Certificate Services integration
Strong understanding of Kerberos and authentication flows
Proficiency in PowerShell automation and scripting
Experience with Active Directory Disaster Recovery and backup/restore procedures
Familiarity with Active Directory Migration & Consolidation using ADMT
Knowledge of NIST and DORA compliance and auditing frameworks
Solid networking fundamentals and strong troubleshooting and analytical skills
Fluent English (spoken and written)
Nice to Have:
Expertise in Microsoft Azure / Entra ID cloud-native capabilities
Hands-on experience with AWS
Background in the banking or financial services industry
📩 Ready to Join?
We look forward to receiving your application and welcoming you to our team!
- Locations
- Estonia, Latvia, Lithuania
- Remote status
- Fully Remote
About Bonapolia
For job seekers, BONAPOLIA offers a gateway to exciting career prospects and the chance to thrive in a fulfilling work environment. We believe that the right job can transform lives, and we are committed to making that happen for you.