Senior Security Engineer - Active Directory
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
Position Summary
As an Active Directory Senior Security Engineer on our team, you will be responsible for securing, hardening, and continuously improving the security posture of a large enterprise, multi‑domain Active Directory environment in a hybrid on‑prem and Azure cloud configuration. This role is primarily focused on identity security engineering, with an emphasis on reducing attack paths, remediating vulnerabilities, and defending against modern identity‑based threats.
You will operate as a key contributor in identifying and eliminating security risks across Active Directory and Azure AD, working closely with Cybersecurity, Red Team, and vulnerability management teams. This role requires deep technical expertise in AD security, a proactive mindset toward threat mitigation, and the ability to translate security findings into scalable, sustainable engineering solutions that strengthen the overall identity landscape.
Responsibilities
Lead the security hardening and governance of Active Directory (AD) and Microsoft Entra ID (Azure AD) environments, reducing attack surfaces and enforcing secure identity configurations
Identify, assess, and remediate identity and access management vulnerabilities, including privilege escalation risks, excessive permissions, and lateral movement attack paths
Design and implement enterprise identity security controls, including privileged access management, tiered administration, secure delegation, Conditional Access, and authentication protections
Partner with Cybersecurity, Red Team, and Infrastructure teams to validate findings, drive remediation efforts, and strengthen overall security posture
Monitor and investigate security events, threats, and indicators of compromise using tools such as Microsoft Security, Splunk, CrowdStrike, BloodHound, and Qualys
Develop and maintain security standards, conduct security assessments, and support compliance and audit initiatives (SOX, PCI, HIPAA) through remediation of identity-related findings
Required Qualifications
5–7 years of experience supporting and securing enterprise Active Directory environments
5–7 years of hands‑on experience administering Active Directory in multi‑domain or complex environments, with a strong emphasis on security
4–6 years of experience administering Azure and Azure Active Directory, including identity security controls
5+ years of experience working with Windows Server and Windows operating systems
3–5 years of experience using PowerShell for administration, automation, and security remediation
4–6 years of experience with vulnerability management, security hardening, and remediation of enterprise systems
Preferred Qualifications
Strong hands-on experience with Active Directory security assessments, attack path analysis, and remediation using tools such as BloodHound, Microsoft AD Assessment, CrowdStrike, or similar platforms
Deep expertise in Active Directory security, including privileged access management, credential protection, delegation and permissions modeling, Group Policy hardening, and authentication/authorization controls
Experience partnering with Red Teams and penetration testing teams to identify, validate, and remediate identity-related security weaknesses
Strong understanding of identity-focused attack techniques such as pass-the-hash, Kerberoasting, and privilege escalation, with experience implementing effective mitigation strategies
Experience with SIEM and security monitoring tools (e.g., Splunk, Microsoft SCOM, Microsoft Sentinel) and supporting remediation efforts for SOX, PCI, and HIPAA audit findings
Education
Bachelor degree from accredited university or equivalent work experience (HS diploma + 4 years relevant experience)
Anticipated Weekly Hours
40Time Type
Full timePay Range
The typical pay range for this role is:
$101,970.00 - $203,940.00This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above.
Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
Great benefits for great people
We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.
Additional details about available benefits are provided during the application process and on Benefits Moments.
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.