Microsoft Security Active Directory Senior Consultant

Deloitte

Charlotte, USonsite$105k-$208k/yrPosted Jul 23, 2026
Posting intelligenceActively listed

About the role

Our Deloitte Cyber team helps organizations address evolving cybersecurity challenges across identity, access, and platform security. Join our team to deliver solutions that help clients strengthen resilience, modernize identity environments, and manage cyber risk with confidence.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a Senior Engineering Management Specialist on the Deloitte Cyber team, you will be responsible for:

Leading Active Directory and identity infrastructure engagements across assessment, design, migration, implementation, stabilization, and post-implementation phases.

Performing and overseeing Active Directory assessments covering domain and forest architecture, domain controllers, Sites and Services, Domain Name System (DNS), Dynamic Host Configuration Protocol (DHCP), replication, trusts, Group Policy, privileged groups, service accounts, authentication protocols, and administrative processes.

Designing and implementing Active Directory security and hardening improvements, including administrative tiering, role-based access controls, service account management, Group Policy controls, and identity threat detection and recovery capabilities.

Architecting and supporting enterprise Active Directory environments, including hybrid identity integrations with Microsoft Entra ID, federation, synchronization services, and application dependencies.

Leading or supporting domain and forest migrations, separations, and consolidations, including discovery, dependency analysis, cutover planning, validation, rollback, and post-migration stabilization.

A successful candidate would possess these skills:

Ability to work independently and collaborate as part of a team

Effective written and verbal communication skills

Meticulous attention to detail and quality of work product

Ability to build and sustain professional relationships

Ability to lead projects or workstreams

Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment

Strong interpersonal skills and professional demeanor

Ability to meet deadlines

Ability to provide clear guidance to others

The team

Deloitte Cyber helps clients build trust in digital environments by strengthening identity, access, and security capabilities across critical platforms. The team supports organizations in protecting users, securing access to data, and improving confidence in digital interactions.

Qualifications

Required:

Bachelor's degree in Computer Science, Cybersecurity, Information Security, Engineering, Information Technology, or another technical field.

4+ years of experience in technical consulting, enterprise infrastructure, identity security, or Active Directory engineering.

4+ years of hands-on experience designing, securing, assessing, migrating, or operating Microsoft Active Directory environments.

Experience with enterprise Active Directory services, including domain and forest architecture, domain controllers and replication, DNS, DHCP, Sites and Services, Group Policy, trusts, service accounts, Lightweight Directory Access Protocol (LDAP), and domain or forest recovery.

Experience leading or supporting Active Directory domain or forest migrations, separations, or consolidations.

Experience with migration tooling such as Quest On Demand Migration (ODM) or Semperis migration capabilities.

Experience with identity threat detection, identity resilience, cyber recovery, or recovery validation tooling such as Semperis, Rubrik, or Microsoft Defender for Identity.

Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve.

Limited immigration sponsorship may be available.

Preferred:

Advanced degree in Cybersecurity, Information Technology, Engineering, or another technical field.

Experience with Active Directory security assessments, attack-path analysis, domain hardening, and privileged access management.

Experience with enterprise identity security architectures, including Enhanced Security Administrative Environment (ESAE), tiered administration, administrative forests, or privileged access workstations.

Experience supporting mergers, acquisitions, divestitures, carve-outs, spin-offs, or enterprise reorganizations involving Active Directory environments.

Experience with Microsoft Entra ID, federation, synchronization, multifactor authentication (MFA), single sign-on (SSO), or hybrid identity architectures.

Certifications such as Certified Information Systems Security Professional (CISSP), Certificate of Cloud Security Knowledge (CCSK), Microsoft SC-300, or Cisco Certified Network Associate (CCNA).

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Compensation

This Security Engineer role pays $105k-$208k/yr. Within typical range for security engineer roles in United States.

Questions about this role

Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

Compensation for Security Engineer roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for United States medians across recent openings.

Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, Personio, Teamtailor and other major ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.