We are seeking a seasoned and strategic Cyber Security Principal to serve as the enterprise technical authority for our Enterprise Directory and Certificate Services ecosystem. In this role, you will lead the strategic architecture, security hardening, governance, and operational resilience of our mission-critical identity tier—focusing exclusively on Active Directory Domain Services (AD DS), Oracle Unified Directory (OUD) LDAP, and Microsoft Entra ID (Azure AD), along with enterprise Public Key Infrastructure (PKI) / Certificate Services.
Essential Functions
- Enterprise Directory Architecture & Governance: Define, maintain, and enforce target-state architecture, security baselines, and configuration standards across on-premises and cloud directory environments (AD DS, OUD LDAP, and Microsoft Entra ID).
- Active Directory & Protocol Hardening: Lead security engineering for domain controllers, schema governance, trust relationships, Group Policy, and authentication protocol security.
- Enterprise OUD LDAP Engineering: Architect, tune, and secure enterprise Oracle Unified Directory deployments, including multi-master replication topologies, access control instructions (ACIs), schema extensions, and high-throughput LDAP integrations.
- Hybrid Identity & Entra ID Security: Design and govern Entra ID tenant configurations, Conditional Access policies, hybrid directory synchronization (Entra Connect), and Privileged Identity Management (PIM).
- Identity Resilience & Cyber Disaster Recovery: Architect, document, and routinely validate comprehensive forest recovery and disaster recovery runbooks for AD and OUD, ensuring rapid recovery against ransomware and catastrophic failure.
- Technical Leadership & Strategy: Provide SME guidance on identity security architecture across enterprise projects, mentor directory engineering staff, and establish security posture KPIs/KRIs for leadership.
Required Qualifications & Technical Competencies
Core Technical Mastery
- Active Directory Domain Services (AD DS):
- Expert-level knowledge of multi-forest/multi-domain topologies, trusts, Kerberos (constrained/unconstrained delegation, PKINIT), DNS, and replication mechanics.
- In-depth expertise in AD hardening/security techniques and attack path reduction.
- Oracle Unified Directory (OUD):
- Advanced design, administration, performance tuning, and replication architecture of OUD LDAP services.
- Deep understanding of LDAP RFCs, search filter indexing, backend database partitions, and directory proxy architectures.
- Microsoft Entra ID (Azure AD):
- Comprehensive expertise in Entra ID architecture, App Registrations, Service Principals, Entra Connect/Cloud Sync, Conditional Access, and hybrid tenant security.
Preferred / Bonus Qualifications
- Automation & Infrastructure-as-Code (Strongly Preferred):
- PowerShell: Advanced scripting and module development for Active Directory administration, reporting, remediation, and API interactions (Microsoft.Graph, ActiveDirectory module).
- Ansible: Proven experience developing and maintaining Ansible playbooks for automated provisioning, configuration management, security baseline enforcement, and deployment of directory infrastructure.
- Identity Governance & Administration (IGA): Familiarity with directory integrations into enterprise IGA platforms (e.g., SailPoint IdentityIQ / Identity Security Cloud).
- Identity Providers and Security: Familiarity with Identity Providers (e.g. Okta) and Identity Protection modules (e.g Crowdstrike IDP).
Leadership & Professional Competencies
- Proven ability to drive consensus and influence architectural standards across security, infrastructure, and application engineering teams.
- Strong communication skills with the ability to convey identity risks and cryptographic concepts clearly to executive stakeholders.
- Experience leading technical response and post-incident hardening during critical Tier-0 / identity security incidents.
Minimum Education
Bachelor's degree/Equivalent in computer science, information systems and/or equivalent formal training.
Minimum Experience
Five (5+) years of experience in IT information security.
Knowledge, Skills, and Abilities
Skills include IT security and infrastructure.
Strong technical and consulting skills, project management capability.
Experience with security and risk frameworks, standards and best practices.
Strong communication skill.
Compensation
US: $9,208.38/mo - $20,872.33/mo, CO: $9,208.38/mo - $20,002.65/mo, MD: $9,719.96/mo - $20,872.33/mo, NY: $9,719.96/mo - $20,872.33/mo, NYC: $11,766.26/mo - $20,872.33/mo, WA: $9,719.96/mo - $20,872.33/mo
Domicile
This is a hybrid position located in Pittsburgh, PA, Memphis, TN, or Plano TX. Candidates must live within 50 miles of the campus location. Employees will be required to work at the FedEx campus location several times per week.
Application Criteria: October 15th
To be considered, candidates must submit their application through the applicable FedEx career site or internal career portal.
This position is anticipated to remain posted for seven (7) calendar days, subject to applicable FedEx posting requirements and business needs.
Pay Transparency:
The compensation listed reflects the pay range or rate of pay reasonably expected for this posted position at the posted location or locations. If this opportunity includes multiple job levels, the pay information represents the ranges for each level in that job family. Actual pay is determined by several job-related factors permitted by law and relevant to the position, including, but not limited to, experience relative to the job, tenure, market level, pay at the location for this job, performance, schedule, and work assignment. In California, the compensation listed reflects the range or rate of pay reasonably expected for this posted position upon hire. In New Jersey, any compensable Security and Walk time will be paid to non-exempt/hourly employees at the state minimum wage.
For details on our comprehensive benefits, click here.
Federal Express Corporation is an Equal Opportunity Employer including, Vets/Disability.
Reasonable accommodations are available for qualified individuals with disabilities throughout the application process. Applicants who require reasonable accommodations in the application or hiring process should contact recruitmentsupport@fedex.com.
Applicants have rights under Federal Employment Laws:
E-Verify Program Participant: Federal Express Corporation participates in the Department of Homeland Security U.S. Citizenship and Immigration Services’ E-Verify program (For U.S. applicants and employees only). Please click below to learn more about the E-Verify program: