Blackstone Technology

Blackstone Technology

Workforce Identity and Directory Services, VP - Enterprise Technology

Miami · Vp

Sponsorship not specified$160k-$225kDetected 30 days ago
PowerShellAzureTerraformOAuthCybersecurityDetection EngineeringIncident ResponseComplianceStakeholder ManagementSalesDNSVoIPZero TrustCommunicationCollaborationProblem SolvingMentoringSharePoint

About the role

  • The Vice President Workforce Identity and Directory Services serves as the primary owner of all Active Directory related infrastructure and strategy.

Responsibilities

  • Lead and execute a long-term technology roadmap to modernize the Active Directory environment, including forest and domain consolidation, AD tiering model implementation, strategic reduction and decommissioning of on-premises domain controllers, and accelerating workload migration from on-premises AD to Microsoft Entra ID.
  • Drive the adoption and optimization of Microsoft Entra ID security features, including Conditional Access, Identity Protection, Identity Governance, Workload Identities, and Entra Permissions Management.
  • Design and enforce Group Policy architecture at scale, including GPO lifecycle management, security baselines, and policy inheritance strategies across complex OU structures.
  • Lead AD Forest and domain trust management, replication topology optimization, Sites and Services configuration, and schema extension governance.
  • Partner with Security, Compliance, and Risk teams to ensure identity infrastructure meets regulatory and audit requirements, including SOX, NIST, and industry-specific mandates.
  • Advising on marketing plans prepared by a sales team or developing and/or contributing information for marketing materials.

Requirements

  • 10+ years of progressive experience in IT infrastructure with a focus on Active Directory and identity management, including at least 5 years in an architect or senior engineering capacity.
  • Deep fluency in authentication and federation protocols, including SAML, OAuth 2.0, OpenID Connect, WS-Federation, Kerberos, LDAP, and NTLM, with a track record of migrating environments away from legacy protocols.
  • Experience implementing passwordless authentication strategies, including FIDO2, Windows Hello for Business, and certificate-based authentication via PKI.
  • Hands-on experience with Active Directory security assessment and hardening tools such as BloodHound, PingCastle, and Purple Knight for attack path analysis and security posture evaluation.
  • Knowledge of service account governance, including Group Managed Service Accounts (gMSA), and endpoint security tooling such as LAPS.
  • Proficiency with PowerShell, Terraform, DSC, and Microsoft Graph API for identity infrastructure automation, reporting, and configuration drift detection.
  • Working knowledge of NIST, SOX, or other regulatory compliance frameworks as they relate to identity management and PKI governance.
  • Fields marked with a red asterisk * must be completed to be considered for employment (although some can be answered "prefer not to say").
  • When you have finished click Submit at the bottom of this form.
  • Depending on the position, you may be required to obtain certain securities licenses if you are in a client facing role and/or if you are engaged in the following:

Nice to have

  • Enterprise security and zero trust mindset
  • Deep technical problem solving across complex, multi-forest AD environments
  • Stakeholder management and executive communication
  • Strong ownership, accountability, and bias toward action
  • Experience in financial services, private equity, or other highly regulated industries.
  • The duties and responsibilities described here are not exhaustive and additional assignments, duties, or responsibilities may be required of this position.
  • Assignments, duties, and responsibilities may be changed at any time, with or without notice, by Blackstone in its sole discretion.
  • $160,000 - $225,000

Compensation

  • $160,000 - $225,000
  • Actual base salary within that range will be determined by several components including but not limited to the individual's experience, skills, qualifications and job location.
  • For roles located outside of the US, please disregard the posted salary bands as these roles will follow a separate compensation process based on local market comparables.
  • Additional compensation and benefits offered in connection with the role consist of comprehensive health benefits, including but not limited to medical, dental, vision, and FSA benefits; paid time off; life insurance; 401(k) plan; and discretionary bonuses.
  • Certain employees may also be eligible for equity and other incentive compensation at Blackstone's sole discretion.
  • This policy applies to all terms and conditions of employment, including but not limited to hiring, placement, promotion, termination, transfer, leave of absence, compensation, and training.

Benefits

  • Manage hybrid Active Directory environments, including Azure AD Connect / Cloud Sync configuration, seamless SSO, pass-through authentication, and directory synchronization health monitoring.

Equal opportunity

  • If you need a reasonable accommodation to complete your application, please contact Human Resources at 212-583-5000 (US), +44 (0)20 7451 4000 (EMEA) or +852 3656 8600 (APAC).

Visa & Work Authorization

  • nd applicants for employment without regard to race, color, creed, religion, sex, pregnancy, national origin, ancestry, citizenship status, age, marital or partnership status, sexual orientation, gender identity or expre

This listing is sourced directly from Blackstone Technology's careers page and normalized into a canonical job model.