girl looking into her desktop
Back to search results

Infrastructure Engineer Lead - GBS IND

Hyderabad, , India;

Job Description:

About Us

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection.  Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.

One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We’re devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.

 Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.

Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!

Global Business Services

Global Business Services delivers Technology and Operations capabilities to Lines of Business and Staff Support Functions of Bank of America through a centrally managed, globally integrated delivery model and globally resilient operations.

Global Business Services is recognized for flawless execution, sound risk management, operational resiliency, operational excellence and innovation.

In India, we are present in five locations and operate as BA Continuum India Private Limited (BACI), a non-banking subsidiary of Bank of America Corporation and the operating company for India operations of Global Business Services.

Process Overview

Technology Infrastructure part of the Global Technology & Operations organization consists of more than 6,600 employees worldwide. With a presence in more than 35 countries, TI designs, builds, and operates end-to-end technology infrastructure solutions and manages critical systems and platforms across the bank. TI delivers industry-leading infrastructure products and services to the company’s employees, customers, and clients around the world.

Job Description

The Active Directory Security & GPO Engineering team is seeking an AD Security Engineer responsible for analysis, design, implementation coordination and 4th level escalation support of complex, enterprise level Active Directory solutions, specifically pertaining to security. The individual will work within the engineering organization, interacting with peer teams and partner groups, scaling and deploying improvement, consolidation and migration efforts within the enterprise. The candidate must be able to operate and function well in a multi-cultural, geographically dispersed virtual team environment.


  • Analysis, design, capacity planning and implementation of Active Directory Security
  • Translate business needs into workable technology solutions that meet the requirements of internal customers and peer Active Directory Engineering and Operations teams
  • Responsible for developing standards, target states, roadmaps, effectively socializing and obtaining consensus across architecture, engineering and operations teams
  • Independently manage and perform engineering role for large scale Active Directory efforts and initiatives
  • Perform various functions and duties in support of audit and compliance deliverables – verification/remittance of directory security evidence
  • Develop detailed architecture, standards, design and implementation documentation
  • Analyze current Active Directory environment to identify both technical and operational challenges while making recommendations and developing solutions for improvement
  • Participate in or lead complex or high severity troubleshooting and incident/problem resolutions with other infrastructure teams


  • Education: Any Graduation
  • Certifications If Any:
  • Experience Range: 9 to 12 years
  • Foundational skills
  • At least 5-10 years of dedicated Active Directory engineering and architecture experience that includes designing, implementing and maintaining complex enterprise level (50K+ objects) Active Directory solutions and security models
  • Overarching broad and deep technical experience with Active Directory Security
  • Extensive experience and advanced knowledge implementing Windows security concepts and policies, least-privilege design principles
  • Extensive knowledge of AD Security best-practices, latest security threats/trends and mitigation thereof
  • Experience with best practices for Active Directory disaster recovery, object management, security models and trust creation
  • Granular ACE permissions models meeting functional and technical requirements
  • Advanced PowerShell scripting experience and capabilities
  • Strong working knowledge of Windows Server operating systems platforms, DNS, networks, DMZs, firewalls, network security zones and IPv6
  • Deep, in-depth working knowledge of Kerberos (Microsoft and MIT/Heimdal) and NTLM authentication, MFA, SSO and federation technologies
  • Extensive and deep knowledge of Group Policy Objects (GPOs), engineering, implementing and 3rd party management solutions thereof
  • Strong knowledge of LDAP and ability to comfortably construct queries
  • Experience performing large scale upgrades, migrations, transitions and consolidation of Active Directory domains and forests
  • Experience and confidence to be the subject matter expert (SME) in an environment of this size and scale in order to coordinate technical efforts and resolve issues across multiple teams
  • Working knowledge of Certificate/CA/PKI infrastructure
  • Excellent communication skills, including proven experience effectively communicating technical challenges and solutions to peers, customers and senior management

  • Desired skills
  • Experience with Microsoft’s Enhanced Security Architecture Environment (ESAE) -  “Red/Bastion/Admin” forest design; including JIT (just in time) & JEA (just enough administration) concepts; Microsoft PAM (Privileged Access Manager)
  • Experience engineering password vaulting solutions (CyberArk, Lieberman, Thycotic, etc.)
  • Red Team assessment, exposure and interaction
  • Alternative scripting/programming skills (C#, VBscript, Javascript, Python, Perl)
  • Microsoft Azure integration
  • MS SQL/DB knowledge
  • Experience with RESTful APIs
  • Microsoft or 3rd party management and monitoring solutions (SCCM, SCOM, VCM, NetIQ GPDH/GPA)
  • Unix/Linux skills; Vintela VAS integration; RedHat IdM

Work Timings: 12:00 to 21:00

Job Location: Hyderabad, Chennai

Learn more about this role

Full time


Manages People: