ForgeApply · Job listing
Workforce Identity and Directory Services, VP - Enterprise Technology
Blackstone
Tailor your resume for this Blackstone job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Blackstone's site. Free trial, no card required.
About this role
Blackstone is the world’s largest alternative asset manager. We seek to create positive economic impact and long-term value for our investors, the companies we invest in, and the communities in which we work. We do this by using extraordinary people and flexible capital to help companies solve problems. Our $1.1 trillion in assets under management include investment vehicles focused on private equity, real estate, public debt and equity, infrastructure, life sciences, growth equity, opportunistic, non-investment grade credit, real assets and secondary funds, all on a global basis. Further information is available at www.blackstone.com . Follow @blackstone on LinkedIn , X , and Instagram .
Role Overview The Vice President Workforce Identity and Directory Services serves as the primary owner of all Active Directory related infrastructure and strategy. This role leads the design, governance, and modernization of the enterprise identity platform across on-premises, hybrid, and cloud environments. The VP is responsible for developing long-term technology roadmaps, driving security best practices, and partnering with Security, Infrastructure, and Application teams to deliver scalable, resilient identity services aligned with business objectives.
Key Responsibilities • Serve as the primary owner and point-of-contact for all Active Directory infrastructure, strategy, and operations across on-premises and cloud environments.
• Lead and execute a long-term technology roadmap to modernize the Active Directory environment, including forest and domain consolidation, AD tiering model implementation, strategic reduction and decommissioning of on-premises domain controllers, and accelerating workload migration from on-premises AD to Microsoft Entra ID.
• Architect and govern enterprise Active Directory Domain Services (AD DS), Active Directory Certificate Services (AD CS), DNS, and DHCP, PKI, ensuring high availability, disaster recovery readiness, and security at scale.
• Drive the adoption and optimization of Microsoft Entra ID security features, including Conditional Access, Identity Protection, Identity Governance, Workload Identities, and Entra Permissions Management.
• Govern Entra ID external collaboration and application identity, including cross-tenant access policies, B2B guest account lifecycle, app registration and enterprise application management, API permission and consent policy governance, and service principal security and credential rotation.
• Manage hybrid Active Directory environments, including Azure AD Connect / Cloud Sync configuration, seamless SSO, pass-through authentication, and directory synchronization health monitoring.
• Design and enforce Group Policy architecture at scale, including GPO lifecycle management, security baselines, and policy inheritance strategies across complex OU structures.
• Establish and enforce identity security best practices, policies, and standards across the organization in alignment with zero trust principles and AD tiering models (Enhanced Security Admin Environment).
• Oversee Kerberos, NTLM, LDAP, and certificate-based authentication protocols, driving migration away from legacy protocols toward modern authentication standards.
• Lead AD Forest and domain trust management, replication topology optimization, Sites and Services configuration, and schema extension governance.
• Partner with Security, Compliance, and Risk teams to ensure identity infrastructure meets regulatory and audit requirements, including SOX, NIST, and industry-specific mandates.
• Oversee incident response, disaster recovery, and root cause analysis for identity-related security events, AD replication failures, and service disruptions.
• Evaluate emerging identity technologies and industry trends including passwordless authentication, decentralized identity, and AI-driven threat detection to inform strategic planning and investment decisions.
Required Qualifications • 10+ years of progressive experience in IT infrastructure with a focus on Active Directory and identity management, including at least 5 years in an architect or senior engineering capacity.
• Deep knowledge of Microsoft 365 from an identity and access management perspective, including Exchange Online, SharePoint Online, and Teams integration with Entra ID, M365 group and license management, app consent frameworks, service principals, and Microsoft 365 Defender for identity related threat detection.
• Deep fluency in authentication and federation protocols, including SAML, OAuth 2.0, OpenID Connect, WS-Federation, Kerberos, LDAP, and NTLM, with a track record of migrating environments away from legacy protocols.
• Experience implementing passwordless authentication strategies, including FIDO2, Windows Hello for Business, and certificate-based authentication via PKI.
• Hands-on experience with Active Directory security assessment and hardening tools such as BloodHound, PingCastle, and Purple Knight for attack path analysis and security posture evaluation.
• Knowledge of service account governance, including Group Managed Service Accounts (gMSA), and endpoint security tooling such as LAPS.
• Proficiency with PowerShell, Terraform, DSC, and Microsoft Graph API for identity infrastructure automation, reporting, and configuration drift detection.
• Working knowledge of NIST, SOX, or other regulatory compliance frameworks as they relate to identity management and PKI governance.
• Microsoft certifications such as Microsoft Certified: Identity and Access Administrator Associate, Azure Solutions Architect Expert, or Cybersecurity Architect Expert.
• Proven track record of building, mentoring, and managing high-performing identity engineering teams.
• Excellent communication and stakeholder management skills, to include translating complex identity concepts for non-technical audiences and influence at all levels of the organization.
Preferred Qualifications • Identity architecture and str
Salary insight
The midpoint of this range ($193k) is about 57% above the median disclosed salary for Miami roles listed on ForgeApply ($123k across 116 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Blackstone role before you apply.
Tailor my resume for this jobSimilar jobs
- Head of Workplace Technology — Legora · New York City
- Workforce IAM Senior Technology Manager — M&T Bank · Buffalo, NY
- Associate Director, Workplace Technology and Business Engagement — Vertex · Boston, MA
- Sr. Enterprise Identity Architect — KLA · Milpitas, CA
- Senior Director - Digital Workplace — 3cloud · Remote
- Partner Development Director, Enterprise Technologies — Snowflake · US-NY-New York
- Manager, Enterprise Identity and Data Protection — QTS · Suwanee, GA | Ashburn, VA | Irving, TX
- Senior Sales Director, Commercial & Workforce Identity Solutions — Idme · Remote
More like this: More jobs at Blackstone · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)