Expert, Infrastructure Security Engineer (Identity & Attack Path Management)
8 hours ago
Barcelona
We are your Energy Technology Partner. We electrify, automate, and digitalize every industry, business, and home, driving efficiency and sustainability for all. At Schneider Electric, our values – IMPACT (Inclusion, Mastery, Purpose, Action, Curiosity, Teamwork) – are the foundation of everything we do. Becoming an Impact Maker means turning sustainability ambitions into actions at the intersection of automation, electrification, and digitization. Are you ready to lead the digital transformation to create a more sustainable world? If you are up to challenge your creativity and make an impact, we are excited to welcome you! Schneider Digital is the digital department of Schneider Electric, leading the digital transformation in the company by giving support globally to our internal teams and our clients. Schneider Digital consists of 6 Digital Hubs worldwide which are strategically located to ensure a 24/7 support across the company (France, China, India, USA, Mexico and Spain). Our Digital Hub in Barcelona is formed by +450 employees working in strategic projects and different roles such as Data, Cybersecurity, ERP, Cloud, Infrastructures, IT Project Management or Digital Marketing. Infrastructure Security Engineer (Identity & Attack Path Management) , you will play a critical role in ensuring the security, integrity, and resilience of our enterprise identity infrastructure across on‑premises and cloud environments. Leveraging your expertise in Active Directory, Azure AD / Entra ID, and hybrid identity integrations, you will analyze identity‑related risks, detect misconfigurations, privilege escalation vectors, and lateral movement paths, and contribute to remediation strategies that strengthen the organization’s identity posture. As a key member of the Infrastructure Security team, you will collaborate with cloud, infrastructure, and security engineering teams, actively sharing knowledge and fostering a collaborative environment. What will you do? Within the Identity & Attack Path Management scope, we: Operate identity security and attack‑path analysis solutions such as BloodHound, PingCastle, and equivalent platforms. Identify identity‑related risks, misconfigurations, excessive privileges, and lateral movement vectors across AD, Entra ID, and hybrid identity environments. Perform continuous discovery and monitoring of identity exposures, high‑risk objects, and structural directory weaknesses. Support incident, problem, and change processes related to identity and directory services. Analyze hybrid identity synchronization issues and collaborate with Cloud and Infrastructure teams to ensure secure, resilient, and compliant directory‑services operations. Contribute to identity security baselines, remediation planning, and hardening initiatives that reduce the enterprise attack surface. What qualifications will make you successful for this role? Candidates must possess a strong background in identity or infrastructure security with a minimum of 5 years of hands‑on experience working with directory services, specifically Active Directory and Azure AD / Entra ID. Experience performing identity‑focused risk assessments, privilege analysis, and directory misconfiguration detection using tools such as BloodHound, PingCastle, or equivalent platforms is required. Practical familiarity with AD Connect, hybrid authentication flows, and troubleshooting identity synchronization issues is highly valuable. Technical Expertise A deep understanding of Active Directory internals, including authentication flows, Kerberos, NTLM, delegation models, privileged groups, service accounts, and domain/forest trust relationships, is essential. Strong familiarity with Entra ID architecture, identity governance concepts, Conditional Access, and hybrid identity integration patterns is expected. Hands‑on experience detecting and analyzing attack paths, excessive privileges, ACL/ACE misconfigurations, and structural directory weaknesses is key. Knowledge of automation or scripting (e.g., PowerShell) to support identity analysis and remediation is a plus. Incident Response & Compliance Candidates should have demonstrated ability to support incidents involving identity compromise, unauthorized privilege escalation, or directory misconfigurations, providing accurate root‑cause analysis and remediation guidance. Experience reviewing identity and directory configurations for compliance with organizational security baselines, privileged access policies, and industry frameworks is an advantage. What will you get? With our flexible schedule, you'll have the freedom to adjust your work hours to accommodate your personal needs and responsibilities. We know how great it is to work from home. With our hybrid work plan, you can enjoy working from the comfort of your home. Need more time to relax and disconnect? With our Holy Pack, you can purchase additional vacation days to recharge when you need it most. Celebrate holidays your way! With Floating Holidays, you can exchange holidays for other days that better suit your plans and personal preferences. Need additional time to explore new experiences or focus on personal projects? With the Sabbatical Pack, you can request up to 2 months of extra leave (unpaid). We value the importance of family and want to support you in all aspects of your life. Our Global Family Leave Policy provides flexible paid conditions for when you need it most, whether you're about to be a parent, need time to overcome a loss, or to care for a loved one. We take care of you With access to the health and wellness platform Wellwo, you and up to 5 people of your choice can enjoy access to wellness content, nutrition counseling, fitness classes, and more! From dance classes to booking a hotel spa, we offer an agreement with Wellhub so you can access a network of thousands of gyms and sports centers to keep your body active in the way you like best. Your well‑being is our priority. You will have medical service at your workplace for close attention to any medical needs. We empower you With Career Hub, our AI‑driven professional development platform, you can connect with job opportunities, projects, and mentors at Schneider Electric globally. We offer you the opportunity to be a shareholder of Schneider Electric and share in our achievements with our stock ownership program. We celebrate everyone's talent and success with our recognition program, through which you can give and receive points for your achievements and redeem them for gift cards at your favorite stores. You will have life insurance for your protection. We offer you a Flexible Remuneration Plan in which you can choose from a variety of options, such as health insurance, meal vouchers, childcare vouchers, transportation vouchers, training, and more. With Club Schneider, you will enjoy special discounts at your favorite stores, restaurants, travel agencies, and other external services. Participate in company‑subsidized volunteer programs to contribute to our community and have a positive impact on your environment. Looking to make an IMPACT with your career? When you are thinking about joining a new team, culture matters. At Schneider Electric, our values and behaviors are the foundation for creating a great culture to support business success. We believe that our IMPACT values – Inclusion, Mastery, Purpose, Action, Curiosity, Teamwork – starts with us. IMPACT is also your invitation to join Schneider Electric where you can contribute to turning sustainability ambition into actions, no matter what role you play. It is a call to connect your career with the ambition of achieving a more resilient, efficient, and sustainable world. We are looking for IMPACT Makers; exceptional people who turn sustainability ambitions into actions at the intersection of automation, electrification, and digitization. We celebrate IMPACT Makers and believe everyone has the potential to be one. Become an IMPACT Maker with Schneider Electric – apply today! €36 billion global revenue +13% organic growth 150 000+ employees in 100+ countries #1 on the Global 100 World’s most sustainable corporations You must submit an online application to be considered for any position with us. This position will be posted until filled. Schneider Electric aspires to be the most inclusive and caring company in the world, by providing equitable opportunities to everyone, everywhere, and ensuring all employees feel uniquely valued and safe to contribute their best. We mirror the diversity of the communities in which we operate, and ‘inclusion’ is one of our core values. We believe our differences make us stronger as a company and as individuals and we are committed to championing inclusivity in everything we do. At Schneider Electric, we uphold the highest standards of ethics and compliance, and we believe that trust is a foundational value. Our Trust Charter is our Code of Conduct and demonstrates our commitment to ethics, safety, sustainability, quality and cybersecurity, underpinning every aspect of our business and our willingness to behave and respond respectfully and in good faith to all our stakeholders. You can find out more about our Trust Charter here. Schneider Electric is an Equal Opportunity Employer. It is our policy to provide equal employment and advancement opportunities in the areas of recruiting, hiring, training, transferring, and promoting all qualified individuals regardless of race, religion, color, gender, disability, national origin, ancestry, age, military status, sexual orientation, marital status or any other legally protected characteristic or conduct. #J-18808-Ljbffr