> Markdown version of [/jobs/ext/1183774-lead-active-directory-infrastructure](https://www.wearedevelopers.com/jobs/ext/1183774-lead-active-directory-infrastructure). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead - Active Directory Infrastructure - **Company:** Sysco Corporation - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Windows, Active Directory, Domain Controllers, Amazon Web Services, User Authentication, Authentication Protocols, Microsoft Azure, Command-Line Interface, Microsoft Management Console, Dynamic Host Configuration Protocol, Desktop Computing, Linux, Domain Name System (DNS), Identity and Access Management, Kerberos (Protocol), Lightweight Directory Access Protocols (LDAP), Windows Servers, NT LAN Manager, OAuth, Public Key Infrastructure, Windows PowerShell, Azure Active Directory, Runbook, Security Assertion Markup Language (SAML), Server Administration, SSL Certificate Management, Google Cloud, Multi-Cloud, Information Technology, Laptops, CIS Benchmarks, Servicenow - **Published:** July 4, 2026 - **Apply:** https://wd5.myworkdaysite.com/recruiting/sysco/syscocareers/job/Sysco-LABS-----Sri-Lanka/Lead---Active-Directory-Infrastructure_R256428 ## About the Role * Bachelor's degree in Computer Science, IT, or related field (or equivalent experience). * Proven experience leading technical teams and managing day-to-day operations. * Demonstrated ability to manage priorities, allocate resources, and deliver projects within agreed timelines. * Experience with incident management, problem management, change management, and service delivery processes. * Strong analytical and troubleshooting skills with the ability to make sound decisions under pressure. * Excellent communication, stakeholder management, and interpersonal skills. * Solid foundational understanding of Active Directory architecture (Domains, Forests, OUs, Sites and Services, Domian Migrations). * Experience with Active Directory Users and Computers (ADUC), DNS, and Group Policy Management Console (GPMC). * Familiarity with navigating and managing GUI-less environments (Windows Server Core) using command-line tools and PowerShell. * Foundational understanding of Public Key Infrastructure (PKI) concepts, including Certificate Authorities (CAs), digital certificates, and encryption basics. * Understanding of core authentication protocols (Kerberos, LDAP, NTLM). * Intermediate experience using PowerShell (specifically the Active Directory module) to query directory objects, parse event logs, and execute administrative commands. * Strong logical troubleshooting skills with a focus on identity, permissions, and access rights. * Excellent communication skills for collaborating with global remote teams and guiding Field Support. * Willingness to work in rotational shifts/on-call. Preferred: * Familiarity with Microsoft Entra ID (Azure AD), AD Connect, and Hybrid Azure AD join scenarios. * Knowledge of enterprise identity integration with cloud platforms (AWS Directory Service, GCP Cloud Identity, SSO). * Relevant Microsoft certifications (e.g., SC-300: Identity and Access Administrator, AZ-800, or foundational MS-900/SC-900). * Familiarity with Privileged Access Management (PAM) or Just-in-Time (JIT) access concepts. * Experience with IT service management (ITSM) tools like ServiceNow. * ITIL Foundation certification. ## Description Join our newly established Active Directory Infrastructure Team as a Team Lead. You'll be part of a 5-member team dedicated to managing and supporting our enterprise identity and directory services across multiple global domains. You will play a crucial role in ensuring secure and seamless authentication for our global workforce. We are seeking a highly motivated and experienced Team Lead to join our Active Directory Infrastructure Team. The successful candidate will be responsible for leading and developing a team of Active Directory Support Engineers, providing coaching, mentorship, and technical guidance while ensuring the effective delivery of Active Directory management services across the enterprise. This role involves providing technical leadership, overseeing day-to-day operations, driving process improvements and automating workflows and ensuring compliance with security and operational standards The ideal candidate will combine strong technical expertise in Microsoft Active Directory environments with proven leadership capabilities, driving continuous improvement, operational efficiency, and a culture of accountability within the team. Note: This role provides 16 hours of daily support (8 hours on-desk, 5 days a week, and 8 hours on-call on a rotational roster). Our Identity Environment: * Hybrid Directory Services: Global On-Premises Active Directory forests integrated with Microsoft Entra ID (formerly Azure AD). * Authentication & Access: Kerberos, NTLM, LDAP/S, SAML, and Oauth integrations across Windows, Linux, and multi-cloud platforms (Azure, AWS, GCP). * Endpoint Integration: Windows and Linux endpoints (workstations, laptops, mobile) domain-joined or hybrid-joined globally. * Collaborative Support Model: Working closely as the Identity Subject Matter Experts (SME) alongside local IT and Field Support teams worldwide. Key Responsibilities: * Directory Administration: Manage Active Directory objects (Users, Computers, Groups, Service Accounts) and Organizational Units (OUs) following best practices. * Authentication Support: Troubleshoot complex authentication and domain-join issues for endpoints (Windows/Linux) and applications utilizing Kerberos, NTLM, and LDAP. * Server Core Administration: Support and troubleshoot Domain Controllers deployed on Windows Server Core, utilizing Remote Server Administration Tools (RSAT), Windows Admin Center, and command-line interfaces for daily maintenance. * Group Policy Management: Assist in the creation, deployment, and troubleshooting of Group Policy Objects (GPOs) to enforce security baselines and configure endpoints. * AD Health & Monitoring: Monitor AD replication, Domain Controller health, and Directory Services event logs (using tools like dcdiag and repadmin). * Directory Automation & Reporting: Utilize PowerShell scripting to automate routine identity tasks, execute bulk object updates (users, groups, computers), and generate directory audit reports. * Hybrid Identity Operations: Support Entra ID (Azure AD) sync operations (AAD Connect) and troubleshoot hybrid-join device scenarios. * Cross-Platform Auth: Assist with Linux domain integration (SSSD, Realmd) and authentication troubleshooting for cross-platform endpoints. * PKI & Certificate Management: Support Active Directory Certificate Services (AD CS) operations, including processing Certificate Signing Requests (CSRs), managing certificate templates, and troubleshooting client auto-enrollment issues for endpoints and servers. * DNS & DHCP: Manage and troubleshoot DNS records and zones, as they relate to domain health and client connectivity. * Migrations: Lead multi-domain and multi-forest Active Directory migration planning, execution, troubleshooting, identity integration, trust management, and post-migration support. * Documentation: Maintain runbooks, standard operating procedures (SOPs), and knowledge base articles for AD support and administration. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Agentic employees in world's most downloaded FinTech app](https://www.wearedevelopers.com/videos/100123-agentic-employees-in-world-s-most-downloaded-fintech-app) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [My journey into DevOps world - How it all started!](https://www.wearedevelopers.com/videos/545-my-journey-into-devops-world-how-it-all-started) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)