Active Directory Remediation Architect

Plexlane, LLC.
Seattle, WA, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$104,000.0 - $135,200.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory Domain Controllers Business Software Dynamic Host Configuration Protocol Linux Domain Name System (DNS) Virtual Private Networks (VPN) Windows Servers Windows PowerShell Role-Based Access Control CIS Benchmarks

Job description

We are looking for a hands-on Active Directory expert who can assess, remediate, and where necessary redesign and rebuild Active Directory across a complex, multi-forest enterprise estate. This is a high-technical-risk, high-visibility role at the center of a broader identity and infrastructure security modernization effort - a healthy, correctly redesigned AD is the foundation everything else depends on.

Domain Controllers in the environment span a wide range of Windows Server versions, including legacy, end-of-life DCs that will require greenfield rebuilds rather than in-place remediation. You will own the full arc - from diagnosis of schema, replication, and DNS health, through account cleanup and least-privilege RBAC design, to standing up a clean, defensible AD foundation.

This is a delivery role for someone who is equally comfortable writing the automation and rolling up their sleeves for the manual rebuilds that automation can’t safely touch.

What you’ll do

  • Assess and remediate multiple Active Directory forests across a segmented network estate; produce clear remediation-versus-rebuild recommendations per environment.

  • Diagnose and fix schema health, replication, and DNS alignment issues across forests.

  • Perform greenfield rebuilds of legacy Domain Controllers where in-place remediation is not safe, with a documented cutover plan and no unplanned outages to line-of-business applications.

  • Design and implement a least-privilege RBAC role model; conduct a full account audit and map ownership for every user, service, and privileged account.

  • Eliminate shared, unnamed, and orphaned accounts; document exceptions where accounts cannot be cleanly remediated.

  • Enforce password and authentication policy via Group Policy; deploy and validate hardening GPOs without breaking LOB applications.

  • Build and run automation and diagnostic tooling - AD health scripts, replication diagnostics, account audit tooling, DNS cleanup scripting - and handle manual remediation where automation cannot be applied.

  • Produce as-built and account-audit documentation: forests healthy, replication clean, no EOL DCs without a documented plan, and zero unnamed or shared accounts without a documented exception.

Requirements

  • 8+ years of hands-on Active Directory engineering, with deep, demonstrable experience remediating and rebuilding multi-forest, multi-domain environments.

  • Proven track record of Domain Controller rebuilds and migrations, including retiring legacy DCs and modernizing to current Windows Server.

  • Strong command of AD internals: schema, FSMO roles, replication (repadmin/dcdiag), sites and services, trusts, and integrated DNS/DHCP.

  • Expertise in RBAC and least-privilege design, tiered administration models, and privileged account cleanup.

  • Fluency in Group Policy design, hardening, and troubleshooting (CIS benchmarks a plus).

  • Strong PowerShell automation skills; experience with AD assessment tooling such as ADRecon, PingCastle, or equivalent.

  • Experience delivering to a compliance framework - NIST 800-171 / CMMC 2.0 and/or ISO/IEC 27001:2022.

  • Ability to work independently over VPN, document rigorously, and communicate risk clearly to technical and program stakeholders.

  • Must be a U.S. person (U.S. citizen or lawful permanent resident) - required for access to controlled systems.

Nice to have

  • Experience with modern identity and privileged-access tooling (MFA, PAM, identity-protection platforms) integrated against Active Directory.

  • Familiarity with Linux/AD integration (SSSD, realm join) and hybrid identity.

  • Exposure to enterprise security monitoring and audit tooling.

  • Prior work in regulated / defense-adjacent or manufacturing environments.

  • Relevant certifications (e.g., Microsoft Identity & Access, security certifications)., * Are you a U.S. person (U.S. citizen or lawful permanent resident)? This role requires access to controlled systems and is restricted to U.S. persons.
  • How many years of hands-on experience do you have remediating and rebuilding multi-forest / multi-domain Active Directory environments, including greenfield Domain Controller rebuilds and retiring legacy/EOL DCs? Share an example.
  • Have you designed a least-privilege RBAC / tiered-admin model AND deployed hardening Group Policy at scale, using PowerShell and AD assessment tooling (e.g., ADRecon, PingCastle)?

Benefits & conditions

Pulled from the full job description Travel reimbursement, This is a project-based contract. Work is primarily remote and delivered via VPN, with occasional on-site travel as required (travel agreed and reimbursed separately). Hours will scale with the AD topology and the extent of greenfield rebuilds required.

If you are an AD specialist who is energized by untangling and rebuilding a real, messy, multi-forest estate the right way, we’d like to talk.

This role is restricted to U.S. persons (U.S. citizens or lawful permanent residents). Applicants must be authorized to work in the U.S. This role involves access to sensitive systems; background screening may apply.

Pay: $50.00 - $65.00 per hour

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:07 min

Building and running Windows containers locally on Windows servers

Don Schenck Don Schenck · World Congress 2024

1:45 min

Addressing active AI incident remediation and broad ecosystem support

Matthew Brady Matthew Brady · World Congress 2026 Europe

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

2:08 min

Managing complex structures and corporate guidelines

Alexandra Petri · World Congress 2023

Videos

See all

Related articles

See all