> Markdown version of [/jobs/ext/1459157-active-directory-remediation-architect](https://www.wearedevelopers.com/jobs/ext/1459157-active-directory-remediation-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Active Directory Remediation Architect - **Company:** Plexlane, LLC. - **Location:** Seattle, WA, United States (Remote available) - **Experience:** Expert - **Salary:** $104,000.0 - $135,200.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Domain Controllers, Business Software, Dynamic Host Configuration Protocol, Linux, Domain Name System (DNS), Virtual Private Networks (VPN), Windows Servers, Windows PowerShell, Role-Based Access Control, CIS Benchmarks - **Published:** July 27, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=42c2e3c573e7308c ## About the Role * 8+ years of hands-on Active Directory engineering, with deep, demonstrable experience remediating and rebuilding multi-forest, multi-domain environments. * Proven track record of Domain Controller rebuilds and migrations, including retiring legacy DCs and modernizing to current Windows Server. * Strong command of AD internals: schema, FSMO roles, replication (repadmin/dcdiag), sites and services, trusts, and integrated DNS/DHCP. * Expertise in RBAC and least-privilege design, tiered administration models, and privileged account cleanup. * Fluency in Group Policy design, hardening, and troubleshooting (CIS benchmarks a plus). * Strong PowerShell automation skills; experience with AD assessment tooling such as ADRecon, PingCastle, or equivalent. * Experience delivering to a compliance framework - NIST 800-171 / CMMC 2.0 and/or ISO/IEC 27001:2022. * Ability to work independently over VPN, document rigorously, and communicate risk clearly to technical and program stakeholders. * Must be a U.S. person (U.S. citizen or lawful permanent resident) - required for access to controlled systems. Nice to have * Experience with modern identity and privileged-access tooling (MFA, PAM, identity-protection platforms) integrated against Active Directory. * Familiarity with Linux/AD integration (SSSD, realm join) and hybrid identity. * Exposure to enterprise security monitoring and audit tooling. * Prior work in regulated / defense-adjacent or manufacturing environments. * Relevant certifications (e.g., Microsoft Identity & Access, security certifications)., * Are you a U.S. person (U.S. citizen or lawful permanent resident)? This role requires access to controlled systems and is restricted to U.S. persons. * How many years of hands-on experience do you have remediating and rebuilding multi-forest / multi-domain Active Directory environments, including greenfield Domain Controller rebuilds and retiring legacy/EOL DCs? Share an example. * Have you designed a least-privilege RBAC / tiered-admin model AND deployed hardening Group Policy at scale, using PowerShell and AD assessment tooling (e.g., ADRecon, PingCastle)? ## Description We are looking for a hands-on Active Directory expert who can assess, remediate, and where necessary redesign and rebuild Active Directory across a complex, multi-forest enterprise estate. This is a high-technical-risk, high-visibility role at the center of a broader identity and infrastructure security modernization effort - a healthy, correctly redesigned AD is the foundation everything else depends on. Domain Controllers in the environment span a wide range of Windows Server versions, including legacy, end-of-life DCs that will require greenfield rebuilds rather than in-place remediation. You will own the full arc - from diagnosis of schema, replication, and DNS health, through account cleanup and least-privilege RBAC design, to standing up a clean, defensible AD foundation. This is a delivery role for someone who is equally comfortable writing the automation and rolling up their sleeves for the manual rebuilds that automation can't safely touch. What you'll do * Assess and remediate multiple Active Directory forests across a segmented network estate; produce clear remediation-versus-rebuild recommendations per environment. * Diagnose and fix schema health, replication, and DNS alignment issues across forests. * Perform greenfield rebuilds of legacy Domain Controllers where in-place remediation is not safe, with a documented cutover plan and no unplanned outages to line-of-business applications. * Design and implement a least-privilege RBAC role model; conduct a full account audit and map ownership for every user, service, and privileged account. * Eliminate shared, unnamed, and orphaned accounts; document exceptions where accounts cannot be cleanly remediated. * Enforce password and authentication policy via Group Policy; deploy and validate hardening GPOs without breaking LOB applications. * Build and run automation and diagnostic tooling - AD health scripts, replication diagnostics, account audit tooling, DNS cleanup scripting - and handle manual remediation where automation cannot be applied. * Produce as-built and account-audit documentation: forests healthy, replication clean, no EOL DCs without a documented plan, and zero unnamed or shared accounts without a documented exception. ## Related Videos - [This Is Not Your Father's .NET](https://www.wearedevelopers.com/videos/967-this-is-not-your-father-s-net) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Introducing Digital Samba Embedded Video Conferencing API MCP Server](https://www.wearedevelopers.com/videos/1640-introducing-digital-samba-embedded-video-conferencing-api-mcp-server) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)