> Markdown version of [/jobs/ext/1917325-active-directory-engineer](https://www.wearedevelopers.com/jobs/ext/1917325-active-directory-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Active Directory Engineer - **Company:** Marotta Controls - **Location:** Parsippany-Troy Hills, NJ, United States - **Experience:** Expert - **Salary:** $108,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Microsoft Azure, Software as a Service, Desktop Computing, Identity and Access Management, Kerberos (Protocol), NT LAN Manager, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Single Sign-On, Systems Integration, User Provisioning Software, Enterprise Software Applications, Information Technology - **Published:** August 4, 2026 - **Apply:** https://www.juju.com/job/00000000glkftz ## About the Role Bachelor's degree in computer science or equivalent Must be a US Citizen Technical solution design and planning experience Strong knowledge of creating, managing and troubleshooting Group Policy Object Basic understanding of the project management life cycle Five to seven years' hands-on experience administering and hardening Microsoft Active Directory in a multi-forest environment Experience with Microsoft Entra (Azure AD) and hybrid identity architectures Experience implementing and supporting Single Sign-On (SSO) technologies (SAML, Kerberos, NTLM) Experience implementing and administering MFA solutions, including Duo MFA Experience with identity lifecycle management and access provisioning/deprovisioning Leverage ADManager Plus tools to automate user provisioning, reporting, delegation, and bulk account management tasks. Experience implementing conditional access and identity security best practices Strong PowerShell scripting skills for automation and administration Strong attention to detail Good problem-solving skills with the ability to think creatively Excellent written and verbal skills, including ability to clearly articulate technical issues and activities to technical and non-technical staff Strong interpersonal skills and the ability to adapt in a complex and changing environment Consistently meet expected production, accuracy and quality standards as set by management Must be team oriented with the ability to work independently Additional Desired Qualifications Experience administering Microsoft 365 (user, license, and service administration) Experience with Privileged Access Management (PAM/PIM) solutions Familiarity with Zero Trust security principles and architecture Experience integrating SaaS and enterprise applications with Microsoft Entra ID Familiarity with NIST 800-171 and CMMC requirements as they relate to identity and access management Experience supporting audits or compliance assessments (e.g., CMMC, NIST, ISO, SOC) Experience with directory synchronization tools (e.g., Entra Connect / Azure AD Connect) Relevant certifications (e.g., Microsoft Identity, Azure Security Engineer, CISSP, CMMC-related certifications) ## Description The Active Directory Engineer is responsible for designing, implementing, and supporting enterprise-level Active Directory Infrastructure, including forests, domain and organization units. This role is also responsible for Managing and supporting Group Policy Objects to enforce security, compliance, and configuration standards and implementing and enforcing security best practices such as least privilege, privileged access management (PAM), and auditing. The ideal candidate will have deep technical expertise, strong troubleshooting skills, and a security-first mindset., Design, implement, and maintain Active Directory (AD) services in a multi-forest, multi-domain environment Administer and optimize Microsoft Entra (Azure AD), including hybrid identity integrations Implement and support Single Sign-On (SSO) solutions for cloud and on-premises applications Manage identity lifecycle processes (joiner, mover, leaver) using tools such as ADManager Configure and maintain authentication methods including MFA, conditional access, and federation Ensure secure access controls through role-based access control (RBAC) and least privilege principles Support identity architectures and configurations aligned with NIST 800-171 and CMMC security controls Monitor and troubleshoot identity-related issues across on-prem and cloud platforms Collaborate with security, infrastructure, and application teams to integrate identity services Assist with audits, compliance assessments, and evidence collection related to identity and access controls Develop and maintain technical documentation, standards, and operational procedures Participate in identity modernization initiatives and continuous improvement efforts Work Environment: This job interacts both in a professional office environment and a manufacturing/machine shop environment. This role uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines, as well as environments inclusive of the appropriate eye, hearing and foot protection (as required). Night and weekend work could be required, as job duties demand. No travel is expected for this position Physical Requirements: While performing the duties of this job, the employee is regularly required to see, talk, and hear The employee is frequently required to reach and lift with hands and arms, and to use hands to finger, handle or feel The employee is regularly required to sit, stand, walk, bend, turn, etc., and move about the facility The employee may be required to lift, push, pull and/or move items weighing up to 25 pounds ## Related Videos - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) - [AI for Enterprise Developers - Dr. Damir Dobric](https://www.wearedevelopers.com/videos/1831-ai-for-enterprise-developers-dr-damir-dobric) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [SSO with Ethereum and Next JS](https://www.wearedevelopers.com/videos/288-sso-with-ethereum-and-next-js) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [How to land a developer job in Amsterdam](https://www.wearedevelopers.com/magazine/36-how-to-land-a-developer-job-in-amsterdam) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)