Active Directory (AD) Engineer

ComTec
Houston, TX, United States
8 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Job source

Tech stack

Active Directory Configuration Management Databases CompTIA Security+ Disaster Recovery Multi-Factor Authentication Local Security Policy Windows PowerShell Role-Based Access Control Azure Active Directory Single Sign-On Scripting Enterprise Software Applications
+2 more
Cloud Platform System Microsoft InTune

Job description

  • Manage and configure Active Directory forests, domains, and organizational units (OUs).
  • Modify and delegate permissions at the forest and root levels, ensuring secure access controls.
  • Design and implement permission structures aligned with security best practices and the principle of least privilege.
  • Perform complex permission migrations and modifications with minimal service disruption.
  • Automate permission changes and audits using PowerShell or other scripting tools.
  • Troubleshoot and resolve permission-related issues, including access denied errors.
  • Collaborate on security policies, audit configurations, and compliance standards related to AD.
  • Apply Group Policy best practices to influence permissions and security settings.
  • Integrate Active Directory into cloud environments for hybrid single sign-on (SSO) and multi-factor authentication (MFA).
  • Manage domain logins, group policies, and access controls for internal enterprise applications.
  • Utilize Microsoft Entra ID (Azure AD), Intune, and ServiceNow CMDB for governance, asset management, and compliance.
  • Maintain AD backup, recovery, and disaster recovery procedures.
  • Follow strict change management, security, testing, documentation, and operational procedures in a highly regulated environment.

Requirements

We are looking for an experienced Senior Active Directory Engineer to manage and secure our AD environment, with a focus on root-level permissions management. The ideal candidate will have a strong understanding of AD architecture, security best practices, and automation tools to ensure the integrity, security, and efficient operation of our directory services in a critical infrastructure environment., * 8+ years of hands-on experience in Active Directory management, including schema, replication, and trust relationships.

  • Expertise in managing permissions at the forest and root levels, with deep knowledge of ACLs, security descriptors, and inheritance.
  • Strong understanding of permissions, security best practices, and the principle of least privilege.
  • Experience integrating AD into cloud environments for hybrid SSO and MFA solutions.
  • Familiarity with Microsoft Entra ID (Azure AD), Intune, and ServiceNow CMDB for governance and compliance.
  • Knowledge of AD security, audit policies, and compliance standards.
  • Strong scripting skills, particularly with PowerShell, for AD queries, reporting, validation, automation, and auditing.
  • Experience with AD backup, recovery, and disaster recovery procedures.
  • Expertise in troubleshooting and problem-solving related to permissions issues.
  • Excellent written and verbal communication skills, including documentation, change requests, and cross-team coordination.
  • Nice-to-have certifications: such as CISSP, CISM, CompTIA Security+, CEH, or relevant Microsoft certifications.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Evolution from manual setups to automated monolith deployments

Axel Barbier · World Congress 2023

2:16 min

Addressing single sign-on challenges in enterprise environments

Alexander Schwartz Alexander Schwartz · World Congress 2025

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

3:18 min

Eliminating passwords using Azure managed identities

Markus Möller · World Congress 2021

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

Videos

See all

Related articles

See all