Active Directory Architect - Windows AD / IAM / Cloud Security

RealTek Consulting
Irvine, United States
8 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory Domain Controllers Amazon Web Services User Authentication Microsoft Azure Cloud Computing Cloud Computing Security Cloud Engineering System Configuration Domain Name System (DNS) Event Logging
+22 more
Identity and Access Management Network Security Lightweight Directory Access Protocols (LDAP) Windows Servers Network Connections Public Key Infrastructure Information Technology Security Auditing Service-Oriented Architecture Service Pack Security Information and Event Management TCP/IP Virtual Machines Software Vulnerability Management Private Cloud Environment Data Logging Transport Layer Security Google Cloud Cloud Platform System HybridCloud Firewalls (Computer Science) Cloud Migration Devsecops

Job description

Active Directory Architecture & Administration

  • Design, maintain, and support enterprise Microsoft Active Directory environments.
  • Architect secure and scalable Active Directory solutions aligned with enterprise security standards.
  • Manage Domain Controllers and Active Directory infrastructure.
  • Perform Domain Controller and AD schema upgrades/migrations, including upgrades from Windows Server 2019/2022 to Windows Server 2025.
  • Troubleshoot Active Directory replication and authentication issues.
  • Manage FSMO (Flexible Single Master Operations) roles.
  • Perform AD health checks and proactively identify infrastructure issues.
  • Support enterprise AD modernization and security initiatives.

IAM & Security

  • Strong experience with Identity and Access Management (IAM).
  • Apply security principles related to:

  • Confidentiality
  • Integrity
  • Authorization
  • Accountability

Implement and maintain secure identity and access controls.

Support authentication, authorization, and directory security.

Identify and remediate Active Directory security vulnerabilities.

Develop security standards and controls for enterprise identity infrastructure.

Windows Server Security & Vulnerability Management

  • Perform Windows Server vulnerability remediation.
  • Manage security patching and compliance activities.
  • Implement secure configuration standards across Windows Server environments.
  • Identify vulnerabilities and coordinate remediation activities.
  • Ensure systems meet enterprise security and compliance requirements.

DNS Administration

Strong hands-on experience managing Microsoft DNS, including:

  • A records
  • AAAA records
  • CNAME records
  • MX records
  • TXT records
  • SRV records
  • NS records
  • SOA records
  • PTR records
  • Reverse lookup zones
  • Create and manage reverse DNS zones.
  • Troubleshoot DNS resolution and Active Directory-integrated DNS issues.
  • Manage DNS dependencies associated with Active Directory services.

Group Policy

  • Design, configure, and manage Group Policy Objects (GPOs).
  • Develop and implement enterprise security policies through GPO.
  • Troubleshoot GPO application and inheritance issues.
  • Manage policies related to authentication, security, system configuration, and compliance.

PKI / Certificates / LDAPS

  • Manage enterprise PKI and digital certificates.
  • Configure and troubleshoot SSL/TLS certificates.
  • Manage SSL cipher suites associated with Active Directory.
  • Configure and troubleshoot LDAPS.
  • Troubleshoot certificate trust, expiration, authentication, and connectivity issues.
  • Ensure certificate infrastructure follows enterprise security standards.

Windows Event Auditing & Centralized Logging

  • Configure Windows Event Auditing.
  • Monitor security and authentication events.
  • Configure forwarding of Windows audit events to centralized logging/SIEM platforms.
  • Troubleshoot security and authentication issues using Windows event logs.
  • Support security monitoring and compliance requirements.

Networking

Strong understanding of:

  • TCP/IP
  • TCP / UDP
  • DNS
  • Network connectivity
  • Firewall concepts
  • Active Directory network ports and protocols
  • Troubleshoot connectivity issues between Domain Controllers, clients, applications, and infrastructure services.
  • Understand network dependencies of Microsoft Active Directory services.
  • Troubleshoot authentication, LDAP/LDAPS, DNS, and directory connectivity issues.

Cloud Architecture & Security

AWS / Azure / Google Cloud Platform

  • Experience supporting Windows and Active Directory environments in cloud platforms.
  • Experience with AWS, Azure, and/or Google Cloud Platform.
  • Design secure cloud architectures aligned with enterprise security requirements.
  • Work with cloud-based virtual machines and Windows workloads.
  • Troubleshoot Windows VMs operating within cloud environments.
  • Understand cloud networking and security controls.
  • Apply IAM and access-control principles to cloud environments.

Cloud Security Architecture

  • Create security blueprints and roadmaps for cloud adoption.
  • Design secure, scalable, and compliant cloud architectures.
  • Establish security policies, standards, and guidelines for:

  • Public Cloud
  • Private Cloud
  • Hybrid Cloud

Assess cloud environments for vulnerabilities and security risks.

Implement technical security controls including:

  • Network security
  • IAM
  • Encryption
  • Access controls

Support compliance and risk-management initiatives.

DevSecOps & Collaboration

  • Collaborate with IT, infrastructure, security, cloud, and development teams.
  • Embed security practices into application and infrastructure development.
  • Support DevSecOps initiatives.
  • Provide technical guidance on identity, security, and cloud architecture.
  • Translate business and security requirements into technical solutions.

Requirements

  • Microsoft Active Directory
  • Domain Controllers
  • AD replication
  • AD schema
  • FSMO roles
  • Active Directory security
  • AD troubleshooting
  • AD migrations/upgrades
  • Windows Server 2019 / 2022 / 2025

DNS - Must Have

  • Microsoft DNS
  • A / CNAME / MX / TXT / SRV / NS / SOA records
  • PTR records
  • Reverse zones
  • AD-integrated DNS
  • DNS troubleshooting

Security / IAM - Must Have

  • IAM
  • Identity and access management
  • Authentication / Authorization
  • Windows Server security
  • Vulnerability remediation
  • Security patching
  • Compliance
  • Security auditing

Group Policy - Must Have

  • GPO creation and management
  • Security policies
  • GPO troubleshooting
  • Group Policy inheritance

PKI / Certificates - Must Have

  • PKI
  • Digital certificates
  • SSL/TLS
  • SSL cipher suites
  • LDAPS
  • Certificate troubleshooting

Networking - Must Have

  • TCP/IP
  • TCP / UDP
  • Active Directory ports
  • DNS networking
  • Basic network troubleshooting

Cloud - Required

  • AWS / Azure / Google Cloud Platform
  • Cloud networking
  • IAM
  • Virtual Machines
  • Windows workloads in cloud environments
  • Cloud security

Preferred Qualifications

  • Experience designing enterprise-scale AD architecture.
  • Experience with Active Directory modernization and migration projects.
  • Windows Server 2025 upgrade experience.
  • Experience with hybrid Active Directory environments.
  • Experience integrating on-premises AD with cloud identity platforms.
  • Experience with centralized logging/SIEM solutions.
  • Experience with cloud security architecture.
  • Experience with DevSecOps.
  • Experience working in highly regulated enterprise environments.
  • Strong documentation and architecture-design skills.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:33 min

Recapping vital capability shifts across security and enterprise infrastructure

Sergej Reznik Sergej Reznik · Europe 2026 Virtual

2:59 min

Designing HTTP and HTML for familiar document sharing

Tim Berners-Lee · World Congress 2023

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

2:48 min

Daily responsibilities and alignment practices for technical engineering leadership

Edoardo Dusi · LIVE

Videos

See all

Related articles

See all