Sr. System Engineer - Active Directory Infrastructure

Communications & Power Industries
United States
17 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Microsoft Windows Active Directory Artificial Intelligence Systems Engineering User Authentication Microsoft Azure Configuration Management Dynamic Host Configuration Protocol Disaster Recovery Domain Name System (DNS) Monitoring of Systems
+23 more
Kerberos (Protocol) Linux System Administration System Center Configuration Manager Windows Servers NetApp Applications NT LAN Manager OAuth OpenID Windows PowerShell Role-Based Access Control Azure Active Directory Security Assertion Markup Language (SAML) Software Vulnerability Management AI Infrastructure Cloud Platform System Microsoft InTune Containerization Information Technology Patch Management Enterprise Integration Virtual Agents Docker Vmware

Job description

The successful candidate will have deep experience with enterprise Active Directory and Windows environments and will lead efforts involving AD consolidation, directory and Group Policy cleanup and maintenance, security hardening, lifecycle management, and patching. The role also provides cross-functional backup for virtualization, compute, storage, backup, and other infrastructure platforms.

U.S. Citizenship is required. Candidates requiring employment authorization through an EAD, visa, or other non-citizen work authorization are not eligible for consideration.

Primary Responsibilities

  • Serve as the primary administrator and technical SME for Microsoft Active Directory Domain Services (AD DS), in a multi-forest, multi-domain, and multi-tenant environment.

  • Design, implement, maintain, troubleshoot, and optimize Group Policy Objects (GPOs), security/WMI filtering, and policy performance.

  • Lead Active Directory consolidation, cleanup, restructuring, and modernization, including remediation of stale accounts/objects, legacy configurations, unnecessary policies, excessive privileges, and other directory complexity.

  • Administer and support Microsoft Entra ID and hybrid identity, including directory synchronization and authentication/authorization across on-premises and cloud environments.

  • Troubleshoot complex AD, Group Policy, DNS, Kerberos, NTLM, certificates, authentication, authorization, and replication issues.

  • Own and improve Windows Server and endpoint patching, using MECM/Configuration Manager and Intune including patch planning, deployment, compliance reporting, troubleshooting failed updates, and remediation of vulnerable or unsupported systems.

  • Provide senior-level backup and troubleshooting support for VMware compute/virtualization, NetApp storage, Rubrik backup and recovery, and related infrastructure.

  • Work with security and infrastructure teams on AD security hardening, privileged access, least privilege, vulnerability remediation, disaster recovery, and business continuity., With a history spanning more than seven decades, Communications & Power Industries’ thousands of products have impacted people’s lives in numerous unseen ways every day. Our highly engineered products serve as the backbone of modern-day commercial and military communications systems, assist in diagnosing medical conditions, empower scientific discoveries and space exploration, and much more.

Requirements

  • U.S. Citizenship is required. Candidates requiring employment authorization through an EAD, visa, or other non-citizen work authorization are not eligible for consideration.

  • Advanced knowledge of AD with strong hands-on experience administering and troubleshooting multi-forest/domain/tenant environments

  • Experience with AD consolidation, migration, cleanup, restructuring, or modernization.

  • Advanced Windows Server administration and troubleshooting experience.

  • Strong experience with Windows patch management, vulnerability remediation, and systems lifecycle management leveraging MECM/Configuration Manager and/or Intune.

  • Strong PowerShell scripting and automation skills.

  • Hands-on experience with Microsoft Entra ID, hybrid identity, and directory synchronization.

  • Working knowledge of Kerberos, NTLM, SAML, OAuth/OIDC, AD CS, DNS, DHCP, and networking dependencies.

  • Ability to troubleshoot across infrastructure layers and work independently in a small, collaborative infrastructure team.

  • Strong documentation, communication, troubleshooting, and root-cause analysis skills.

  • Security and Compliance perspective, NIST 800-43, 171, CMMC, CUI, ITAR, ECI

Preferred Qualifications

  • Bachelor’s degree in Computer Science, Information Technology, or similar.

  • Experience with Active Directory security hardening, privileged access management, and least-privilege design.

  • Experience supporting VMware, NetApp, and/or Rubrik environments.

  • Experience with disaster recovery, business continuity, infrastructure monitoring, and enterprise lifecycle management.

  • Microsoft certifications related to Windows Server, Azure/Entra Identity, or Security.

  • Experience supporting regulated, defense, aerospace, or other security-sensitive environments.

  • Strong Linux administration experience and familiarity with Docker/containerized workloads.

  • Familiarity with Microsoft Azure Government / GCC High, including identity, security, networking, and compliance considerations.

  • Experience supporting AI infrastructure, agentic AI platforms, MCP (Model Context Protocol), AI gateways, or enterprise integration of AI workloads with identity and access controls., The ideal candidate is a hands-on infrastructure engineer who takes ownership, understands Active Directory at a deep technical level, and can independently diagnose and resolve difficult identity and Windows problems. You should enjoy cleaning up and improving environments, not simply maintaining them, and be comfortable balancing AD engineering, patching, security, automation, and broader infrastructure support in a small team.

Benefits & conditions

Whether you are a seasoned professional or just embarking on your career, CPI is an ideal place to expand your knowledge and expertise. We cultivate a healthy, dynamic, and team-oriented environment that empowers our employees to develop, create and deliver innovative, reliable technology solutions to power, connect, protect, and support a better tomorrow.

We offer our employees an attractive compensation package with competitive salaries and comprehensive benefits, including health and wellness programs, career development, generous retirement savings plan with company match and more!

About the company

CPI is headquartered in Plano, Texas and is a global manufacturer of electronic components and subsystems. We have manufacturing locations in the United States, Canada, Europe, and Asia. With a heritage of technological excellence, our team serves customers in the communications, defense, medical, industrial, and scientific markets., We value the unique and diverse skills, qualities, and backgrounds that each employee brings to CPI, and we respect each employee as an integral member of our growing team. CPI is committed to providing equal employment opportunities for all current and prospective employees, as well as to promoting a culture of inclusion and respect for everyone. We celebrate the innovation that diversity creates in the work environment, and we recognize that each employee brings their own unique capabilities, experiences, and perspectives to the organization. It is this variety that adds value to our teams, as well as to our stakeholders. We welcome and encourage applicants to reach their full potential with us.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

1:40 min

Managing containerized infrastructure with Podman Desktop

Cedric Clyburn Cedric Clyburn +1 · World Congress 2025

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

3:09 min

Balancing data science skillings alongside systems engineering rigor

Nico Schmidt · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

Videos

See all

Related articles

See all