Windows Active Directory Engineer

SRE TECH SOLUTIONS LLC
United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$114,400.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Microsoft Windows Active Directory Domain Controllers Microsoft Azure Bash Shell Cyber Security Dynamic Host Configuration Protocol Domain Name System (DNS) Multi-Factor Authentication Identity and Access Management Intrusion Detection and Prevention
+21 more
Virtual Private Networks (VPN) Kerberos (Protocol) Lightweight Directory Access Protocols (LDAP) Unix Shell Windows Servers NT LAN Manager OAuth Windows PowerShell Systems Development Life Cycle Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Service-Oriented Architecture Security Information and Event Management Software Engineering Scripting Load Balancing Computer Network Operations HybridCloud Firewalls (Computer Science) Information Technology

Job description

We are seeking a dynamic and highly skilled Windows Active Directory Engineer to join our innovative IT team. The Windows Active Directory Engineer is responsible for stabilizing, securing, and modernizing the enterprise Active Directory environment with a strong focus on directory cleanup, identity hygiene, replication health, and security hardening. This role ensures AD remains healthy, compliant, resilient, and aligned with Zero Trust identity principles across on-prem and hybrid cloud environments., * Design, deploy, and manage Windows Active Directory environments to support organizational needs, including domain controllers, Group Policy Objects (GPOs), and replication topology.

  • Collaborate with cross-functional teams to integrate AD with other IT infrastructure components such as DNS, DHCP, VPNs, firewalls, and load balancers to ensure secure and efficient network operations.
  • Implement security best practices for AD environments, including identity management, access controls, multi-factor authentication, and information security protocols.
  • Support and optimize Azure AD Connect sync, attribute flows, and identity lifecycle.
  • Remediate sync errors, duplicate identities, and hybrid identity conflicts.
  • Monitor and maintain AD replication topology, site links, and inter-site connectivity.
  • Perform comprehensive AD cleanup including stale objects, unused OUs, orphaned SIDs, legacy GPOs, and deprecated configurations.
  • Perform system administration tasks such as user account provisioning/de-provisioning, password resets, and permissions management while adhering to the SDLC (Software Development Life Cycle) standards.
  • Monitor AD health using various tools; troubleshoot issues related to replication failures or authentication errors promptly.
  • Support solution architecture initiatives by designing scalable and resilient AD solutions aligned with service-oriented architecture principles.
  • Automate routine tasks using scripting languages like PowerShell or Bash (Unix shell), enhancing operational efficiency across systems.

Requirements

Do you have experience in Windows?, * Maintain comprehensive documentation of system configurations, updates, and incident reports to ensure compliance and audit readiness.Skills

  • 5-10+ years of hands-on experience with Active Directory, DNS, DHCP, GPO, and Windows Server.
  • Deep expertise in AD cleanup, replication troubleshooting, and security hardening.
  • Strong PowerShell skills for automation and bulk remediation.
  • Experience with Azure AD / Entra ID, hybrid identity, and AAD Connect.
  • Familiarity with SIEM, identity threat detection, and AD attack paths.
  • Understanding of Kerberos, NTLM, LDAP, SAML, OAuth, and modern auth.

Pay: $55.00 per hour

Application Question(s):

  • Do you have Microsoft Identify & Access Administrator Certification?
  • Do you have any Azure Certification?
  • Do you have 7+ years experience with Active Directory, DNS, DHCP, GPO and Windows Server?
  • Are you a US Citizen or Green Card Holder?

Benefits & conditions

$55 an hour - Contract

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · WWC 2022

3:24 min

Evaluating remote software roles and compensation structures

Nacho Iacovino · WWC 2021

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 · LIVE

Videos

See all

Related articles

See all