Active Directory SME (Identity Security)
Role details
Job location
Tech stack
Job description
Job Description: Cargill's Identity Security team is seeking a highly experienced Active Directory Subject Matter Expert (SME) to help modernize and optimize its enterprise Active Directory environment. This is a senior-level engineering role for someone who can independently design, implement, and improve large-scale AD environments while extending Active Directory into AWS and other cloud platforms. The ideal candidate is a hands-on Active Directory expert who thrives in complex enterprise environments, is comfortable working with minimal direction, and can balance engineering execution with long-term architecture and strategy. Required Experience * 8+ years of hands-on Active Directory engineering experience (6 years minimum) * Extensive enterprise Active Directory design, implementation, and administration * Experience building new AD environments and decommissioning legacy environments * Strong understanding of hybrid identity and cloud integrations *, Ability to lead technical
Requirements
initiatives with minimal supervision Core Technical Skills Active Directory, (Highest Priority) * Active Directory architecture and engineering * Domain and forest design, migrations, and consolidations * Domain controller deployment, promotions, and demotions * Organizational Units (OUs) * Group Policy (GPO) * Sites & Services * User and computer administration * Domain joins * AD health, performance, and troubleshooting Cloud Identity * AWS Managed Microsoft AD / Active Directory integration (highest priority after AD) * Microsoft Entra ID (Azure AD) * Google Cloud Platform (nice to have) Modern Infrastructure & Automation Experience with modern infrastructure engineering practices is highly preferred, including: * Infrastructure as Code (IaC) * Terraform * Ansible * GitHub * CI/CD pipelines * Jenkins * DevOps / SecDevOps practices Key Responsibilities * Design, implement, and modernize enterprise Active Directory environments * Build and decommission Active Directory domains and forests * Improve hybrid connectivity between on-premises Active Directory and AWS * Manage domain controllers, GPOs, Sites & Services, and overall AD health * Automate Active Directory administration and operational tasks * Partner with Identity & Access Management teams on AD integrations * Support Identity Governance (IGA) and Privileged Access Management (PAM) initiatives * Troubleshoot complex AD issues and perform root cause analysis * Mentor engineers and share technical knowledge across the team Role Evolution Early in the Engagement * 80% hands-on Active Directory engineering * 20% architecture and strategy As the Engagement Progresses * 80% architecture, modernization, and technical leadership * 20% hands-on engineering * Mentor Cargill engineers and help shape long-term AD strategy Ideal Candidate Profile We're looking for candidates with experience in: * 8-15+ years of Active Directory engineering * Large enterprise Active Directory environments * AD migrations, consolidations, and modernization initiatives * AWS Managed Microsoft AD or hybrid Active Directory * Microsoft Entra ID * Infrastructure as Code (Terraform, Ansible) * GitHub and CI/CD automation * Architecture and hands-on engineering * Leading technical initiatives and mentoring engineers Preferred Qualifications * Experience supporting Identity Governance (IGA) or Privileged Access Management (PAM) solutions (specific platforms not required) * Microsoft, AWS, CyberArk, or SailPoint certifications are a plus, but hands-on experience is valued more than certifications