Systems Engineer (Active Directory
Role details
Job location
Tech stack
Job description
The Sr. Systems Engineer (Active Directory) is an experienced Active Directory specialist to design, implement, and manage our enterprise-wide Active Directory/Entra Hybrid infrastructure. This is a highly technical, senior-level position requiring expertise in AD architecture, security best practices, and automation. This is not an administrator role. The ideal candidate will be a subject matter expert in AD technologies, with a proven track record of designing scalable, secure, and resilient AD solutions for complex environments. Experience with Active Directory Integrated DNS and Domain Controller administration is essential. This position is on the Platform Identity Management team with a focus on owning Active Directory as a Source of Truth (SOT) for Identity. This team is also responsible for Entra and Auth0 identity services, AD CS PKI, and Identity authN/authZ.
-
Systems Planning and Implementation: Serve as the enterprise subject matter expert (SME) for Active Directory architectural designs, ensuring they align with business needs and security requirements.
-
AD Management: Develop, implement, and maintain the AD architecture, including forests, domains, organizational units (OUs), and Group Policies (GPOs). Perform advanced troubleshooting and root cause analysis for complex AD infrastructure issues, including replication, DNS, and authentication.
-
Scripting/Automation: Utilize DevOps and Platform Engineering principles to support the automation of administrative tasks across the Active Directory and Entra environment. Ensures critical AD roles and Entra Identity services have health monitoring and alerting.
-
Security Standards: Ensure the security of the AD environment by implementing best practices for authentication, authorization, and auditing. Perform periodic Domain Controller security hardening.
-
Documentation: Develop and maintain comprehensive documentation, including architectural designs, configuration standards, and standard operating procedures (SOPs).
-
Project and cross-matrix Leadership: Lead projects, working directly with Project Management, Account Management, and Customer teams. Collaborate and consult with other Berkley Technology Services teams, including security, networking, and application development to ensure seamless integration and operational efficiency.
-
Mentorship: Mentor and cross-train technical staff, peers, and subordinate team members in AD/IAM technologies and best practices.
-
ITIL Standards: Participate and adhere to defined ITIL standards for incident, request, and change management.
Requirements
Active Directory Architecture: Extensive, hands-on experience in designing, implementing, and managing large, complex, multi-forest Active Directory environments (Minimum 5 years of experience). Deep expertise in AD components such as DNS, DC, GPOs, Sites and Services, and trusts.
Netwrix Directory Manager (NDM): Proven experience implementing, configuring, and managing NDM (or similar products) to provide a policy-based delegated AD administration and governance model within a least-privileged security framework.
Windows Platforms: In-depth knowledge of Windows Server operating systems (2016, 2019, 2022, 2025) and their roles within an enterprise environment.
Security Expertise: Strong understanding of AD security best practices, including privileged access management (PAM), role-based access control (RBAC), and security hardening techniques. Previous experience with server hardening within an AD environment is preferred.
Identity & Access Management (IAM): Ability to integrate Active Directory with IAM solutions aligned with Zero Trust, identity governance, and adaptive authentication concepts. Previous experience with Okta/Auth0, Microsoft Entra ID, MFA, LDAPS preferred.
Communication: Excellent written and verbal communication skills, with the ability to document and convey complex technical concepts to both technical and non-technical audiences.
Disaster Recovery: Experience with disaster recovery and business continuity planning for AD and its role within the organization's technology stacks.
AI Tools: Demonstrate comfort using AI-assisted tools in a professional context; approach AI as a standard part of modern workflow rather than a specialized or optional capability.
Education Requirement
- Bachelor's degree in Computer Science, Information Technology, Information Systems, or a related discipline.
- Equivalent experience and/or alternative qualifications will be considered.
Benefits & conditions
The company offers a competitive compensation plan and robust benefits package for full time regular employees which for this role include:
- Base Salary Range: $107,000-$198,000
- Benefits: Health, Dental, Vision, Life, Disability, Wellness, Paid Time Off, 401(k) and Profit-Sharing plans.