01Overview
About the Role
We're looking for a hands-on operations engineer to own the day-to-day health of our enterprise Active Directory environment domain controllers, replication, DNS, Group Policy, and the authentication plumbing that keeps everything else running. You'll be the person cybersecurity, infrastructure, endpoint, and service desk teams call when something in the directory layer breaks, and the one who makes sure it doesn't break the same way twice.
What You Bring
Must-Have
Bachelor's degree in Computer Science, IT, Engineering, Information Systems, or equivalent hands-on experience
5+ years running enterprise Active Directory in large, multi-site, multi-domain, or multi-forest setups
Deep comfort with AD DS, domain controllers, replication, Sites and Services, FSMO roles, trusts, SYSVOL, DNS, and Windows Server
A track record diagnosing Kerberos, LDAP/LDAPS, NTLM, DNS, SPN, GPO, and trust-relationship issues, including where they intersect with directory-integrated applications
Experience pushing production changes through formal change control validation, rollback plans, peer review, documentation, the works
Solid grasp of least-privilege design, delegated admin models, privileged access controls, stale object cleanup, and service account hygiene
Working knowledge of SSO, MFA, federation/ADFS, LDAP, Kerberos, SAML/OAuth/OpenID Connect, Microsoft Entra ID, and hybrid identity sync
Experience responding to audit evidence requests, compliance checks, access reviews, and remediation work tied to AD
Strong PowerShell chops for admin tasks, reporting, troubleshooting, cleanup, and automation
Comfort with monitoring/logging/alerting tools used to gauge directory health
Sharp analytical and communication skills, and the follow-through to see issues to resolution
Ability to operate independently while working closely with identity, security, infra, endpoint, and application teams
Nice-to-Have
Microsoft identity, Windows Server, security, or cloud identity certifications (or equivalent depth)
Exposure to PKI/AD Certificate Services, RADIUS/NPS, secure LDAP, ADFS/federation, certificate-based auth, SailPoint, CyberArk, Microsoft Entra, or similar tooling
Background supporting global AD footprints, migration/consolidation efforts, M&A integration, SIEM/log analysis, vulnerability management, or enterprise monitoring
What You'll Do
Keep the Directory Healthy
Own daily health across domain controllers, replication, trusts, Sites and Services, DNS, SYSVOL, and FSMO awareness
Catch and fix authentication failures, replication errors, DC performance issues, time-sync drift, and general service degradation
Support multi-domain/multi-forest topologies, including cross-trust authentication and replication troubleshooting
Roll out AD platform changes safely approved standards, validation, documentation, full change control
Be the Escalation Point
Take ownership of complex AD incidents spanning authentication, access, GPO, replication, DNS, DC availability, and app integration
Drive or support root-cause analysis on recurring or high-impact directory incidents, and track fixes through to done
Work cross-functionally with service desk, endpoint, network, security, infra, and application teams whenever AD sits in the dependency chain
Take part in on-call/escalation coverage for critical AD and identity issues
Administer Group Policy & Access
Manage and troubleshoot GPOs inheritance, filtering, item-level targeting, loopback processing, conflicts, and endpoint impact
Govern OU structure, delegated permissions, privileged groups, service accounts, and directory object lifecycle
Review proposed GPO/directory changes for operational and security risk, scope, performance, and standards alignment
Secure the Identity Layer
Troubleshoot Kerberos, LDAP/LDAPS, NTLM, DNS, SPNs, constrained delegation, certificates, service accounts, and app integrations
Support LDAP, ADFS/federation, Microsoft Entra hybrid dependencies, SSO, MFA, privileged access, and identity governance tooling
Run privileged group reviews, delegation reviews, stale object cleanup, service account hygiene checks, and audit evidence gathering
Partner with security teams to investigate and close out directory security findings and control gaps
Automate & Document
Support DC upgrades, Windows Server lifecycle work, certificate lifecycle, DNS cleanup, migrations, consolidations, decommissions, and modernization
Build PowerShell automation for health checks, reporting, cleanup, compliance evidence, GPO inventory, and privileged group monitoring
Keep SOPs, runbooks, topology docs, GPO documentation, and handoff records current
Join peer reviews, lessons-learned sessions, and service improvement planning
How Success Gets Measured
Fewer repeat authentication, replication, DNS, GPO, and lockout incidents thanks to real root-cause fixes
Privileged group reviews, stale object cleanup, and .