We are looking for a Senior Active Directory Engineer to join our global infrastructure team. This role is central to managing and securing the organization's identity services across a complex enterprise environment. You will be responsible for designing, operating, and securing Active Directory, Group Policies, DNS, Certificate Services, and directory integrations with hybrid/cloud systems like Azure AD. You will also support automation, standardization, and the stability of our Windows Server ecosystem.
Active Directory & Identity Management
Design, manage, and support complex multi-domain/multi-forest
Active Directory
environments.
Maintain and optimize
Group Policy Objects (GPO)
to enforce security and configuration standards.
Operate and secure
DNS
,
DHCP
, and
Certificate Services (PKI)
.
Implement and monitor domain trusts, replication, and OU structure across global regions.
Manage
AD-integrated services
and applications (LDAP, Kerberos, SSO, etc.).
Perform regular AD health checks, audits, and remediation tasks.
Integrate and support
hybrid identity models
involving
Azure AD
,
Entra ID
, and
M365
.
Security & Compliance
Apply security baselines (CIS, Microsoft STIGs) to harden domain controllers and related services.
Support privileged access management and role-based access controls within AD.
Collaborate with security and compliance teams to meet audit and regulatory requirements.
Windows Server Infrastructure Support
Support domain controllers running
Windows Server 2016/2019/2022
.
Participate in server patching, lifecycle management, and incident response.
Contribute to performance tuning and troubleshooting related to AD services.
Automation & Scripting
Develop
PowerShell
scripts to automate AD tasks such as user provisioning, OU management, and reporting.
Use tools like
DSC
,
SCCM
, or
Ansible
for configuration consistency where applicable.
Maintain scripts in version-controlled repositories and follow scripting best practices.
Projects & Operational Excellence
Lead or support AD migration, consolidation, and upgrade initiatives.
Provide 3rd-level escalation for directory-related incidents and change requests.
Document architecture, configuration, and standard operating procedures (SOPs).
Required Skills & Experience
Bachelor's degree in Computer Science, Information Systems, or equivalent experience.
12+ years of hands-on experience with
Active Directory administration
in enterprise environments.
Deep expertise in
GPOs
,
OU design
,
domain trusts
,
replication
,
FSMO roles
, and
AD health
.
Strong experience with
PKI
,
DNS
, and
DHCP
in Microsoft ecosystems.
Excellent
PowerShell scripting
for AD automation.
Solid understanding of identity integrations with