Job Description
- Architect, implement, and maintain enterprise-scale Active Directory environments, including forests, domains, trusts, and replication strategies.
- Serve as a Domain Administrator with privileged access to Domain Controllers, responsible for managing directory infrastructure (FSMO roles, Kerberos KDCs, replication topology), overseeing schema modifications and trust relationships, creating and managing top-level OU hierarchies with appropriate security permissions and GPO linkages, monitoring and securing the domain root and Domain Controllers OU.
- Lead disaster recovery planning and execution for schema, trust, and domain-level incidents.
- Administer Group Policy at the domain root and Domain Controllers OU, ensuring compliance and security.
- Perform secure remote administration of Domain Controllers and member servers.
- Coordinate alarm distribution and security event monitoring with OU Admins.
- Plan and manage all AD and Domain Controller migrations and upgrades.
- Ensure compliance with regulatory and auditing requirements in a highly secure environment.
- 4+ years of proven experience in software delivery automation and architecting complex Active Directory environments.
- Deep expertise in the Windows Server platform and supporting identity services, including Active Directory, GPO, DNS, DHCP, and Certificate Authorities (CAs).
- Strong knowledge of identity lifecycle management and authentication protocols (Kerberos, NTLM).
- Expertise designing and implementing AD forests, domains, trusts, and replication strategies.
- Extensive hands-on experience utilizing and administering CI/CD tools (e.g., Jenkins, GitHub, Octopus).
- Strong programming and scripting proficiency in PowerShell or
- Intermediate programming proficiency in python or equivalent language (Advanced PowerShell acceptable alternative).
- Hands-on experience with Infrastructure as Code (IaC) tools (Terraform, Ansible, Chef, or Salt) and applying DevOps principles.
- Comprehensive knowledge of Windows Server operating systems.
- Familiarity with monitoring and logging tools (e.g., Grafana, Humio).
- Solid understanding of security best practices, change management, and backup/recovery strategies in AD.
- Experience working in regulated environments with an emphasis on compliance and auditing.
- Ability to work collaboratively in a fast-paced, team-oriented environment.
Degree in Computer Science, Engineering, Mathematics, or a similar field of study, or equivalent work experience.
- Hybrid Identity: Hands-on experience with Azure AD, Azure AD Connect, and Conditional Access policies.
- Authentication & Integration: Familiarity with MFA, SSO, and federation technologies (e.g., ADFS, SAML, OAuth).
- Experience integrating AD with other platforms (e.g., Linux, SaaS applications).
- Security Operations: Experience with enterprise-wide EDR or Antivirus deployment and maintenance.
- Certifications: Microsoft certifications such as Microsoft Certified: Identity and Access Administrator Associate or Azure Solutions Architect.
- Mindset: A strong documentation focus, excellent verbal communication skills, and a mindset for proactive problem-solving and continuous improvement.
- Experience with third-party identity and privilege access management tools (e.g., CyberArk, BeyondTrust).
- Familiarity with Zero Trust architecture and conditional access models.
- Exposure to incident response, AD forensics, and ITIL-based change management processes.
We offer one of the most comprehensive and generous benefits plans available and offer a range of total rewards that may include merit increases, incentive compensation (exempt roles only), paid holidays, paid time off, medical, dental, vision, short and long term disability benefits, 401(k) +match, life insurance, and various wellness programs, among others. The Company does not provide benefits directly to contingent workers/contractors and interns.