via Careerplug
$85K - 130K a year
Lead design, modernization, and security of enterprise identity infrastructure including Active Directory and drive automation initiatives.
Over 10 years hands-on Active Directory experience, expert identity security knowledge, strong PowerShell skills, and understanding of Zero Trust principles.
Senior Directory Services Engineer (Active Directory Expert) Location: Remote Type: Contract to Hire (6-12 months) Role Overview The Senior/Principal Directory Services Engineer is the organization’s top technical authority for Active Directory and core identity infrastructure. This role leads the design, modernization, security, and lifecycle management of enterprise directory services, ensuring reliability, scalability, and alignment with business and regulatory requirements. Key Responsibilities Serve as the principal expert for Active Directory architecture, design, and operations across multi‑domain, multi‑forest environments. Lead modernization initiatives including domain consolidation, schema upgrades, AD hardening, and identity lifecycle automation. Architect and maintain Group Policy, DNS, DHCP, replication, trusts, and domain controller strategy. Oversee AD security posture: privileged access, tiering models, delegation, auditing, and Zero Trust alignment. Drive root‑cause analysis and resolution of complex directory issues impacting authentication, authorization, and enterprise applications. Develop standards, runbooks, and automation using PowerShell and modern configuration tools. Collaborate with cross‑functional teams (Security, Cloud, Infrastructure, Applications) to ensure directory stability and performance. Evaluate and optimize vendor, contractor, and staffing partnerships supporting directory services. Required Experience 10+ years of hands‑on experience with Active Directory in large, complex enterprise environments. Expert‑level knowledge of AD architecture, domain controllers, replication, GPOs, DNS/DHCP, trusts, and security models. Strong experience with PowerShell scripting and automation. Deep understanding of identity security, privileged access management, and Zero Trust principles. Proven ability to lead large‑scale directory upgrades, migrations, and remediation efforts. Preferred Qualifications Background in AD forest recovery, DR planning, and cyber‑resiliency hardening. Microsoft certifications (MS‑102, AZ‑104, SC‑300) or equivalent is a plus This is a remote position.
This job posting was last updated on 9/24/2026