L3 AD Engineer
We are seeking an L3 AD Engineer to supplement the existing team. Candidate must have a strong background in designing, building and maintaining complex, large scale and global identity directory services environments. This is a 6-month remote contract opportunity.
Primary Duties:
· Resolve production escalations in large, global AD forest with regional domains
· Support operations for break / fix activities
· Train / mentor junior engineers
Required Skills:
· AD Engineer with 7 Years Experience, including in large enterprise environments
· 5-10 Years experience in directory services engineering
· Good understanding of AD / Entra ID Security
· AD Support: Extensive experience in supporting and troubleshooting on-prem Active Directory services (Authentication, DFS, GPO, LDAP)
o Domain Controller Roles (GCS, Operational Masters, etc.)
o Forest and Domain Design
o DNS Infrastructure
o OU Design
o Site Topology, Replication and Knowledge Consistency Checking
o Trusts (Transitive and Non-Transitive)
o Group Policy Management
o Sites & Services
o AD Certificate Services
o Troubleshooting replication, SYSVOL, GPO, DNS, Digital Certificate, LDAP, Kerberos, Federation, AD Connect and NTP issues
o Recovery
o Domain Controller migrations
o AD Domain Services
o Directory Hardening
o ADFS
o Logging and Monitoring
· AD Security: Good understanding of AD security, vulnerabilities, and common safeguards
· Tier-0 Security: Specific understanding of Tier-0 and identifying its security boundaries.
· Domain Consolidation: Experience or enhanced understanding of consolidating a large enterprise AD forest
· Cloud Interface: Familiar working with the AWS EC2 and Azure environments to build and support services
· PowerShell Scripting
· Excellent analytical skills
· Ability to leverage existing documentation
· Collaborative team worker – both in person and virtually using MS Teams or similar
· Excellent documentation skills; demonstrated proficiency in Microsoft Office including Word, Excel and PowerPoint
· Ability to work as liaison between business and information security / information technology
· Flexibility to accommodate working across different time zones
· Excellent interpersonal communication skills with strong spoken and written English
· Business outcomes mindset
· Solid balance of strategic thinking with detail orientation
· Self-starter, ability to take initiative
· Project management and organizational skills with attention to detail
Preferred Skills:
· AD Utility Tools Familiarity with: Adprep, dsadd, ntdsutil, repadmin, replsummary, dsquery, dsrm, gpupdate, gpresult, klist, netdom, dcdiag, net stop (windows service), net start (windows service), nslookup, regsvr32, etc.
Required Education
· Bachelor's degree (BA/BS) from four-year college or university; or equivalent training, education, and work experience.
· Cybersecurity certifications such as CISSP, CISM, etc.