Summary
Seeking an experienced Senior Active Directory Engineer to support its highly sensitive, enterprisescale identity and authentication environment. This role sits within the Tier 0 onprem infrastructure team responsible for Active Directory services, domain controller lifecycle, privileged global admin functions, and secure infrastructure automation.
Work is performed onprem in Exxon s corporate environment hosted in AWS, not in Azure.
This is a missioncritical, securitysensitive role that requires advanced experience operating at the highest administrative tier in a large enterprise.
Key Responsibilities
Operate and maintain Tier 0 Active Directory for a global enterprise (~30+ domains (in consolidation).
Build, harden, configure, and maintain primary and secondary domain controllers across onprem (AWShosted) environments.
Own Tier 0scoped Group Policies, specifically those tied to domain controllers and enterprise authentication controls.
Develop and automate AD infrastructure workflows using PowerShell and Terraform (Infrastructure as Code).
Leverage Datadog for proactive monitoring, observability, and health scoring of domain controllers and authentication services.
Support major recovery operations including accidental object deletion, DC recovery, and enterprise authentication incidents.
Collaborate with PKI, PAM, cloud authentication (Entra ID), and cybersecurity teams on boundary definitions and Tier 0 protection.
Ensure strict adherence to admintier separation, secure workstation use, and privileged identity operations.
Participate in architectural discussions around domain consolidation, forest strategy, and modernization.
Qualifications MustHave Experience
8+ years working with Active Directory in large, multiforest, multidomain enterprises.
Demonstrated experience in domain controller build & hardening, replication, FSMO roles, AD Sites & Services.
Strong PowerShell automation capabilities.
Handson experience with Terraform in hybrid or onprem environments.
Experience using Datadog for infrastructure monitoring (alerting, dashboards, log correlation).
Strong understanding of Tier 0 security boundaries, privileged access standards, and AD best practices.
Preferred
Exposure to Tanium (as Exxon transitions off SCCM).
Experience with domain consolidation projects.
Working knowledge of PKI, certificates, enterprise authentication, and cybersecurity controls.