Hi,
Greetings from Conch Technologies Inc
Position: Sr Indentity Infrastructure Engineer ( Active Directory )
Location: Wayzata, MN ( Hybrid 2-3 days onsite in Minneapolis or near Wayzata, MN )
Duration: 6+ Months Contract
Responsibilities include but are not limited to:
- Design, engineer, operate, and secure Active Directory forests, domains, trusts, organizational units, Group Policy, and domain controllers.
- Partner with IAM and PAM teams to design and support privileged access controls, including administrative group structures and delegated administration models.
- Monitor, troubleshoot, and remediate Active Directory health issues, including authentication failures, replication, DNS dependencies, domain controller availability, and account state incidents.
- Support integrations between Active Directory and identity governance, access request, authentication, and certification platforms.
- Develop and maintain standards, runbooks, and operational documentation for Active Directory services and domain controller operations.
- Participate in change management, incident response, audits, and continuous improvement initiatives aligned to the IAM roadmap and security strategy.
- Develop integration patterns with AWS to facilitate authentication with AD using LDAP or Kerberos
- Develop application development patterns encouraging app devs to leverage Kerberos over just LDAP
Required Qualifications include:
- Hands‑on experience administering Microsoft Active Directory in large, complex enterprise environments.
- Strong understanding of Active Directory security principles, delegation models, and privileged group management.
- Experience operating Active Directory as part of an integrated Identity and Access Management (IAM) ecosystem.
- Proven troubleshooting skills across authentication, replication, DNS, account lifecycle, and access issues.
- Experience working with AWS and any of its Active Directory implementation options (e.g. Managed AD, self-hosted, etc.)
- Experience integrating Active Directory with identity governance or privileged access management platforms.
- Experience supporting global, multi‑domain, or multi‑region Active Directory environments.