Title: Senior Active Directory (AD) Engineer
Location: Houston, TX/Hybrid
Job Description:
We are looking for an experienced Senior Active Directory Engineer to manage and secure our AD environment, with a focus on root-level permissions management. The ideal candidate will have a strong understanding of AD architecture, security best practices, and automation tools to ensure the integrity, security, and efficient operation of our directory services in a critical infrastructure environment.
Responsibilities:
Manage and configure Active Directory forests, domains, and organizational units (OUs).
Modify and delegate permissions at the forest and root levels, ensuring secure access controls.
Design and implement permission structures aligned with security best practices and the principle of least privilege.
Perform complex permission migrations and modifications with minimal service disruption.
Automate permission changes and audits using PowerShell or other scripting tools.
Troubleshoot and resolve permission-related issues, including access denied errors.
Collaborate on security policies, audit configurations, and compliance standards related to AD.
Apply Group Policy best practices to influence permissions and security settings.
Integrate Active Directory into cloud environments for hybrid single sign-on (SSO) and multi-factor authentication (MFA).
Manage domain log-ins, group policies, and access controls for internal enterprise applications.
Utilize Microsoft Entra ID (Azure AD), Intune, and ServiceNow CMDB for governance, asset management, and compliance.
Maintain AD backup, recovery, and disaster recovery procedures.
Follow strict change management, security, testing, documentation, and operational procedures in a highly regulated environment.
Requirements:
8+ years of hands-on experience in Active Directory management, including schema, replication, and trust relationships.
Expertise in managing permissions at the forest and root levels, with deep knowledge of ACLs, security descriptors, and inheritance.
Strong understanding of permissions, security best practices, and the principle of least privilege.
Experience integrating AD into cloud environments for hybrid SSO and MFA solutions.
Familiarity with Microsoft Entra ID (Azure AD), Intune, and ServiceNow CMDB for governance and compliance.
Knowledge of AD security, audit policies, and compliance standards.
Strong scripting skills, particularly with PowerShell, for AD queries, reporting, validation, automation, and auditing.
Experience with AD backup, recovery, and disaster recovery procedures.
Expertise in troubleshooting and problem-solving related to permissions issues.
Excellent written and verbal communication skills, including documentation, change requests, and cross-team coordination.
Nice to have certifications: such as CISSP, CISM, CompTIA Security+, CEH, or relevant Microsoft certifications.