Technical Support Engineer

Soroc Technology

Toronto

Hybrid

CAD 69,000 - 83,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Soroc Technology in Toronto is seeking an Active Directory Support Engineer on contract for a banking client. The role is hybrid in Toronto with four days on-site per week and focuses on maintaining and hardening AD infrastructure.

You will manage AD DS across multi-domain environments, implement security controls like LDAP signing, Kerberos hardening, and Zero Trust aligned with CyberArk. The contract ranges from 6 to 12 months with rates of $50–$60 CAD per hour depending on incorporation

Qualifications

  • Hands-on AD DS administration in multi-domain environments.
  • Strong knowledge of AD DCs, DNS, and GPOs.
  • Experience with security controls: LDAP signing, Kerberos hardening, SMB signing.
  • PowerShell for audit, remediation, and automation.

Responsibilities

  • Deploy and configure domain controllers across sites for availability.
  • Replace legacy domain controllers and support modernization.
  • Implement network segmentation aligned with Zero Trust.
  • Maintain AD health: replication, authentication, DNS, and Group Policy.
  • Enforce password and privileged account controls.

Skills

Active Directory
PowerShell
NTLM
LDAP signing
Zero Trust
CyberArk
Domain Controllers
DNS
Group Policy
Windows Server hardening

Tools

CyberArk

Job description

Soroc is seeking a Active Directory Support Engineer on contract for one of our banking clients in Toronto.

Active Directory L3 Support Engineer - NTLM, PowerShell, AD, LDAP signing, Zero Trust, CyberArk

Toronto, ON - Hybrid (4 Days WFO)

6-12 months contract

Contract Rate: $50/hr on T4 OR $60/hr on Incorp

Required Technical Skills:

  • Hands-on experience administering Active Directory Domain Services in multi-domain or multi-site enterprise environments.
  • Strong knowledge of domain controllers, replication, DNS, Group Policy, authentication flows, and disaster recovery design for AD.
  • Practical experience implementing Microsoft security controls such as EPA, LDAP signing, channel binding, Kerberos hardening, SMB signing, and privileged account protections.
  • Experience with Active Directory Certificate Services, Active Directory Web Services, Windows Server hardening, and identity-related remediation programs.
  • Ability to analyze and remediate privilege escalation paths, insecure account settings, and policy-based configuration weaknesses.
  • Proficiency with PowerShell for audit, remediation, automation, and operational reporting.
  • Experience planning and executing infrastructure upgrades, domain controller replacement, and controlled production changes.

Key Responsibilities

  • Deploy and configure additional domain controllers across primary and disaster recovery sites, including DC01 and DC02, to improve availability, resilience, and site-level recovery readiness.
  • Replace legacy Windows Server 2016 domain controllers and support platform modernization activities with minimal service disruption.
  • Implement production and development network segmentation to reduce lateral movement risk and align identity services with Zero Trust principles.
  • Maintain Active Directory health across replication, authentication, DNS integration, and Group Policy processing.
  • Security Hardening and Access Control
  • Enable Extended Protection for Authentication (EPA) and require SSL/TLS for privileged HTTP-based services such as AD CS and ADWS to reduce credential relay and man-in-the-middle exposure.
  • Enforce SMB signing to help prevent tampering and NTLM relay over SMB sessions.
  • Disable NTLMv1 and strengthen LDAP protections by enforcing LDAP signing and channel binding / LDAPS for directory communications.
  • Implement Kerberos armoring, restrict unconstrained delegation, tighten delegation permissions on privileged accounts, and address unknown delegation entries.
  • Remediate excessive privilege findings, including AdminCount issues, GPO-deployed file exposure, missing protective ACLs, and privileged accounts not enrolled in Protected Users.
  • Remove insecure legacy access patterns such as Pre-Windows 2000 compatible group usage and administrator logon allowances through Group Policy.
  • Enforce stronger password and privileged account controls, including a 12-character minimum complexity baseline, password expiration where appropriate, and smartcard password rotation requirements.
  • Identify and remediate risky account configurations such as PASSWD_NOTREQD, password never expires, admin accounts with email usage, and missing delegation restrictions.
  • Group Policy, Logging, and Compliance
  • Harden Group Policy baselines by enforcing event audit logging, PowerShell logging, supported encryption types, remote desktop best-practice settings, and secure administrator sign-in controls.
  • Review and remediate LDAP signing and channel binding gaps, privileged HTTP service protection gaps, and other domain-level weak configurations identified through assessments.
  • Document remediation plans, implementation standards, and operational procedures to support audit readiness and ongoing compliance.
  • Partner with infrastructure, cybersecurity, and application teams to validate compatibility, sequence change windows, and reduce operational risk during security enforcement activities.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Active Directory L3 Support Engineer
Active Directory L3 Support Engineer

Net2Source (N2S) • Toronto

Hybrid
CAD 96,000 - 165,000
Windows Active Directory L3 Support Engineer
Windows Active Directory L3 Support Engineer

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision! • Toronto

Hybrid
CAD 90,000 - 120,000
Active Directory Specialist
Active Directory Specialist

Pacer Group • Toronto

Hybrid
CAD 83,000 - 85,000
Active Directory L3 Support Engineer
Active Directory L3 Support Engineer

Pacer Group • Toronto

Hybrid
CAD 76,000 - 83,000
Active Directory Support Engineer
Active Directory Support Engineer

Pacer Group • Toronto

Hybrid
CAD 69,000 - 83,000
Active Directory L3 Support Engineer
Active Directory L3 Support Engineer

Apptoza Inc. • Toronto

On-site
CAD 110,000 - 150,000
Senior Active Directory L3 Engineer — Hybrid/Onsite
Senior Active Directory L3 Engineer — Hybrid/Onsite

Pacer Group • Toronto

Hybrid
CAD 76,000 - 83,000
Hybrid Active Directory L3 Engineer - PowerShell Pro
Hybrid Active Directory L3 Engineer - PowerShell Pro

Pacer Group • Toronto

Hybrid
CAD 83,000 - 85,000
Active Directory Support Engineer
Active Directory Support Engineer

Tata Consultancy Services • Toronto

On-site
CAD 90,000 - 110,000
Active Directory L3 Support Engineer
Active Directory L3 Support Engineer

Tata Consultancy Services • Toronto

On-site
CAD 90,000 - 110,000