Active Directory Architect – Windows AD / IAM / Cloud Security

Realtek Consulting LLC

Irvine (CA)

On-site

USD 100,000 - 140,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Realtek Consulting LLC is seeking an experienced Active Directory Architect/Administrator in Irvine, CA to design, implement, and manage enterprise AD environments. The role focuses on secure, scalable domain services, DNS, GPOs, PKI, and cloud integrations across AWS/Azure/Google Cloud.

Responsibilities include AD health checks, migrations to Windows Server 2025, FSMO management, and IAM security alignment with enterprise policies.

Qualifications

  • Must have extensive experience with Microsoft Active Directory and Domain Controllers.
  • Experience with AD migrations and upgrades, including Windows Server 2019/2022 to 2025.
  • Strong DNS, GPO, PKI, and LDAPS experience.
  • Experience with cloud platforms (AWS, Azure and/or Google Cloud) and hybrid AD.
  • Knowledge of IAM security principles and vulnerability remediation.
  • Ability to design secure AD architectures and implement security controls.

Responsibilities

  • Design, maintain, and support enterprise Microsoft Active Directory environments.
  • Architect secure and scalable Active Directory solutions aligned with enterprise security standards.
  • Manage Domain Controllers and Active Directory infrastructure.
  • Perform Domain Controller and AD schema upgrades/migrations, including upgrades from Windows Server 2019/2022 to Windows Server 2025.
  • Troubleshoot Active Directory replication and authentication issues.
  • Manage FSMO (Flexible Single Master Operations) roles.
  • Perform AD health checks and proactively identify infrastructure issues.
  • Support enterprise AD modernization and security initiatives.

Skills

Active Directory
Domain Controllers
AD replication
AD schema
FSMO roles
AD security
AD troubleshooting
AD migrations
Windows Server 2025
DNS
GPOs
IAM
PKI
LDAPS
Vulnerability remediation

Tools

Azure
AWS
Google Cloud
Virtual Machines

Job description

Key Responsibilities
  • Design, maintain, and support enterprise Microsoft Active Directory environments.
  • Architect secure and scalable Active Directory solutions aligned with enterprise security standards.
  • Manage Domain Controllers and Active Directory infrastructure.
  • Perform Domain Controller and AD schema upgrades/migrations, including upgrades from Windows Server 2019/2022 to Windows Server 2025.
  • Troubleshoot Active Directory replication and authentication issues.
  • Manage FSMO (Flexible Single Master Operations) roles.
  • Perform AD health checks and proactively identify infrastructure issues.
  • Support enterprise AD modernization and security initiatives.
Key Responsibilities
  • Design, maintain, and support enterprise Microsoft Active Directory environments.
  • Architect secure and scalable Active Directory solutions aligned with enterprise security standards.
  • Manage Domain Controllers and Active Directory infrastructure.
  • Perform Domain Controller and AD schema upgrades/migrations, including upgrades from Windows Server 2019/2022 to Windows Server 2025.
  • Troubleshoot Active Directory replication and authentication issues.
  • Manage FSMO (Flexible Single Master Operations) roles.
  • Perform AD health checks and proactively identify infrastructure issues.
  • Support enterprise AD modernization and security initiatives.
Active Directory Architecture & Administration
  • Design, maintain, and support enterprise Microsoft Active Directory environments.
  • Architect secure and scalable Active Directory solutions aligned with enterprise security standards.
  • Manage Domain Controllers and Active Directory infrastructure.
  • Perform Domain Controller and AD schema upgrades/migrations, including upgrades from Windows Server 2019/2022 to Windows Server 2025.
  • Troubleshoot Active Directory replication and authentication issues.
  • Manage FSMO (Flexible Single Master Operations) roles.
  • Perform AD health checks and proactively identify infrastructure issues.
  • Support enterprise AD modernization and security initiatives.
IAM & Security
  • Strong experience with Identity and Access Management (IAM).
  • Apply security principles related to:
  • Confidentiality
  • Integrity
  • Authorization
  • Accountability

Implement and maintain secure identity and access controls.Support authentication, authorization, and directory security.Identify and remediate Active Directory security vulnerabilities.Develop security standards and controls for enterprise identity infrastructure.

Windows Server Security & Vulnerability Management
  • Perform Windows Server vulnerability remediation.
  • Manage security patching and compliance activities.
  • Implement secure configuration standards across Windows Server environments.
  • Identify vulnerabilities and coordinate remediation activities.
  • Ensure systems meet enterprise security and compliance requirements.
DNS Administration
Strong Hands-on Experience Managing Microsoft DNS, Including
  • A records
  • AAAA records
  • CNAME records
  • MX records
  • TXT records
  • SRV records
  • NS records
  • SOA records
  • PTR records
  • Reverse lookup zones
  • Create and manage reverse DNS zones.
  • Troubleshoot DNS resolution and Active Directory-integrated DNS issues.
  • Manage DNS dependencies associated with Active Directory services.
Group Policy
  • Design, configure, and manage Group Policy Objects (GPOs).
  • Develop and implement enterprise security policies through GPO.
  • Troubleshoot GPO application and inheritance issues.
  • Manage policies related to authentication, security, system configuration, and compliance.
PKI / Certificates / LDAPS
  • Manage enterprise PKI and digital certificates.
  • Configure and troubleshoot SSL/TLS certificates.
  • Manage SSL cipher suites associated with Active Directory.
  • Configure and troubleshoot LDAPS.
  • Troubleshoot certificate trust, expiration, authentication, and connectivity issues.
  • Ensure certificate infrastructure follows enterprise security standards.
Windows Event Auditing & Centralized Logging
  • Configure Windows Event Auditing.
  • Monitor security and authentication events.
  • Configure forwarding of Windows audit events to centralized logging/SIEM platforms.
  • Troubleshoot security and authentication issues using Windows event logs.
  • Support security monitoring and compliance requirements.
Networking
Strong Understanding Of
  • TCP/IP
  • TCP / UDP
  • DNS
  • Network connectivity
  • Firewall concepts
  • Active Directory network ports and protocols
  • Troubleshoot connectivity issues between Domain Controllers, clients, applications, and infrastructure services.
  • Understand network dependencies of Microsoft Active Directory services.
  • Troubleshoot authentication, LDAP/LDAPS, DNS, and directory connectivity issues.
Cloud Architecture & Security
AWS / Azure / Google Cloud Platform
  • Experience supporting Windows and Active Directory environments in cloud platforms.
  • Experience with AWS, Azure, and/or Google Cloud Platform.
  • Design secure cloud architectures aligned with enterprise security requirements.
  • Work with cloud-based virtual machines and Windows workloads.
  • Troubleshoot Windows VMs operating within cloud environments.
  • Understand cloud networking and security controls.
  • Apply IAM and access-control principles to cloud environments.
Cloud Security Architecture
  • Create security blueprints and roadmaps for cloud adoption.
  • Design secure, scalable, and compliant cloud architectures.
  • Establish security policies, standards, and guidelines for:
  • Public Cloud
  • Private Cloud
  • Hybrid Cloud

Assess cloud environments for vulnerabilities and security risks.Implement technical security controls including:

  • Network security
  • IAM
  • Encryption
  • Access controls

Support compliance and risk-management initiatives.

DevSecOps & Collaboration
  • Collaborate with IT, infrastructure, security, cloud, and development teams.
  • Embed security practices into application and infrastructure development.
  • Support DevSecOps initiatives.
  • Provide technical guidance on identity, security, and cloud architecture.
  • Translate business and security requirements into technical solutions.
Required Technical Skills
Active Directory — Must Have
  • Microsoft Active Directory
  • Domain Controllers
  • AD replication
  • AD schema
  • FSMO roles
  • Active Directory security
  • AD troubleshooting
  • AD migrations/upgrades
  • Windows Server 2019 / 2022 / 2025
DNS — Must Have
  • Microsoft DNS
  • A / CNAME / MX / TXT / SRV / NS / SOA records
  • PTR records
  • Reverse zones
  • AD-integrated DNS
  • DNS troubleshooting
Security / IAM — Must Have
  • IAM
  • Identity and access management
  • Authentication / Authorization
  • Windows Server security
  • Vulnerability remediation
  • Security patching
  • Compliance
  • Security auditing
Group Policy — Must Have
  • GPO creation and management
  • Security policies
  • GPO troubleshooting
  • Group Policy inheritance
PKI / Certificates — Must Have
  • PKI
  • Digital certificates
  • SSL/TLS
  • SSL cipher suites
  • LDAPS
  • Certificate troubleshooting
Networking — Must Have
  • TCP/IP
  • TCP / UDP
  • Active Directory ports
  • DNS networking
  • Basic network troubleshooting
Cloud — Required
  • AWS / Azure / Google Cloud Platform
  • Cloud networking
  • IAM
  • Virtual Machines
  • Windows workloads in cloud environments
  • Cloud security
Preferred Qualifications
  • Experience designing enterprise-scale AD architecture.
  • Experience with Active Directory modernization and migration projects.
  • Windows Server 2025 upgrade experience.
  • Experience with hybrid Active Directory environments.
  • Experience integrating on-premises AD with cloud identity platforms.
  • Experience with centralized logging/SIEM solutions.
  • Experience with cloud security architecture.
  • Experience with DevSecOps.
  • Experience working in highly regulated enterprise environments.
  • Strong documentation and architecture-design skills.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Active Directory Engineer
Active Directory Engineer

Perennial Resources International • New York (NY)

On-site
USD 120,000 - 150,000
Active Directory Architect
Active Directory Architect

Pipe Recruit • United States

On-site
USD 110,000 - 130,000
AD Architect
AD Architect

Tata Consultancy Services • Irvine (CA)

On-site
USD 95,000 - 140,000
Active Directory Architect - Remote
Active Directory Architect - Remote

Covetus • Texas City (TX)

On-site
USD 100,000 - 130,000
AD Architect - Hybrid Identity & Cloud IAM Lead
AD Architect - Hybrid Identity & Cloud IAM Lead

Siri InfoSolutions, Inc. • Irvine (CA)

On-site
Confidential
Azure Directory Architect
Azure Directory Architect

METRIX IT SOLUTIONS INC • Irvine (CA)

On-site
USD 100,000 - 150,000
Windows/Active Directory Security Lead
Windows/Active Directory Security Lead

PRI Technology • New York (NY)

On-site
USD 286,541,000 - 315,195,000
Active Directory Administrator
Active Directory Administrator

Vortalsoft Inc • New Jersey

On-site
USD 80,000 - 110,000
Windows System Engineer
Windows System Engineer

Remote Jobs • United States

Remote
USD 90,000 - 140,000
Windows AD Administrator
Windows AD Administrator

Saicon • San Jose (CA)

On-site
USD 120,000 - 180,000