Active Directory Engineer

Insight Global

Houston (TX)

On-site

USD 76,000 - 103,000

Full time

24 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Insight Global in Houston, TX is seeking a hands-on Active Directory Engineer to join their Cloud Infrastructure / Identity team. This long-term contract role is on-site in the Energy Corridor three days a week, and you’ll manage a large, hybrid AD environment that combines on-prem with Entra ID.

You will stabilize, modernize, and clean up the environment, drive migrations, automate with PowerShell, and implement least-privilege controls while collaborating with IAM stakeholders.

Qualifications

  • 7+ years of hands-on Active Directory engineering experience in enterprise environments.
  • Strong experience in multi-domain/multi-forest AD environments, including domain controllers, trusts, schema, GPOs, FSMO, replication, and troubleshooting.
  • Proven AD migration experience using tools and PowerShell-based migration and support scripting.
  • Experience supporting hybrid identity environments, with AD integrated with Entra ID/Azure AD, Entra ID Connect and directory synchronization concepts.
  • Strong PowerShell automation skills for operational improvements.
  • Proven experience leveraging AD migration tools.
  • Solid understanding of AD security, least-privilege access, auditing and hardening practices.
  • A hands-on mindset with comfort working in imperfect, not perfectly documented environments.

Responsibilities

  • Clean up, stabilize, and improve an existing enterprise Active Directory environment.
  • Support and execute Active Directory migration and optimization efforts across workstations, servers, and applications with minimal disruption.
  • Troubleshoot and remediate complex AD issues, including replication, DNS, schema, trusts, domain controllers, GPOs, and legacy performance problems.
  • Assess AD health and drive improvements across multi-domain and multi-forest environments.
  • Support hybrid identity operations, including on-prem AD integration with Entra ID and directory synchronization tooling.
  • Build and maintain PowerShell automation to improve AD health, compliance, and operational consistency.
  • Implement and reinforce tiered security / tiered administration practices, least-privilege access, and auditing standards.
  • Collaborate with cross-functional teams to assess dependencies, mitigate risk, and execute changes in a controlled manner.
  • Partner with IAM stakeholders to support governance workflows and understand how SailPoint integrates with AD for access lifecycle management.

Skills

AD engineering
Multi-domain AD
AD migration
Entra ID/Azure AD
PowerShell automation
AD security
Troubleshooting
Migration tooling

Tools

Quest Migrator Pro
Binary Tree
SailPoint
Azure AD Connect

Job description

3 Days a week ONSITE in Houston, Texas - Energy Corridor

Long-term contract, $55-$75/hr on W2

Required Skills & Experience
  • 7+ years of hands‑on Active Directory engineering experience in enterprise environments.
  • Strong experience working in multi‑domain and multi‑forest Active Directory environments, including domain controllers, trusts, schema, Group Policy Objects (GPOs), FSMO roles, replication, and advanced troubleshooting.
  • Proven Active Directory migration experience using tools and PowerShell‑based migration and support scripting.
  • Experience supporting hybrid identity environments, with Active Directory integrated with Entra ID, including exposure to Entra ID (Azure AD), Azure AD Connect and directory synchronization concepts, and identity federation tools as applicable.
  • Strong PowerShell automation skills focused on operational improvements and repeatable engineering outcomes.
  • Proven experience leveraging Active Directory migration tools
  • Solid understanding of Active Directory security and controls, including least‑privilege access, auditing, and security hardening practices.
  • A hands‑on, “roll up your sleeves” mindset with comfort working in environments that are mid‑improvement and not perfectly documented.
Nice to Have Skills & Experience
  • Experience with identity governance tools (strong preference for SailPoint) and understanding of how governance integrates with AD.
  • Hands‑on experience with Quest Migrator Pro for Active Directory (MPAD) or Binary Tree migration tools.
  • Familiarity with tiered security model concepts (Tier 0/1/2 administration patterns).
  • Experience supporting environments impacted by M&A, legacy consolidation, or recovery from migration issues.
  • Exposure to: Windows Server 2016+, Azure infrastructure and/or Intune, Monitoring / AD tooling (e.g., SolarWinds, ManageEngine), ITSM tools (ServiceNow) and Agile tooling (Jira)
  • Relevant certifications: Microsoft identity-focused certifications or equivalent experience.
Job Description

A client of Insight Global is seeking a highly skilled Active Directory Engineer to join their Cloud Infrastructure / Identity team. This is an engineer-level, hands‑on role (not an architect-only position). You’ll step into a large, complex on‑prem Active Directory environment that has grown over many years and includes legacy domains from past acquisitions/mergers. The environment is hybrid (on‑prem AD integrated with Entra ID) and needs stabilization, modernization, and cleanup. This role is ideal for someone who enjoys “getting into the weeds,” improving imperfect systems, and helping shape how the environment should operate going forward. The team is looking for an engineer who is comfortable with ambiguity, enjoys problem-solving, and is excited to help re‑engineer and optimize identity infrastructure.

Key Responsibilities:
  • Clean up, stabilize, and improve an existing enterprise Active Directory environment.
  • Support and execute Active Directory migration and optimization efforts across workstations, servers, and applications with minimal disruption.
  • Troubleshoot and remediate complex AD issues, including replication, DNS, schema, trusts, domain controllers, GPOs, and legacy performance problems.
  • Assess AD health and drive improvements across multi‑domain and multi‑forest environments.
  • Support hybrid identity operations, including on‑prem AD integration with Entra ID and directory synchronization tooling.
  • Build and maintain PowerShell automation to improve AD health, compliance, and operational consistency.
  • Implement and reinforce tiered security / tiered administration practices, least‑privilege access, and auditing standards.
  • Collaborate with cross‑functional teams to assess dependencies, mitigate risk, and execute changes in a controlled manner.
  • Partner with IAM stakeholders to support governance workflows and understand how SailPoint integrates with AD for access lifecycle management (joiner/mover/leaver, provisioning, deprovisioning).
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr Active Directory Engineer
Sr Active Directory Engineer

Revel IT • Houston (TX)

Hybrid
USD 120,000 - 170,000
Hybrid work model
Infobox Engineer
Infobox Engineer

JSM Consulting Inc. • New York (NY)

Hybrid
USD 96,000 - 165,000
Senior Active Directory Engineer
Senior Active Directory Engineer

Optomi • Orlando (FL)

On-site
USD 120,000 - 180,000
Senior Active Directory & Entra ID Engineer
Senior Active Directory & Entra ID Engineer

Noblesoft Solutions • Saint Petersburg (FL)

Hybrid
USD 90,000 - 140,000
AD Engineer — Hybrid Identity & Automation (Houston Onsite)
AD Engineer — Hybrid Identity & Automation (Houston Onsite)

Insight Global • Houston (TX)

On-site
USD 76,000 - 103,000
Senior Directory Services Engineer Active Directory Expert
Senior Directory Services Engineer Active Directory Expert

DEXTER TECHNOLOGIES INC • United States

Remote
USD 124,000 - 207,000
Active Directory Architect
Active Directory Architect

Clark Davis Associates • Morristown (NJ)

On-site
USD 150,000 - 160,000
Medical insurance
401(k)
Active Directory Architect - Remote
Active Directory Architect - Remote

Covetus • Texas City (TX)

On-site
USD 100,000 - 130,000
Active Directory Architect
Active Directory Architect

Pipe Recruit • United States

On-site
USD 110,000 - 130,000
Active Directory Specialist
Active Directory Specialist

Compunnel, Inc. • Richmond (VA)

On-site
USD 100,000 - 130,000