Active Directory Engineer

Perennial Resources International

New York (NY)

On-site

USD 120,000 - 150,000

Full time

20 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Perennial Resources International seeks an experienced Active Directory Security Architect to lead design, deployment, and hardening across large Windows environments. You will implement MFA, LAPS, and credential theft mitigations while guiding governance and compliance efforts with security teams.

You will also automate admin tasks with PowerShell, assess vulnerabilities, and design trusted AD topologies to reduce risk in regulated enterprise settings.

Qualifications

  • 7+ years architecting, administering, and securing Active Directory in large enterprises.
  • Deep expertise in AD, Group Policy, DNS, DHCP, and Windows Server.
  • Strong hands-on experience implementing AD security controls and hardening.
  • Experience deploying Windows LAPS and MFA for key systems.
  • Experience with credential theft mitigation technologies and Credential Guard.
  • Knowledge of Kerberos/NTLM and identity lifecycle management.
  • Designing forests, domains, trusts, replication, and privileged access models.
  • Familiar with AD security assessment tools and attack path analysis.
  • Proficient in PowerShell scripting and automation.
  • Degree in CS/Engineering/Math or equivalent experience.

Responsibilities

  • Design and implement AD architectures, forests, and trusts for large enterprises.
  • Evaluate and enhance AD security controls, hardening, and monitoring.
  • Lead MFA deployment, LAPS rollout, and credential theft mitigation initiatives.
  • Coordinate with security teams on governance, audits, and compliance.
  • Automate administrative tasks with PowerShell and related tools.
  • Assess vulnerabilities and remediate AD misconfigurations in regulated environments.

Skills

Active Directory
Group Policy
DNS
DHCP
Windows Server
MFA deployment
Credential Guard
Identity lifecycle management
Kerberos NTLM
Privileged access models
PowerShell scripting
Security governance
Communication skills
Problem solving

Education

Bachelor's degree in Computer Science or related field

Tools

AD security assessment tools

Job description

  • 7+ years of experience architecting, administering, and securing Active Directory in large enterprise environments
  • Deep expertise in Active Directory, Group Policy, DNS, DHCP, and Windows Server platforms
  • Strong hands-on experience implementing and managing Active Directory security controls and hardening initiatives
  • Experience deploying and managing Windows Local Administrator Password Solution
  • Experience implementing and supporting MFA for key systems
  • Experience deploying and managing Windows security features such as Credential Guard, and other credential theft mitigation technologies
  • Strong understanding of identity lifecycle management, authentication protocols (Kerberos, NTLM), and access control models
  • Proven experience designing and implementing AD forests, domains, trusts, replication strategies, and privileged access models
  • Knowledge of Active Directory tiering, privileged access management, administrative workstation strategies, and least-privilege principles
  • Experience assessing and remediating Active Directory security vulnerabilities and misconfigurations
  • Proficiency in scripting and automation using PowerShell
  • Experience working in regulated environments with an emphasis on compliance, auditing, and security governance
  • A Degree in Computer Science, Engineering, Mathematics, similar field of study, or equivalent work experience
  • Familiarity with Active Directory security assessment tools and methodologies, including attack path analysis and privilege escalation remediation
  • Experience integrating AD with other platforms (e.g. Linux systems, SaaS applications)
  • Strong understanding of EDR, endpoint security, and security monitoring solutions in Windows environments
  • Strong documentation and communication skills
  • A mindset for proactive problem-solving and continuous improvement
  • Microsoft certifications such as Microsoft Certified: Identity and Access Administrator Associate, Security Operations Analyst Associate, or Azure Solutions Architect
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Windows/Active Directory Security Lead
Windows/Active Directory Security Lead

PRI Technology • New York (NY)

On-site
USD 286,541,000 - 315,195,000
Active Directory Architect
Active Directory Architect

Pipe Recruit • United States

On-site
USD 110,000 - 130,000
Active Directory Administrator
Active Directory Administrator

Vortalsoft Inc • New Jersey

On-site
USD 80,000 - 110,000
Active Directory Architect - Remote
Active Directory Architect - Remote

Covetus • Texas City (TX)

On-site
USD 100,000 - 130,000
Senior Active Directory & Entra ID Engineer
Senior Active Directory & Entra ID Engineer

Noblesoft Solutions • Saint Petersburg (FL)

Hybrid
USD 90,000 - 140,000
Sr. Azure Active Directory Engineer
Sr. Azure Active Directory Engineer

InnoCore Solutions, Inc. • Dallas (TX)

On-site
USD 120,000 - 150,000
AD Architect
AD Architect

Tata Consultancy Services • Irvine (CA)

On-site
USD 95,000 - 140,000
Active Directory Specialist
Active Directory Specialist

Compunnel, Inc. • Richmond (VA)

On-site
USD 100,000 - 130,000
Senior Active Directory Engineer
Senior Active Directory Engineer

Insight Global • Beachwood (OH)

On-site
USD 140,000 - 170,000
Active Directory Architect
Active Directory Architect

Clark Davis Associates • Morristown (NJ)

On-site
USD 150,000 - 160,000
Medical insurance
401(k)