Active Directory Engineer

Marotta Controls

Parsippany-Troy Hills (NJ)

On-site

USD 108,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical
Dental
Vision
Life and disability insurance
401k with company match
Tuition aid
Paid vacation
Sick days
Holidays and flexible hours

Job summary

Marotta Controls in Parsippany, NJ is seeking an Active Directory Engineer to design, implement and support enterprise AD infrastructure in a multi-forest environment, focusing on security and identity services.

The role emphasizes Entra/Azure AD, SSO, MFA, RBAC and identity lifecycle management to enable secure access across cloud and on‑premises applications.

Qualifications

  • Bachelor's degree in computer science or equivalent.
  • Must be a US Citizen.
  • Five to seven years' hands-on AD admin experience in a multi-forest environment.
  • Experience with Microsoft Entra (Azure AD) and hybrid identity.
  • Experience implementing SSO: SAML, Kerberos, NTLM.
  • Experience implementing MFA including Duo MFA.
  • Identity lifecycle management and provisioning/deprovisioning.
  • ADManager Plus for provisioning, reporting and bulk management.
  • Strong PowerShell scripting skills.
  • Excellent written and verbal communication; team oriented.

Responsibilities

  • Design, implement, and maintain Active Directory services in a multi-forest environment.
  • Administer and optimize Microsoft Entra (Azure AD) including hybrid identity.
  • Implement and support SSO for cloud and on‑prem apps.
  • Manage identity lifecycle processes using ADManager and related tooling.
  • Configure authentication methods including MFA and conditional access.
  • Enforce RBAC and least privilege across identities.
  • Support audits and compliance with NIST/CMMC controls.
  • Collaborate with security and infrastructure teams on identity services.
  • Develop documentation and runbooks for identity platforms.
  • Participate in modernization initiatives and continuous improvement.

Skills

Active Directory Admin
PowerShell scripting
Group Policy management
Azure AD / Entra
SSO technologies
MFA solutions
Identity lifecycle mgmt
RBAC / least privilege
Troubleshooting
Documentation & communication

Education

Bachelor's degree in computer science or equivalent

Tools

ADManager Plus
Azure AD Connect
PowerShell tooling
SAML/Kerberos/NTLM concepts

Job description

Position: Active Directory Engineer

Location: Parsippany, NJ

Job Id: 1906-290-26-R-S

# of Openings: 1

Pay Range: $108,000 - $130,000 per year

Elevate your career at Marotta Controls, a New Jersey Top Workplace three years running! Dedicated to innovation, quality and excellence, we deliver cutting edge control systems for the Aerospace & Defense industry. At Marotta, we value bold thinking and teamwork, and we empower our employees to push boundaries while delivering top-tier solutions to our customers. Our team fosters a fun, collaborative culture where creativity and technical excellence thrives! Your next big opportunity starts here.

Active Directory Engineer
Essential Functions

The Active Directory Engineer is responsible for designing, implementing, and supporting enterprise-level Active Directory Infrastructure, including forests, domain and organization units. This role is also responsible for Managing and supporting Group Policy Objects to enforce security, compliance, and configuration standards and implementing and enforcing security best practices such as least privilege, privileged access management (PAM), and auditing. The ideal candidate will have deep technical expertise, strong troubleshooting skills, and a security-first mindset.

Minimum Required Qualifications
  • Bachelor's degree in computer science or equivalent
  • Must be a US Citizen
  • Technical solution design and planning experience
  • Strong knowledge of creating, managing and troubleshooting Group Policy Object
  • Basic understanding of the project management life cycle
  • Five to seven years' hands-on experience administering and hardening Microsoft Active Directory in a multi-forest environment
  • Experience with Microsoft Entra (Azure AD) and hybrid identity architectures
  • Experience implementing and supporting Single Sign-On (SSO) technologies (SAML, Kerberos, NTLM)
  • Experience implementing and supporting MFA solutions, including Duo MFA
  • Experience with identity lifecycle management and access provisioning/deprovisioning
  • Leverage ADManager Plus tools to automate user provisioning, reporting, delegation, and bulk account management tasks. Experience implementing conditional access and identity security best practices
  • Strong PowerShell scripting skills for automation and administration
  • Strong attention to detail
  • Good problem-solving skills with the ability to think creatively
  • Excellent written and verbal skills, including ability to clearly articulate technical issues and activities to technical and non-technical staff
  • Strong interpersonal skills and the ability to adapt in a complex and changing environment
  • Consistently meet expected production, accuracy and quality standards as set by management
  • Must be team oriented with the ability to work independently
Additional Desired Qualifications
  • Experience administering Microsoft 365 (user, license, and service administration)
  • Experience with Privileged Access Management (PAM/PIM) solutions
  • Familiarity with Zero Trust security principles and architecture
  • Experience integrating SaaS and enterprise applications with Microsoft Entra ID
  • Familiarity with NIST 800-171 and CMMC requirements as they relate to identity and access management
  • Experience supporting audits or compliance assessments (e.g., CMMC, NIST, ISO, SOC)
  • Experience with directory synchronization tools (e.g., Entra Connect / Azure AD Connect)
  • Relevant certifications (e.g., Microsoft Identity, Azure Security Engineer, CISSP, CMMC-related certifications)
Responsibilities
  • Design, implement, and maintain Active Directory (AD) services in a multi-forest, multi-domain environment
  • Administer and optimize Microsoft Entra (Azure AD), including hybrid identity integrations
  • Implement and support Single Sign-On (SSO) solutions for cloud and on-premises applications
  • Manage identity lifecycle processes (joiner, mover, leaver) using tools such as ADManager
  • Configure and maintain authentication methods including MFA, conditional access, and federation
  • Ensure secure access controls through role-based access control (RBAC) and least privilege principles
  • Support identity architectures and configurations aligned with NIST 800-171 and CMMC security controls
  • Monitor and troubleshoot identity-related issues across on-prem and cloud platforms
  • Collaborate with security, infrastructure, and application teams to integrate identity services
  • Assist with audits, compliance assessments, and evidence collection related to identity and access controls
  • Develop and maintain technical documentation, standards, and operational procedures
  • Participate in identity modernization initiatives and continuous improvement efforts
Work Environment

This job interacts both in a professional office environment and a manufacturing/machine shop environment. This role uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines, as well as environments inclusive of the appropriate eye, hearing and foot protection (as required). Night and weekend work could be required, as job duties demand. No travel is expected for this position.

Physical Requirements

While performing the duties of this job, the employee is regularly required to see, talk, and hear

The employee is frequently required to reach and lift with hands and arms, and to use hands to finger, handle or feel

The employee is regularly required to sit, stand, walk, bend, turn, etc., and move about the facility

The employee may be required to lift, push, pull and/or move items weighing up to 25 pounds

This position is at our Parsippany NJ office location.

The salary range is $108k - $130k/year

Many of our contracts require proof that you are a U.S. citizen and/or that an export license has been obtained for employees who are citizens of certain countries. Your employment, both initially and continually thereafter, is conditioned on production of such proof of citizenship and/or any export license that may be required to comply with any and all applicable laws, regulations, or executive orders, or required by Federal, State, or local government contracts.

We offer a highly competitive compensation package for this outstanding position plus a quarterly bonus along with a full range of top quality benefits and employee services including:

  • medical
  • prescription
  • dental
  • vision
  • life and disability income insurance programs
  • 401k retirement plans with company match
  • generous tuition aid program
  • paid vacation
  • sick and personal days
  • paid holidays and flexible work hours with compressed work week options

We recognize and reward our employee's accomplishments and host several employee engagement events per quarter.

We are an affirmative action and equal opportunity employer M/F/IWD/Veterans

VETERANS ARE ENCOURAGED TO APPLY

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Active Directory Engineer
Active Directory Engineer

Marotta Controls, Inc. • Parsippany-Troy Hills (NJ)

On-site
USD 108,000 - 130,000
Medical, prescription, dental, and vision insurance
401(k) plan with company match
Tuition assistance
+2
Active Directory Engineer (Top Secret Clearance Required)
Active Directory Engineer (Top Secret Clearance Required)

TEKsystems • Richardson (TX)

On-site
USD 93,676 - 126,739
Medical, dental & vision
401(k)
Life Insurance
+5
Active Directory Administration Architect
Active Directory Administration Architect

Compunnel, Inc. • Mahwah (NJ)

On-site
USD 100,000 - 130,000
Active Directory Lead/Manager
Active Directory Lead/Manager

Revel IT • Houston (TX)

Hybrid
USD 120,000 - 150,000
Competitive salary and benefits package
Opportunities for professional growth
Flexible work options
Active Directory Infrastructure Engineer
Active Directory Infrastructure Engineer

Strategic Staffing Solutions • Charlotte (NC)

Hybrid
USD 85,000 - 105,000
Active Directory Engineer
Active Directory Engineer

Belcan LLC • Springfield (VA)

On-site
USD 110,000 - 125,000
Health care
Dental benefits
401(k)
Windows Active Directory Architect
Windows Active Directory Architect

PRI Technology • New York (NY)

On-site
USD 120,000 - 180,000
Active Directory Specialist
Active Directory Specialist

HCLTech • Cary (NC)

On-site
USD 90,000 - 120,000
Medical, dental, vision insurance
401(k) retirement plan
Paid time off
+3
Active Directory Engineer
Active Directory Engineer

System One • Springfield (VA)

On-site
USD 100,000 - 130,000
Health and welfare benefits
401(k) plan
Life insurance
+1
Principal IAM/AD Engineer -- DAVDC5693168
Principal IAM/AD Engineer -- DAVDC5693168

Compunnel Inc. • Natick (MA)

Remote
USD 110,000 - 140,000