Senior Windows Platform Engineer | Contract | Hybrid, Agoura Hills

Techholding

Los Angeles (CA)

Hybrid

USD 120,000 - 160,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Tech Holding is seeking a Senior Windows Engineer for a project-based assignment to strengthen the stability of a critical Windows environment. You will work across AD, DNS, authentication, automation, observability, security, and disaster recovery, using PowerShell and IaC to implement resilient, cloud-enabled platforms.

The role blends deep AD/Kerberos expertise with Windows automation, cloud infra, and open tooling.

Qualifications

  • Expert-level AD and DNS resilience including replication topology and health.
  • Expert Kerberos authentication knowledge with SPNs, delegation, AES/RC4.
  • Identity integration across Windows and non-Windows with LDAP and SSO.
  • Golden image and patch pipelines, CI builds, CVE-driven updates.
  • Strong Windows observability and PowerShell automation experience.
  • IaC and configuration management with OpenTofu, Chef, Ansible, Systems Manager.
  • Cloud infrastructure understanding, security, and data-protection controls.
  • PKI and certificate services expertise, and disaster recovery design.
  • Able to operate as platform/automation engineer in code-managed Windows env.

Responsibilities

  • Improve AD and DNS resilience, replication health, and domain controllers in cloud.
  • Migrate NTLM to Kerberos with outage-free transition planning.
  • Manage SPNs, constrained delegation, and reverse DNS; audit and fix issues.
  • Support identity integration including LDAP and cloud SSO across estate.
  • Enhance image and patch pipelines, CI builds, and CVE-driven rebuilds.
  • Improve Windows observability with agents, service health, and logs.
  • Develop PowerShell automation for platform operations and resiliency.
  • Support IaC and config management with OpenTofu, Chef, Ansible, Systems Manager.
  • Strengthen security controls, encryption, key management, and hardening.
  • Disaster recovery design with RTO/RPO, failover testing, and cloud accounts.

Skills

Active Directory
DNS resilience
Kerberos authentication
Identity integration LDAP
PowerShell automation
Infrastructure as Code
Cloud infrastructure
OpenTofu
Chef
Ansible
RBAC concepts
Disaster recovery planning

Tools

PowerShell
OpenTofu
Chef
Ansible
Systems Manager

Job description

About us:

Working at Tech Holding isn't just a job, it's an opportunity to be a part of something bigger. We are a full-service consulting firm that was founded on the premise of delivering predictable outcomes and high-quality solutions to our clients. Our founders and team members have industry experience and have held senior positions in a wide variety of companies – from emerging startups to large Fortune 50 firms – and we have taken our combined experiences and developed a unique approach that is supported by the principles of deep expertise, integrity, transparency, and dependability.

The Role:

We are looking for a Senior Windows Engineer for a project-based assignment to strengthen the stability and resiliency of a business-critical Windows environment across Active Directory, DNS, authentication, automation, observability, security, and disaster recovery. This is a hands-on platform engineering role that combines deep Active Directory and Kerberos expertise with Windows automation, cloud infrastructure, and Infrastructure as Code. You will work across directory services, authentication, golden image and patching pipelines, PowerShell automation, PKI, configuration management, and recovery capabilities while helping improve the reliability and resilience of the overall Windows platform. The ideal candidate is a Windows platform and automation engineer rather than a traditional Windows administrator, with strong cloud fluency and experience managing infrastructure through code and automation.

Key Responsibilities:

  • Improve Active Directory and DNS resilience, including replication topology and health, FSMO roles, DFS-R, NTDS, AD-integrated DNS, and domain controllers running as cloud instances.
  • Support the estate's migration fromNTLM to Kerberos, ensuring both protocols can operate without an outage during the transition.
  • Work with service principal names and duplicate-SPN failure modes, constrained delegation, AES over RC4 through the supported-encryption-types attribute, managed and group managed service accounts, and reverse DNS.
  • Support identity integration across the estate, including LDAP for non-Windows hosts, desktop single sign-on via Kerberos passthrough with constrained delegation, cloud single sign-on, and brokered application identity.
  • Support and improve thegolden image and patch pipeline, including image bake automation, CI-scheduled builds, promotion, deprecation, deregistration, and CVE-driven rebuilds.
  • ImproveWindows observability, including infrastructure agents, Windows service and event-channel collection, script-derived metrics, domain controller service health, replication status, and operational log-channel forwarding.
  • Develop and maintainPowerShell automation supporting Windows platform operations and resiliency.
  • SupportInfrastructure as Code and configuration management, including Chef, Ansible, Systems Manager, guardrail policies, pipeline pre-deploy validation, and OpenTofu.
  • Support multi-account rebuild, guardrail policies, and module compliance.
  • Strengthen security and data-protection controls, including encryption by default on block storage, key management, web-tier protection, and instance metadata hardening.
  • ImprovePKI and certificate services resilience, including certificate authority recovery posture.
  • Supportdisaster recovery design, cloud platform, and file services, including recovery tiering with defined RTO and RPO, pilot light versus active-passive trade-offs, non-disruptive failover testing, and divisional cloud accounts.
  • Support file-services resilience and legacy distributed file system decommissioning targeting zero RPO and sub-five-minute RTO.

Additional Areas of Focus:

  • Active Directory backup and forest recovery: Define, test, and document backup, restore, and forest recovery, including the achievable RTO.
  • NTLM decommission path: Define when NTLM can be retired and how remaining NTLM use will be audited.
  • Certificate authority recovery posture: Define recovery requirements and establish certificate inventory and expiry alerting.
  • Privileged access model for the directory: Address the RBAC transition or document the decision regarding its future state.
  • Directory-specific recovery testing: Exercise domain controller and directory recovery as part of resiliency testing.
  • Windows image catalogue rationalisation: Review the image catalogue and multi-tenant configuration.
  • Group Policy surface: Confirm whether Group Policy is genuinely unused or currently unmanaged.

Requirements:

  • Expert-level experience with Active Directory and DNS resilience, including replication topology and health, FSMO roles, DFS-R, NTDS, AD-integrated DNS, and domain controllers.
  • Expert-level knowledge of Kerberos authentication, including SPNs, duplicate-SPN failure modes, constrained delegation, AES/RC4 encryption, managed service accounts, group managed service accounts, and reverse DNS dependencies.
  • Strong experience with identity integration across Windows and non-Windows environments, including LDAP and single sign-on.
  • Expert-level experience with golden image and patch pipelines, including image bake automation, CI-scheduled builds, promotion, deprecation, deregistration, and CVE-driven rebuilds.
  • Strong Windows observability and PowerShell experience.
  • Strong experience with Infrastructure as Code and configuration management, including OpenTofu and tools such as Chef, Ansible, and Systems Manager.
  • Strong understanding of cloud infrastructure, security, data-protection controls, and infrastructure automation.
  • Strong experience with PKI and certificate services.
  • Strong experience with disaster recovery design, including RTO/RPO, recovery strategies, failover testing, and Windows file services.
  • Ability to work as a platform and automation engineer in a code-managed Windows environment rather than relying on traditional
  • Windows administration practices.
  • Ability to work independently across complex, business-critical Windows infrastructure and communicate technical decisions clearly.

Location:

  • Hybrid: 3 days per week onsite in Agoura Hills, California.
Employment type:
  • Contract

*Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time

Tech Holding is proud to be an Equal Opportunity Employer and is committed to fostering a diverse and inclusive workplace. We welcome applicants from all backgrounds and experiences, and we consider qualified applicants without regard to race, color, religion, gender, sexual orientation, gender identity, national origin, disability, veteran status, or any other legally protected characteristic. If you require accommodation in the application process, please contact our HR

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Windows Platform Engineer | Contract | Hybrid, Agoura Hills
Senior Windows Platform Engineer | Contract | Hybrid, Agoura Hills

Tech Holding • Los Angeles (CA)

Hybrid
USD 120,000 - 180,000
Hybrid work model
Senior Windows Engineer
Senior Windows Engineer

KTek Resourcing • Jersey City (NJ)

On-site
USD 110,000 - 140,000
Senior Windows Platform Engineer - Cloud & Automation
Senior Windows Platform Engineer - Cloud & Automation

Tech Holding • Los Angeles (CA)

Hybrid
USD 120,000 - 180,000
Hybrid work model
Systems Engineer III - Windows
Systems Engineer III - Windows

Applied Digital • Dallas (TX)

On-site
USD 140,000 - 180,000
Senior Windows Platform Engineer (Automation / SRE)
Senior Windows Platform Engineer (Automation / SRE)

Michael Page • New York (NY)

On-site
USD 250,000 - 300,000
Competitive salary
Comprehensive benefits package
401(k) match
Senior Windows Systems & Active Directory Administrator
Senior Windows Systems & Active Directory Administrator

Blue Star Partners LLC • Columbus (OH)

Hybrid
Confidential
10% bonus
Hybrid work model
Parking available on-site
Senior Windows Platform Engineer: AD Resilience & IaC
Senior Windows Platform Engineer: AD Resilience & IaC

Techholding • Los Angeles (CA)

Hybrid
USD 120,000 - 160,000
Windows/Active Directory Security Lead
Windows/Active Directory Security Lead

PRI Technology • New York (NY)

On-site
USD 286,541,000 - 315,195,000
Senior Cloud DevOps Engineer | Contract | Hybrid | Agoura Hills, CA New Los Angeles, California, United States
Senior Cloud DevOps Engineer | Contract | Hybrid | Agoura Hills, CA New Los Angeles, California, United States

Tech Holding • Agoura Hills (CA), Northern (KY)

On-site
USD 140,000 - 190,000
Server Engineer
Server Engineer

MMD Services, Inc. • Houston (TX)

On-site
USD 110,000 - 150,000
Hybrid schedule (3 onsite / 2 remote)