Windows Active Directory Architect

PRI Technology

New York (NY)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

PRI Technology in New York, NY is seeking an experienced Windows / Active Directory Infrastructure Architect to design, secure, and modernize a large-scale Microsoft identity and compute environment. You will lead efforts to strengthen identity services, improve reliability, and support 24/7 operations across global business processes.

The role requires hands-on expertise with AD architecture, security hardening, automation with PowerShell, and PAM tools, with responsibilities spanning forests,

Qualifications

  • 7+ years in AD architecture, administration, and security.
  • Strong AD, GPO, DNS, DHCP, and Windows Server expertise.
  • Experience with CyberArk PAM.
  • AD security controls and hardening.
  • Experience with LAPS and MFA deployment.
  • Identity protocols Kerberos/NTLM.
  • Strong PowerShell scripting and automation.
  • Experience in regulated environments.
  • Bachelor's degree or equivalent.
  • Preferred: AD forest/trust design.

Responsibilities

  • Design, administer, secure, and support large-scale Active Directory environments.
  • Manage core Microsoft services: AD, GPO, DNS, DHCP, Windows Server.
  • Support modernization of identity and authentication services.
  • Implement and maintain AD security controls and hardening.
  • Deploy and manage LAPS and other PAM tools.
  • Support MFA for critical systems.
  • Deploy Credential Guard and other credential theft defenses.
  • Assess AD for security risks and misconfigurations.
  • Apply least-privilege and privileged access models.
  • Automate tasks and reporting with PowerShell.
  • Collaborate with security, compliance, and infrastructure teams.
  • Create and maintain documentation and standards.

Skills

Active Directory architecture
PowerShell scripting
Automation
Identity and access management
Security governance
Least-privilege principles

Education

Bachelor's degree or equivalent

Tools

CyberArk PAM
Windows LAPS
Credential Guard

Job description

Windows / Active Directory Infrastructure Architect

Location: New York, NY

We are seeking an experienced Windows / Active Directory Infrastructure Engineer to support and modernize a large-scale, mission‑critical Microsoft infrastructure environment. This role is part of a managed systems engineering team responsible for maintaining highly available compute infrastructure that supports global business operations 24/7.

We believe the ideal candidate will have deep hands‑on experience with Active Directory architecture, security, administration, automation, and infrastructure hardening in a large enterprise environment. This position will play a key role in strengthening identity services, improving reliability, enhancing security posture, and supporting the continued evolution of Windows services across a complex distributed environment.

Key Responsibilities
  • Design, administer, secure, and support large-scale Active Directory environments, including forests, domains, trusts, replication strategies, and privileged access models.
  • Manage and enhance core Microsoft infrastructure services including Active Directory, Group Policy, DNS, DHCP, and Windows Server platforms.
  • Support modernization efforts for enterprise identity and authentication services across development and production environments.
  • Implement and maintain Active Directory security controls, hardening initiatives, and vulnerability remediation efforts.
  • Deploy and manage Windows Local Administrator Password Solution and other privileged access security tools.
  • Support MFA implementation for critical systems and privileged access workflows.
  • Deploy and manage Windows security features such as Credential Guard and other credential theft mitigation technologies.
  • Assess Active Directory environments for security risks, misconfigurations, and privilege escalation paths.
  • Apply least‑privilege principles, administrative tiering models, privileged access management practices, and secure workstation strategies.
  • Automate administrative tasks, reporting, and operational processes using PowerShell.
  • Partner with security, compliance, and infrastructure teams to support auditing, governance, and regulatory requirements.
  • Create and maintain clear technical documentation, operational procedures, and infrastructure standards.
Required Qualifications
  • 7+ years of experience architecting, administering, and securing Active Directory in large enterprise environments.
  • Strong expertise in Active Directory, Group Policy, DNS, DHCP, and Windows Server administration.
  • Experience in CyberArk PAM.
  • Hands‑on experience implementing Active Directory security controls and hardening initiatives.
  • Experience deploying and managing Windows Local Administrator Password Solution.
  • Experience implementing and supporting MFA for key systems.
  • Experience with Windows security technologies such as Credential Guard and other credential theft mitigation solutions.
  • Strong understanding of identity lifecycle management, authentication protocols including Kerberos and NTLM, and access control models.
  • Proven experience designing and implementing AD forests, domains, trusts, replication, and privileged access models.
  • Knowledge of Active Directory tiering, privileged access management, administrative workstation strategies, and least-privilege practices.
  • Experience identifying and remediating Active Directory vulnerabilities and misconfigurations.
  • Strong PowerShell scripting and automation skills.
  • Experience working in regulated environments with a focus on compliance, auditing, and security governance.
  • Bachelor’s degree in Computer Science, Engineering, Mathematics, a related field, or equivalent professional experience.
Preferred Qualifications
  • Familiarity with Active Directory security assessment tools, attack path analysis, and privilege escalation remediation.
  • Experience integrating Active Directory with Linux systems, SaaS applications, or other enterprise platforms.
  • Strong understanding of EDR, endpoint security, and security monitoring solutions within Windows environments.
  • Strong documentation, communication, and cross‑functional collaboration skills.
  • Proactive problem‑solving mindset with a focus on continuous improvement.
  • Microsoft certifications such as Identity and Access Administrator Associate, Security Operations Analyst Associate, Azure Solutions Architect, or similar credentials.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Active Directory Engineer
Active Directory Engineer

Perennial Resources International • New York (NY)

On-site
USD 120,000 - 150,000
Senior Windows & Active Directory Infra Architect
Senior Windows & Active Directory Infra Architect

PRI Technology • New York (NY)

On-site
USD 120,000 - 180,000
Active Directory Architect
Active Directory Architect

Pipe Recruit • United States

On-site
USD 110,000 - 130,000
Senior Windows Engineer
Senior Windows Engineer

KTek Resourcing • Jersey City (NJ)

On-site
USD 110,000 - 140,000
Senior System Architect
Senior System Architect

Sira Consulting, an Inc 5000 company • Jersey City (NJ)

On-site
USD 120,000 - 150,000
Active Directory Architect - Remote
Active Directory Architect - Remote

Covetus • Texas City (TX)

On-site
USD 100,000 - 130,000
Active Directory Architect
Active Directory Architect

Devcare Solutions • United States

Hybrid
USD 120,000 - 160,000
Active Directory Architect
Active Directory Architect

Clark Davis Associates • Morristown (NJ)

On-site
USD 150,000 - 160,000
Medical insurance
401(k)
Active Directory Specialist
Active Directory Specialist

Compunnel, Inc. • Richmond (VA)

On-site
USD 100,000 - 130,000
AD Security & Authentication Engineer
AD Security & Authentication Engineer

Cloudicagroup • United States

Remote
USD 100,000 - 130,000
Opportunity to work with modern technologies
Training and development in Microsoft solutions
Sports package and private medical care