Windows/Active Directory Security Lead

PRI Technology

New York (NY)

On-site

USD 286,541,000 - 315,195,000

Full time

5 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

PRI Technology seeks a seasoned Windows/Active Directory Lead for a long-term contract to support and modernize a large-scale Microsoft infrastructure for a top-tier financial services firm. The role is part of a managed systems engineering team ensuring 24/7 availability of compute infrastructure worldwide.

The ideal candidate will architect, secure, and automate AD environments, implement MFA and LAPS, and advance security posture across a complex distributed Windows landscape.

Qualifications

  • 7+ years of experience architecting, administering, and securing Active Directory in large enterprise environments.
  • Strong expertise in Active Directory, Group Policy, DNS, DHCP, and Windows Server administration.
  • Experience in CyberArk PAM.
  • Hands-on experience implementing Active Directory security controls and hardening initiatives.
  • Experience deploying and managing Windows Local Administrator Password Solution.
  • Experience implementing and supporting MFA for key systems.
  • Experience with Credential Guard and other credential theft mitigation solutions.
  • Strong understanding of identity lifecycle management and authentication protocols (Kerberos/NTLM).

Responsibilities

  • Design, administer, secure, and support large-scale Active Directory environments (forests, domains, trusts, replication, privileged access).
  • Manage core Microsoft infrastructure services: AD, Group Policy, DNS, DHCP, Windows Server.
  • Support modernization of enterprise identity and authentication services across dev and prod.
  • Implement and maintain AD security controls, hardening, and remediation efforts.
  • Deploy and manage LAPS and other privileged access security tools.
  • Support MFA implementations for critical systems.
  • Deploy and manage Windows security features like Credential Guard.
  • Assess AD environments for risks, misconfigurations, and privilege escalation.
  • Apply least-privilege principles and administrative tiering; secure workstations.
  • Automate tasks, reporting, and operations with PowerShell.
  • Collaborate with security, compliance, and infra teams for auditing and governance.
  • Create and maintain clear technical docs and standards.

Skills

Active Directory
Group Policy
DNS
DHCP
Windows Server
CyberArk PAM
MFA
Credential Guard
PowerShell
Automation
Identity lifecycle
Kerberos/NTLM

Education

Bachelor's degree in CS/Engineering

Job description

I have a long term contract for a Windows / Active Directory Lead to support and modernize a large-scale, mission-critical Microsoft infrastructure environment for one of our top tier financial services firms.

This role is part of a managed systems engineering team responsible for maintaining highly available compute infrastructure that supports global business operations 24/7.

This role is onsite 4 days a week.

$100-$110/hr

The ideal candidate will have deep hands-on experience with Active Directory architecture, security, administration, automation, and infrastructure hardening in a large enterprise environment. This position will play a key role in strengthening identity services, improving reliability, enhancing security posture, and supporting the continued evolution of Windows services across a complex distributed environment.

Responsibilities:

  • Design, administer, secure, and support large-scale Active Directory environments, including forests, domains, trusts, replication strategies, and privileged access models.
  • Manage and enhance core Microsoft infrastructure services including Active Directory, Group Policy, DNS, DHCP, and Windows Server platforms.
  • Support modernization efforts for enterprise identity and authentication services across development and production environments.
  • Implement and maintain Active Directory security controls, hardening initiatives, and vulnerability remediation efforts.
  • Deploy and manage Windows Local Administrator Password Solution and other privileged access security tools.
  • Support MFA implementation for critical systems and privileged access workflows.
  • Deploy and manage Windows security features such as Credential Guard and other credential theft mitigation technologies.
  • Assess Active Directory environments for security risks, misconfigurations, and privilege escalation paths.
  • Apply least-privilege principles, administrative tiering models, privileged access management practices, and secure workstation strategies.
  • Automate administrative tasks, reporting, and operational processes using PowerShe
  • ll.Partner with security, compliance, and infrastructure teams to support auditing, governance, and regulatory requirements.
  • Create and maintain clear technical documentation, operational procedures, and infrastructure standards.

Qualifications:

  • 7+ years of experience architecting, administering, and securing Active Directory in large enterprise environments.
  • Strong expertise in Active Directory, Group Policy, DNS, DHCP, and Windows Server administration.
  • Experience in CyberArk PAM
  • Hands-on experience implementing Active Directory security controls and hardening initiatives.
  • Experience deploying and managing Windows Local Administrator Password Solution.
  • Experience implementing and supporting MFA for key systems.
  • Experience with Windows security technologies such as Credential Guard and other credential theft mitigation solutions.
  • Strong understanding of identity lifecycle management, authentication protocols including Kerberos and NTLM, and access control models.
  • Proven experience designing and implementing AD forests, domains, trusts, replication, and privileged access models.
  • Knowledge of Active Directory tiering, privileged access management, administrative workstation strategies, and least-privilege practices.
  • Experience identifying and remediating Active Directory vulnerabilities and misconfigurations.
  • Strong PowerShell scripting and automation skills.
  • Experience working in regulated environments with a focus on compliance, auditing, and security governance.
  • Bachelor’s degree in Computer Science, Engineering, Mathematics, a related field, or equivalent professional experience.

Preferred Qualifications:

  • Familiarity with Active Directory security assessment tools, attack path analysis, and privilege escalation remediation.
  • Experience integrating Active Directory with Linux systems, SaaS applications, or other enterprise platforms.
  • Strong understanding of EDR, endpoint security, and security monitoring solutions within Windows environments.
  • Strong documentation, communication, and cross-functional collaboration skills.
  • Proactive problem-solving mindset with a focus on continuous improvement.
  • Microsoft certifications such as Identity and Access Administrator Associate, Security Operations Analyst Associate, Azure Solutions Architect, or similar credentials.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Active Directory Engineer
Active Directory Engineer

Perennial Resources International • New York (NY)

On-site
USD 120,000 - 150,000
AD Security & Authentication Engineer
AD Security & Authentication Engineer

Cloudicagroup • United States

Remote
USD 100,000 - 130,000
Opportunity to work with modern technologies
Training and development in Microsoft solutions
Sports package and private medical care
Senior Windows Systems & Active Directory Administrator
Senior Windows Systems & Active Directory Administrator

Blue Star Partners LLC • Columbus (OH)

Hybrid
10% bonus
Hybrid work model
Parking available on-site
Active Directory Architect
Active Directory Architect

Pipe Recruit • United States

On-site
USD 110,000 - 130,000
Senior Windows Engineer
Senior Windows Engineer

KTek Resourcing • Jersey City (NJ)

On-site
USD 110,000 - 140,000
Active Directory Architect
Active Directory Architect

Clark Davis Associates • Morristown (NJ)

On-site
USD 150,000 - 160,000
Medical insurance
401(k)
Sr Active Directory Engineer
Sr Active Directory Engineer

Revel IT • Houston (TX)

Hybrid
USD 120,000 - 170,000
Hybrid work model
Senior Automation Developer
Senior Automation Developer

XMS Solutions • Washington

On-site
USD 140,000 - 170,000
Senior Active Directory & Entra ID Engineer
Senior Active Directory & Entra ID Engineer

Noblesoft Solutions • Saint Petersburg (FL)

Hybrid
USD 90,000 - 140,000
Active Directory Specialist
Active Directory Specialist

Compunnel, Inc. • Richmond (VA)

On-site
USD 100,000 - 130,000