Sr. Systems Engineer (Active Directory)
Berkley Technology Services · Wilmington, Delaware, United States · 1 wk ago
$107k–$198k/yrFull-time
Responsibilities
- Serve as the enterprise subject matter expert (SME) for Active Directory architectural designs, ensuring they align with business needs and security requirements.
- Develop, implement, and maintain the AD architecture, including forests, domains, organizational units (OUs), and Group Policies (GPOs).
- Perform advanced troubleshooting and root cause analysis for complex AD infrastructure issues, including replication, DNS, and authentication.
- Utilize DevOps and Platform Engineering principles to support the automation of administrative tasks across the Active Directory and Entra environment.
- Ensure critical AD roles and Entra Identity services have health monitoring and alerting.
- Ensure the security of the AD environment by implementing best practices for authentication, authorization, and auditing.
- Perform periodic Domain Controller security hardening.
- Develop and maintain comprehensive documentation, including architectural designs, configuration standards, and standard operating procedures (SOPs).
- Lead projects, working directly with Project Management, Account Management, and Customer teams.
- Collaborate and consult with other Berkley Technology Services teams, including security, networking, and application development to ensure seamless integration and operational efficiency.
- Mentor and cross-train technical staff, peers, and subordinate team members in AD/IAM technologies and best practices.
- Participate and adhere to defined ITIL standards for incident, request, and change management.
- On Call Rotation (PIC) is required as part of the Platform Identity Management Team.
Qualifications
- Extensive, hands-on experience in designing, implementing, and managing large, complex, multi-forest Active Directory environments (Minimum 5 years of experience).
- Deep expertise in AD components such as DNS, DC, GPOs, Sites and Services, and trusts.
- Proven experience implementing, configuring, and managing Netwrix Directory Manager (NDM) (or similar products) to provide a policy-based delegated AD administration and governance model within a least-privilege security framework.
- In-depth knowledge of Windows Server operating systems (2016, 2019, 2022, 2025) and their roles within an enterprise environment.
- Strong understanding of AD security best practices, including privileged access management (PAM), role-based access control (RBAC), and security hardening techniques.
- Previous experience with server hardening within an AD environment is preferred.
- Ability to integrate Active Directory with IAM solutions aligned with Zero Trust, identity governance, and adaptive authentication concepts.
- Previous experience with Okta/Auth0, Microsoft Entra ID, MFA, LDAPS preferred.
- Excellent written and verbal communication skills, with the ability to document and convey complex technical concepts to both technical and non-technical audiences.
- Experience with disaster recovery and business continuity planning for AD and its role within the organization's technology stacks.
- Demonstrate comfort using AI-assisted tools in a professional context; approach AI as a standard part of modern workflow rather than a specialized or optional capability.
Education Requirement
- Bachelor’s degree in Computer Science, Information Technology, Information Systems, or a related discipline.