Sr. System Engineer - Active Directory Infrastructure
San Diego, San Diego County, California, 92189, USA
Listed on 2026-10-02
-
IT/Tech
Windows Server, Systems Administrator, Cybersecurity, Disaster Recovery IT
Job Category: Information Technology
Requisition Number: SRSYS
002311
Full-Time
LocationsShowing 1 location
Remote
DescriptionCPI is seeking a Senior Systems Engineer – Active Directory & Infrastructure to join our three-person infrastructure team. This remote position is a hands‑on senior role and the primary technical owner for Microsoft Active Directory Domain Services (AD DS), Group Policy, hybrid identity, and Windows patching.
The successful candidate will have deep experience with enterprise Active Directory and Windows environments and will lead efforts involving AD consolidation, directory and Group Policy cleanup and maintenance, security hardening, lifecycle management, and patching. The role also provides cross-functional backup for virtualization, compute, storage, backup, and other infrastructure platforms.
U.S. Citizenship is required. Candidates requiring employment authorization through an EAD, visa, or other non-citizen work authorization are not eligible for consideration.
Primary Responsibilities
- Serve as the primary administrator and technical SME for Microsoft Active Directory Domain Services (AD DS), in a multi-forest, multi-domain, and multi-tenant environment.
- Design, implement, maintain, troubleshoot, and optimize Group Policy Objects (GPOs), security/WMI filtering, and policy performance.
- Lead Active Directory consolidation, cleanup, restructuring, and modernization, including remediation of stale accounts/objects, legacy configurations, unnecessary policies, excessive privileges, and other directory complexity.
- Administer and support Microsoft Entra hybrid identity, including directory synchronization and authentication/authorization across on-premises and cloud environments.
- Troubleshoot complex AD, Group Policy, DNS, Kerberos, NTLM, certificates, authentication, authorization, and replication issues.
- Own and improve Windows Server and endpoint patching, using MECM/Configuration Manager and Intune including patch planning, deployment, compliance reporting, troubleshooting failed updates, and remediation of vulnerable or unsupported systems.
- Provide senior-level backup and troubleshooting support for VMware compute/virtualization, Net App storage, Rubrik backup and recovery, and related infrastructure.
- Work with security and infrastructure teams on AD security hardening, privileged access, least privilege, vulnerability remediation, disaster recovery, and business continuity.
Required Qualifications & Technical Skills
- U.S . Citizenship is required. Candidates requiring employment authorization through an EAD, visa, or other non-citizen work authorization are not eligible for consideration.
- Advanced knowledge of AD with strong hands‑on experience administering and troubleshooting multi‑forest/domain/tenant environments
- Experience with AD consolidation, migration, cleanup, restructuring, or modernization.
- Advanced Windows Server administration and troubleshooting experience.
- Strong experience with Windows patch management, vulnerability remediation, and systems lifecycle management leveraging MECM/Configuration Manager and/or Intune.
- Strong Power Shell scripting and automation skills.
- Hands‑on experience with Microsoft Entra , hybrid identity, and directory synchronization.
- Working knowledge of Kerberos, NTLM, SAML, OAuth/OIDC, AD CS, DNS, DHCP, and networking dependencies.
- Ability to troubleshoot across infrastructure layers and work independently in a small, collaborative infrastructure team.
- Strong documentation, communication, troubleshooting, and root‑cause analysis skills.
- Security and Compliance perspective, NIST 800-43, 171, CMMC, CUI, ITAR, ECI
Preferred Qualifications
- Bachelor's degree in Computer Science, Information Technology, or similar.
- Experience with Active Directory…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).