×
Register Here to Apply for Jobs or Post Jobs. X

Active Directory Specialist

Job in Pleasanton, Alameda County, California, 94566, USA
Listing for: HCLTech
Full Time position
Listed on 2026-07-27
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer, Systems Administrator
Salary/Wage Range or Industry Benchmark: 140000 - 210000 USD Yearly USD 140000.00 210000.00 YEAR
Job Description & How to Apply Below

Job Description:

L3 Engineer / SME – Active Directory (On‑Premise)

Experience:

10+ years

Domain:
Identity & Access Management, Windows Infrastructure

Role Summary

We are looking for a highly skilled L3 Active Directory (On‑Premise) SME with deep experience in designing, managing, and troubleshooting complex AD environments. The candidate will be the highest escalation point for AD issues, lead architectural improvements, perform RCA, and ensure AD security, availability, and performance in a large enterprise environment.

Key Responsibilities

Serve as the top‑tier escalation for Active Directory and Windows infrastructure issues.

Troubleshoot complex authentication, replication, DNS, GPO, policy processing, and trust issues.

Perform advanced RCA, log analysis, and performance debugging.

Develop L3 SOPs, KB articles, scripts, and automation for operations teams.

2. Active Directory Administration & Architecture

Oversee FSMO roles, domain controllers (DC health), AD sites, replication topology.

Install, upgrade, and harden domain controllers (physical/virtual).

Implement AD schema updates, forest/domain functional level upgrades.

Perform AD migration, consolidation, restructuring, and domain/forest trust design.

3. DNS, DHCP, & Windows Core Infrastructure

Troubleshoot AD-integrated DNS issues (zones, scavenging, forwarding, delegation).

Manage and secure DHCP scopes, reservations, failover.

Deep understanding of Kerberos, NTLM, LDAP, LDAPS, SPNs, tickets, token bloat.

Ensure GPO performance tuning, inheritance control, WMI filters, controlled rollouts.

4. Security & Hardening

Implement AD security baselines, CIS benchmarks, and Microsoft security best practices.

Periodically audit domain controllers, replication, delegations, privileged groups.

Manage tiered admin model, least privilege, Just‑In‑Time (JIT) & Just‑Enough‑Administration (JEA).

Enforce password policies, PAM/Privileged Identity controls, and secure service account management.

Perform logs and event analysis through SIEM (Splunk, Sentinel, QRadar).

5. High Availability & DR

Build and validate disaster recovery procedures for AD, DNS, and DHCP.

Maintain backup/restore strategies using tools like AD Recycle Bin, Authoritative Restore, System State, VM snapshots.

Ensure site resiliency, replication health, and multi‑site availability.

6. Automation & Scripting

Automate AD operations using Power Shell (mandatory).

Build scripts for:

Group management

GPO backup/restore

ACL/permissions

Health monitoring & reporting

7. Integration & Identity Services

Expertise integrating AD with:

ADFS

SSO solutions

LDAP‑based applications

PKI/Certification Services

Understand hybrid identity dependencies (even though this role is on‑prem focused).

Required

Skills & Qualifications

10–12+ years hands‑on experience in enterprise Active Directory environments.

Deep knowledge of:

DNS, DHCP, Sites & Services

Kerberos, LDAP, GPO, trusts, replication

Experience implementing AD hardening, security baselines, RBAC delegation.

Knowledge of backup/restore and DR strategies for domain controllers.

Strong understanding of networking fundamentals (TCP/IP, firewall rules, ports).

Preferred Skills

Experience with Azure AD and hybrid identity models.

Experience with IAM/PAM tools (Delinea, Cyber Ark, Beyond Trust).

Familiarity with virtualization (VMware/Hyper‑V).

Experience with enterprise SIEM and security monitoring tools.

  • Design, implement, and maintain enterprise Active Directory infrastructure.
  • Manage Domain Controllers, Global Catalogs, FSMO roles, Sites and Services, and AD Replication.
  • Perform Domain Controller promotions, demotions, migrations, and health validations.
  • Troubleshoot complex AD replication, authentication, Kerberos, DNS, LDAP, and Group Policy issues.
  • Administer Active Directory objects including Users, Groups, Computers, Organizational Units (OUs), and Trusts.
  • Manage Group Policy Objects (GPOs), security baselines, and policy troubleshooting.
  • Design, deploy, and troubleshoot Group Policy Objects (GPOs) for enterprise-wide policy management.
  • Support Microsoft Entra  (Azure AD), Azure AD Connect, and Hybrid Identity environments.
  • Perform forest and domain upgrades, schema extensions, and disaster recovery…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary