Remote job
Senior Engineer, Directory Services
Job details
About this role
Role overview We are hiring a Senior Engineer to lead operations and modernization for enterprise Active Directory, certificate services, DNS, replication, and Linux integration within an Identity and Access Management team. This is a hands-on infrastructure role focused on securing, scaling, and hardening critical directory services in a large, distributed environment.
Responsibilities
- Secure, operate, and improve enterprise Active Directory services, including domain controllers, sites and services, Group Policy, authentication flows, and directory-integrated services - Harden supporting directory services such as Windows Enterprise Certificate Authority, Windows DNS, and Active Directory replication - Investigate and resolve complex identity, authentication, Kerberos, LDAP, DNS, certificate, and replication issues across Windows and Linux environments - Support and optimize secure Linux integrations with Active Directory using tools like SSSD, realmd, Samba, Kerberos, LDAP, and PAM - Partner with security, infrastructure, cloud, and application teams to strengthen monitoring, privileged access controls, operational resilience, and audit readiness - Develop standards, runbooks, automation, and security controls that reduce operational risk and improve supportability at scale
Requirements
- Deep expertise securing and managing Microsoft Active Directory in large-scale enterprise environments, including domain controllers, Group Policy, trusts, authentication, and directory-integrated services - Strong knowledge of AD hardening, authentication protocols, DNS, Kerberos, LDAP, replication, and secure configuration baselines - Experience securing and administering Windows Server environments, including DNS, Enterprise Certificate Services, and certificate lifecycle management - Proficiency integrating Linux systems with Active Directory using SSSD, realmd, Samba, Kerberos, LDAP, and PAM - Hands-on experience with automation, scripting, and security operations using PowerShell, Python, Bash, Puppet/OpenVox, incident response, monitoring, and change management
Nice to have
- Experience with hybrid identity or adjacent platforms such as Microsoft Entra ID, Okta, privileged access management, or identity governance - Experience securing Windows Enterprise Certificate Authority environments, including certificate templates, enrollment controls, lifecycle management, and risk reduction
Benefits and work setup
- Remote position; occasional in-office meetings may be required - Comprehensive benefits including medical, dental, and vision insurance, 401(k), paid time off, parental and wellness leave, life insurance, AD&D, mental health or EAP programs, holidays, tuition assistance, adoption, surrogacy, and fertility benefits, dependent daycare and backup care, an employee stock purchase plan, and financial education resources - Estimated base pay ranges from $106,500–$159,500 in most U.S. locations, with higher bands in higher-cost metros such as the SF Bay Area, Los Angeles, NYC, and Seattle; potential eligibility for bonus and equity