
Staff Engineer, Microsoft Active Directory
Posted Aug 5

Posted Aug 5
This is a fully remote position, open to applicants in India.
• Design, manage, and enhance enterprise environments for Microsoft Active Directory and Microsoft Entra ID.
• Oversee Domain Controllers, Active Directory replication, FSMO roles, trusts, schema, NTDS, DFSR, and AD Sites & Services.
• Implement, maintain, and secure Group Policy (GPO) frameworks across enterprise settings.
• Administer core identity infrastructure services including Windows Server, DNS, DHCP, and IIS.
• Create and enforce policies for Conditional Access, MFA, SSO, RBAC, PIM, and identity governance.
• Manage Hybrid Identity through Microsoft Entra Connect (Azure AD Connect) to ensure directory synchronization is seamless.
• Oversee Microsoft 365 identity services, Exchange Online, and Hybrid Exchange environments.
• Manage mail flow, connectors, authentication protocols, and compliance-related identity configurations.
• Develop and maintain PowerShell automation scripts while utilizing Microsoft Graph API for administration and reporting.
• Lead initiatives for Active Directory upgrades, migrations, consolidations, backup, recovery, and disaster recovery.
• Troubleshoot and resolve intricate authentication challenges involving OAuth, SAML, Kerberos, and NTLM.
• Conduct root cause analysis for critical production incidents and implement preventive measures.
• Collaborate with cloud, infrastructure, and security teams to enhance enterprise identity services.
• Monitor identity security posture, ensure compliance, and continuously refine identity management processes and automation.
• Total experience: 5.5+ years.
• Extensive experience in Microsoft Active Directory administration across enterprise, multi-site environments.
• Must possess expertise in Microsoft Entra ID (Azure AD) administration and Hybrid Identity (Entra Connect/AD Connect).
• Significant experience managing Domain Controllers, AD Replication, FSMO Roles, Schema, Trusts, NTDS, DFSR, and AD Sites & Services.
• Practical experience with Windows Server (2012–2022+), DNS, DHCP, IIS, and Group Policy (GPO) administration.
• Experience in designing and implementing Conditional Access, SSO, MFA, RBAC, PIM, and Identity Lifecycle Management.
• Strong understanding of Microsoft 365 identity services, Exchange Online, and Hybrid Exchange administration.
• Experience managing mail flow, connectors, SPF, DKIM, DMARC, licensing, and directory synchronization.
• Hands-on experience in troubleshooting OAuth, SAML, Kerberos, and NTLM authentication issues.
• Proficient in scripting with PowerShell and automation utilizing Microsoft Graph API.
• Experience in Active Directory migrations, upgrades, consolidations, backup, disaster recovery, and high availability.
• Good knowledge of identity security, IAM best practices, compliance, and enterprise authentication.
• Experience with Active Directory administration and migration tools such as Quest is preferred.
• Strong analytical, troubleshooting, communication, and stakeholder management skills.
• Bachelor’s or master’s degree in computer science, Information Technology, or a related field.
• Competitive salary and performance bonuses.
• Comprehensive health insurance and wellness programs.
• Opportunities for professional development and certifications.
• Flexible work hours and remote work options.
• Supportive and inclusive company culture.
Travoom
EverCommerce
Cisco
Pluribus Digital
Get handpicked remote jobs straight to your inbox weekly.