Active Directory Engineer - Tier 3

Career PathsWestborough, MA

About The Position

eClinicalWorks is seeking an experienced Active Directory / Microsoft Entra ID Engineer to support and enhance our global identity infrastructure. This role is responsible for the administration, security, and optimization of enterprise Active Directory and Microsoft Entra ID environments supporting both corporate operations and production healthcare platforms. The engineer will manage user, service, and privileged accounts, Group Policy administration, authentication services, hybrid identity, and access governance across a large-scale infrastructure. The ideal candidate will possess deep expertise in Active Directory architecture, enterprise Group Policy management, Microsoft Entra ID, and identity security within a highly available production environment.

Requirements

  • 5+ years of experience in Enterprise Active Directory administration experience.
  • Strong experience with Group Policy design, troubleshooting, and governance.
  • Experience managing large global Active Directory environments.
  • Expert knowledge of Active Directory replication, DNS, trusts, and authentication.
  • Strong PowerShell scripting and automation skills.
  • Experience with identity security, privileged access, and access management.
  • Strong troubleshooting, communication, and documentation skills.

Nice To Haves

  • Experience supporting healthcare or regulated environments is highly preferred
  • Experience with Microsoft Defender for Identity is highly preferred
  • Experience with Conditional Access, Identity Governance, and PAM solutions is highly preferred
  • Microsoft identity and Azure certifications.
  • Experience supporting cloud and hybrid infrastructure environments is highly preferred

Responsibilities

  • Administer and support large-scale Active Directory and Microsoft Entra ID environments.
  • Manage corporate, production, service, and privileged administrative accounts.
  • Design, deploy, and maintain enterprise Group Policy Objects (GPOs)
  • Support hybrid identity solutions including Microsoft Entra Connect.
  • Troubleshoot authentication, replication, DNS, LDAP, Kerberos, and Group Policy issues.
  • Manage Active Directory domains, forests, trusts, sites, and services.
  • Implement identity security best practices, including MFA and Conditional Access
  • Develop PowerShell automation for provisioning, reporting, and administration.
  • Participate in major incident response and on-call support.
  • Maintain identity standards, documentation, and operational procedures.

Benefits

  • competitive salary and benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service