About The Position

This role is responsible for designing, building, and maintaining automation frameworks that implement security-driven configuration changes across Windows servers, workstations, and Active Directory infrastructure in response to CVEs and emergent threats. The engineer translates security intent into repeatable automated tasks that can be deployed safely at scale. They partner closely with cybersecurity teams to operationalize advisories and with AD platform teams to ensure changes align with enterprise standards.

Requirements

  • Active Directory (Expert level)
  • Windows Server
  • GPOs
  • Powershell (Advanced)
  • Group Policy internals and management tools
  • Windows Server and Windows client internals
  • Active Directory schema, security descriptors, and replication behavior
  • Configuration management (SCCM or equivalent)
  • Git-based version control and code reviews
  • GPO administration using Quest GP Admin
  • Automated systems validation testing experience

Responsibilities

  • Automating GPO creation, modification, and rollback
  • Automating Windows and application patch deployment
  • Creating AD-safe configuration enforcement workflows
  • Building guardrails that prevent unsafe or partial deployments
  • Rapidly converting CVE guidance into deployable updates within hours
  • Supporting break-glass? mitigation scenarios with pre-approved automation
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service