Sr. Systems Engineer (Active Directory)

BerkleyWilmington, DE

About The Position

The Sr. Systems Engineer (Active Directory) is an experienced Active Directory specialist responsible for designing, implementing, and managing the enterprise-wide Active Directory / Entra Hybrid infrastructure. This is a highly technical, senior-level position requiring expertise in AD architecture, security best practices, and automation. The ideal candidate will be a subject matter expert in AD technologies with a proven track record of designing scalable, secure, and resilient AD solutions for complex environments. Experience with Active Directory Integrated DNS and Domain Controller administration is essential. This position is part of the Platform Identity Management team, focusing on owning Active Directory as a Source of Truth (SOT) for Identity. The team also manages Entra and Auth0 identity services, AD CS PKI, and Identity authentication/authorization.

Requirements

  • Extensive, hands-on experience in designing, implementing, and managing large, complex, multi-forest Active Directory environments (Minimum 5 years of experience).
  • Deep expertise in AD components such as DNS, DC, GPOs, Sites and Services, and trusts.
  • Proven experience implementing, configuring, and managing Netwrix Directory Manager (NDM) (or similar products) to provide a policy-based delegated AD administration and governance model within a least-privileged security framework.
  • In-depth knowledge of Windows Server operating systems (2016, 2019, 2022, 2025) and their roles within an enterprise environment.
  • Strong understanding of AD security best practices, including privileged access management (PAM), role-based access control (RBAC), and security hardening techniques.
  • Ability to integrate Active Directory with IAM solutions aligned with Zero Trust, identity governance, and adaptive authentication concepts.
  • Excellent written and verbal communication skills, with the ability to document and convey complex technical concepts to both technical and non-technical audiences.
  • Experience with disaster recovery and business continuity planning for AD and its role within the organization's technology stacks.
  • Demonstrate comfort using AI-assisted tools in a professional context; approach AI as a standard part of modern workflow rather than a specialized or optional capability.
  • Bachelor’s degree in Computer Science, Information Technology, Information Systems, or a related discipline. Equivalent experience and/or alternative qualifications will be considered.

Nice To Haves

  • Previous experience with server hardening within an AD environment is preferred.
  • Previous experience with Okta/Auth0, Microsoft Entra ID, MFA, LDAPS preferred.

Responsibilities

  • Serve as the enterprise subject matter expert (SME) for Active Directory architectural designs, ensuring they align with business needs and security requirements.
  • Develop, implement, and maintain the AD architecture, including forests, domains, organizational units (OUs), and Group Policies (GPOs).
  • Perform advanced troubleshooting and root cause analysis for complex AD infrastructure issues, including replication, DNS, and authentication.
  • Utilize DevOps and Platform Engineering principles to support the automation of administrative tasks across the Active Directory and Entra environment.
  • Ensure critical AD roles and Entra Identity services have health monitoring and alerting.
  • Ensure the security of the AD environment by implementing best practices for authentication, authorization, and auditing.
  • Perform periodic Domain Controller security hardening.
  • Develop and maintain comprehensive documentation, including architectural designs, configuration standards, and standard operating procedures (SOPs).
  • Lead projects, working directly with Project Management, Account Management, and Customer teams.
  • Collaborate and consult with other Berkley Technology Services teams, including security, networking, and application development to ensure seamless integration and operational efficiency.
  • Mentor and cross-train technical staff, peers, and subordinate team members in AD/IAM technologies and best practices.
  • Participate and adhere to defined ITIL standards for incident, request, and change management.
  • Participate in an on-call rotation as part of the Platform Identity Management Team.

Benefits

  • Health
  • Dental
  • Vision
  • Life
  • Disability
  • Wellness
  • Paid Time Off
  • 401(k)
  • Profit-Sharing plans
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service