L3 Active Directory Engineer / AD SME
E-Solutions
Position:1
Job Description: L3 Engineer / SME - Active Directory (On-Premise)
Role Title: L3 Active Directory Engineer / AD SME
Experience: 12+ years
Domain: Identity & Access Management, Windows Infrastructure Role Summary
We are looking for a highly skilled L3 Active Directory (On-Premise) SME with deep experience in designing, managing, and troubleshooting complex AD environments. The candidate will be the highest escalation point for AD issues, lead architectural improvements, perform RCA, and ensure AD security, availability, and performance in a large enterprise environment. Key Responsibilities
1. L3 Escalation & Technical Support
Serve as the top-tier escalation for Active Directory and Windows infrastructure issues.
Troubleshoot complex authentication, replication, DNS, GPO, policy processing, and trust issues.
Perform advanced RCA, log analysis, and performance debugging.
Develop L3 SOPs, KB articles, scripts, and automation for operations teams. 2. Active Directory Administration & Architecture
Manage and maintain large multi-domain, multi-forest on-prem AD environments.
Oversee FSMO roles, domain controllers (DC health), AD sites, replication topology.
Install, upgrade, and harden domain controllers (physical/virtual).
Implement AD schema updates, forest/domain functional level upgrades.
Perform AD migration, consolidation, restructuring, and domain/forest trust design. 3. DNS, DHCP, & Windows Core Infrastructure
Troubleshoot AD-integrated DNS issues (zones, scavenging, forwarding, delegation).
Manage and secure DHCP scopes, reservations, failover.
Deep understanding of Kerberos, NTLM, LDAP, LDAPS, SPNs, tickets, token bloat.
Ensure GPO performance tuning, inheritance control, WMI filters, controlled rollouts. 4 . Security & Hardening
Implement AD security baselines, CIS benchmarks, and Microsoft security best practices.
Periodically audit domain controllers, replication, delegations, privileged groups.
Manage tiered admin model, least privilege, Just-In-Time (JIT) & Just-Enough-Administration (JEA).
Enforce password policies, PAM/Privileged Identity controls, and secure service account management.
Perform logs and event analysis through SIEM (Splunk, Sentinel, QRadar). 5. High Availability & DR
Build and validate disaster recovery procedures for AD, DNS, and DHCP.
Maintain backup/restore strategies using tools like AD Recycle Bin, Authoritative Restore, System State, VM snapshots.
Ensure site resiliency, replication health, and multi-site availability. 6. Automation & Scripting
Automate AD operations using PowerShell (mandatory).
Build scripts for:
User provisioning/deprovisioning
Group management
GPO backup/restore
ACL/permissions
Health monitoring & reporting 7. Integration & Identity Services
Expertise integrating AD with:
ADFS
Azure AD Connect (Sync rules, writeback, filtering)
SSO solutions
LDAP-based applications
PKI/Certification Services Understand hybrid identity dependencies (even though this role is on-prem focused). Required Skills & Qualifications 7-12+ years hands-on experience in enterprise Active Directory environments.
Deep knowledge of: AD architecture, design & security
DNS, DHCP, Sites & Services
Kerberos, LDAP, GPO, trusts, replication Experience troubleshooting large distributed Windows Server infrastructures.
Strong PowerShell automation skills.
Experience implementing AD hardening, security baselines, RBAC delegation.
Knowledge of backup/restore and DR strategies for domain controllers.
Strong understanding of networking fundamentals (TCP/IP, firewall rules, ports). Preferred Skills
Microsoft certifications (AZ-800, AZ-801, MS-100/101, SC-300, MCSA/MCSE).
Experience with Azure AD and hybrid identity models.
Experience with IAM/PAM tools (Delinea, CyberArk, BeyondTrust).
Familiarity with virtualization (VMware/Hyper-V).
Experience with enterprise SIEM and security monitoring tools.
Job Description: L3 Engineer / SME - Active Directory (On-Premise)
Role Title: L3 Active Directory Engineer / AD SME
Experience: 12+ years
Domain: Identity & Access Management, Windows Infrastructure Role Summary
We are looking for a highly skilled L3 Active Directory (On-Premise) SME with deep experience in designing, managing, and troubleshooting complex AD environments. The candidate will be the highest escalation point for AD issues, lead architectural improvements, perform RCA, and ensure AD security, availability, and performance in a large enterprise environment. Key Responsibilities
1. L3 Escalation & Technical Support
Serve as the top-tier escalation for Active Directory and Windows infrastructure issues.
Troubleshoot complex authentication, replication, DNS, GPO, policy processing, and trust issues.
Perform advanced RCA, log analysis, and performance debugging.
Develop L3 SOPs, KB articles, scripts, and automation for operations teams. 2. Active Directory Administration & Architecture
Manage and maintain large multi-domain, multi-forest on-prem AD environments.
Oversee FSMO roles, domain controllers (DC health), AD sites, replication topology.
Install, upgrade, and harden domain controllers (physical/virtual).
Implement AD schema updates, forest/domain functional level upgrades.
Perform AD migration, consolidation, restructuring, and domain/forest trust design. 3. DNS, DHCP, & Windows Core Infrastructure
Troubleshoot AD-integrated DNS issues (zones, scavenging, forwarding, delegation).
Manage and secure DHCP scopes, reservations, failover.
Deep understanding of Kerberos, NTLM, LDAP, LDAPS, SPNs, tickets, token bloat.
Ensure GPO performance tuning, inheritance control, WMI filters, controlled rollouts. 4 . Security & Hardening
Implement AD security baselines, CIS benchmarks, and Microsoft security best practices.
Periodically audit domain controllers, replication, delegations, privileged groups.
Manage tiered admin model, least privilege, Just-In-Time (JIT) & Just-Enough-Administration (JEA).
Enforce password policies, PAM/Privileged Identity controls, and secure service account management.
Perform logs and event analysis through SIEM (Splunk, Sentinel, QRadar). 5. High Availability & DR
Build and validate disaster recovery procedures for AD, DNS, and DHCP.
Maintain backup/restore strategies using tools like AD Recycle Bin, Authoritative Restore, System State, VM snapshots.
Ensure site resiliency, replication health, and multi-site availability. 6. Automation & Scripting
Automate AD operations using PowerShell (mandatory).
Build scripts for:
User provisioning/deprovisioning
Group management
GPO backup/restore
ACL/permissions
Health monitoring & reporting 7. Integration & Identity Services
Expertise integrating AD with:
ADFS
Azure AD Connect (Sync rules, writeback, filtering)
SSO solutions
LDAP-based applications
PKI/Certification Services Understand hybrid identity dependencies (even though this role is on-prem focused). Required Skills & Qualifications 7-12+ years hands-on experience in enterprise Active Directory environments.
Deep knowledge of: AD architecture, design & security
DNS, DHCP, Sites & Services
Kerberos, LDAP, GPO, trusts, replication Experience troubleshooting large distributed Windows Server infrastructures.
Strong PowerShell automation skills.
Experience implementing AD hardening, security baselines, RBAC delegation.
Knowledge of backup/restore and DR strategies for domain controllers.
Strong understanding of networking fundamentals (TCP/IP, firewall rules, ports). Preferred Skills
Microsoft certifications (AZ-800, AZ-801, MS-100/101, SC-300, MCSA/MCSE).
Experience with Azure AD and hybrid identity models.
Experience with IAM/PAM tools (Delinea, CyberArk, BeyondTrust).
Familiarity with virtualization (VMware/Hyper-V).
Experience with enterprise SIEM and security monitoring tools.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the L3 Active Directory Engineer / AD SME in San Francisco, CA vacancy
- Systems Engineer/L3 Support with Retail Industry Contract •Advanced level of server, desktop and remote support knowledge. This experience... ...of the following: Windows Server (2000, 2003, 2008), Active Directory, and other third party software and tools (Altiris, Ghost, Anti...SuggestedContract workRemote work
- ...solutions firm based in San Francisco is seeking a motivated Systems Engineer to provide advanced server, desktop, and remote support.... ...possess significant experience with Windows Server and Active Directory and have a strong understanding of enterprise network infrastructure...SuggestedRemote work
- ...Systems Engineer Atlas Technica's mission is to shoulder IT management, user support,... ...Online, SharePoint Online, Intune, Azure AD) ~ Systems Administration: Knowledge of... ...Windows Server Platforms as well as Active Directory, Group Policy, good if you are familiar...SuggestedWork at office
$140k - $160k
...Senior Infrastructure Engineer - IAM & Automation At Polsinelli, What a Law Firm Should... ...Access controls through Okta and Entra/Active Directory. Create, support, and maintain Okta configurations... ...filters, exception handling, and AD extension attributes. Assist in the...SuggestedFull timeTemporary workPart timeRemote workFlexible hoursShift work$167.25k - $216k
Virta Health is looking for a Senior Software Engineer in Denver, CO, to drive the activation process for members. You will tackle complex projects, design scalable backend systems, and collaborate closely with product and operations teams. Ideal candidates have at least...SuggestedRemote work- ...&T) - Credit Risk Management SME Services within Mastercard... ...experience. We provide value-added services and leverage... ...and slides. Passion: Actively seeks responsibility and takes... ...Statistics, Mathematics, or Engineering Credit risk management...Full timePart timeWork at officeLocal areaWorldwideFlexible hours
- ...solutions provider in South San Francisco is seeking a Systems Engineer to provide advanced technical support for complex hardware,... ...strong background in IT support with a focus on Windows Server, Active Directory, and cloud environments. Responsibilities include...
- ...Linux Systems Engineer Locations: Owings Mills, MD 21117 OR Baltimore, MD 21202 OR Philadelphia... .... Primary skills: Fluent in Linux / Active Directory and Kerberos / Developer tooling /... ...Linux really well to diagnose kerberos, AD or NFS issues and you need to know developer...For contractors
$184k - $230k
...employment Visa sponsorship. Overall Purpose As a Principal Engineer in the Identity and Access Management (IAM) team, you will... ...access management platforms, privileged access management, active directory, and network protocols, you will contribute to the...Hourly payFor contractorsWork experience placementWork at officeImmediate startVisa sponsorshipWork visaFlexible hours- ...to take on a dynamic role in the heart of San Francisco? We are seeking a talented individual to lead our co-marketing activation efforts within the Ads New Ventures team. This position offers the opportunity to work at the intersection of marketing, sales, and creative...
- ...Job Title: Co-Marketing Activation Lead Ads New Ventures CW Duration: 06-month contract Work Location: San Francisco, CA Pay Rate: $60/hr - $65/hr. on w2. Job ID: #26-16857 Role Overview This role sits within the Ads New Ventures team and serves...Contract work
$42 - $52 per hour
...About the role: As Controls & Automation Engineer, you will own advanced technical support... ...when required Support field service activities within your local region for both reactive... ...experiences that are clear, fast, value-added, and outcome-driven. You don’t say “not...Full timeTemporary workLocal areaRemote workHome officeFlexible hoursShift work$194k - $243k
...talk. We are seeking an experienced Staff Software Engineer to join Okta's Universal Directory Platform team within the Product Platform Pillar. The... ...PostgreSQL, Docker and Kubernetes. Experience working with Active Directory or Microsoft Azure. P17918_3419596 #LI-...Work at officeLocal areaWorldwideFlexible hours2 days per week$216.7k - $303.4k
Tensec is seeking a Machine Learning Engineer to join the Ads team in San Francisco. In this role, you will design, build, and deploy machine learning models that enhance advertising effectiveness, influencing ad ranking and bidding processes. Ideal candidates should have...$60k - $80k
Samba TV, Inc. is hiring a Campaign Activation Analyst in San Francisco, California. This role is essential for activating audience segments across various platforms and ensuring the effective execution of programmatic campaigns. Ideal candidates should be detail-oriented...- ...Field Service Engineer Your mission as the Field Service Engineer is to provide expert... ...Service Manager. Conduct planned and ad hoc visits to inspect, service, troubleshoot... ..., ensure safety compliance, and document activities. Be the on-site contact, providing service...Remote workNight shiftWeekend workAfternoon shift
- ...to dive deep. We call this role a Cloud Service Reliability Engineer. The Cloud Service Reliability Engineer will be responsible... ...as a Code(Terraform, Ansible) experience Expertise in Active Directory Domain Services, Active Directory Federation Services (ADFS),...
$156.5k - $235k
...deepening customer engagement and loyalty, activating new partnerships, and maximizing the... ...Kafka) where appropriate. Use workflow engines such as Temporal and Cadence to orchestrate... ...Ordinance. We use automated decision systems (ADS) as part of our recruitment and hiring...Work at officeWork from homeFlexible hoursShift workNight shift$95k - $125k
...Townsend Heery exceeds client expectations — adding value, best practice and expertise at... ...an ambitious and self-starting Project Engineer to support K-12 and public sector... ...procedures, and deliverables for all reporting activities for assigned delivery team. Ensure...Full timeFor contractorsFor subcontractor$196k - $220.5k
I did my part and supported the Regular Toilet is seeking a Senior Software Engineer for their Ads team in San Francisco. This role focuses on innovative ad products that enhance user engagement and revenue growth. The ideal candidate will have a strong technical background...Relocation package$192.2k - $260k
...a multi-disciplinary team of scientists, engineers, and technicians, on a mission to develop... ...design software. - Empower scientists to actively contribute to the codebase through... ...dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life...Permanent employmentLocal areaFlexible hours$99k - $121k
...Engineer II - Privileged Access Management At Early Warning, we've powered and protected the U.S. financial system for over thirty... ...PKI / certificate management ~ Experience administering Active Directory service accounts. Working knowledge of: RBAC and...Hourly payImmediate startVisa sponsorshipWork visaFlexible hours$103.76k - $118.77k
...System Engineer Daly City, CA 94014 Overview Salary Range $103,760.80 - $118,768.00 Description The Systems Engineer... ...system infrastructure including but not limited to Microsoft Active Directory, Microsoft Exchange, VMWare ESX, Citrix XenApp, and enterprise...Full timeWork experience placement$75k - $90k
...Server. General knowledge of Microsoft AD, SQL DB, Windows OS, and RHEL. Ability... ...as required by government contract(s). Active Clearances are a plus but are not required... ...Networking, CAD, System Management, Network Engineering, Networking Equipment, Solution...Contract workRelocation$75k - $125k
At KPFF Consulting Engineers, we are more than just an engineering design firm. For over 60... ...needed. Collaborate and Provide Mentorship: Actively participate in cross-functional team... ...personal, family, and work challenges. Life & AD&D Insurance: Company-provided life...Temporary workFor contractorsFlexible hours$70k - $85k
The Customer Support Field Engineer helps Revvity customers enhance the productivity of their... ...Development Drive the sale of value‑added options to our customers including new service... ...Continuous Skill Development. Take an active role in developing technical skills and...Hourly payFull timeContract workTemporary workPart timeLocal areaLong distanceNight shift- ...PAM/CyberArk Engineer They are seeking a hands-on Information Security Engineer with strong expertise in Identity and Access... ...Preferred Qualifications Experience with: Active Directory (AD) Federation tools (e.g., Ping, Okta) Familiarity with...Weekday work
$105k - $131.33k
...not just talking about the future, but actively shaping it? Join The AES Corporation (NYSE... ...interconnection, permitting, land, engineering, and commercial workstreams while navigating... ...environmental, and commercial teams - Integrate SME inputs into cohesive development...For contractorsWorldwide- ...team of over 50,000 planners, designers, engineers, scientists, digital innovators, program... ...recruitment process and take any fraudulent hiring activity seriously. To support this commitment,... ...include medical, dental, vision, life, AD&D, disability benefits, paid time off,...Work at officeLocal areaWorldwideFlexible hours
$85.4k - $119.6k
...integrated design practice. Our architects, engineers, interior designers, consultants,... ...project engineer with more advanced technical activities. Uses appropriate technology and software... ...and accidental death & dismemberment (AD&D) insurance, short-term/long-term disability...Full timeTemporary workPart timeCasual workWork at officeShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to L3 Active Directory Engineer / AD SME. Be the first to apply!

