Identity Engineer - Active Directory
Ralliant
Identity Engineer – Active Directory
The Identity Engineer – Active Directory is responsible for administering, engineering, and optimizing Ralliant Corporation's complex, multi-domain Active Directory environment. This role serves as a hands-on technical leader across core AD infrastructure, ensuring stability, security, and scalability while supporting the broader Identity & Access Management (IAM) program.
This position operates within a multi-domain, multi-forest environment (13+ domains) with hybrid identity integration and deep dependencies across enterprise IAM systems. The engineer is expected to operate confidently across all layers of Active Directory, from object lifecycle management and Group Policy to replication topology, authentication mechanisms, and disaster recovery.
The role partners closely with Security, Infrastructure, and Compliance teams to ensure Active Directory functions as a secure and reliable foundation for enterprise identity. It contributes to identity strategy by aligning AD schema, attributes, and configurations with identity governance platforms and access lifecycle processes.
The role embraces the Ralliant Business System (RBS) by embedding operational discipline, documentation, and continuous improvement into tools, workflows, and standard work. The engineer drives repeatable, scalable processes that improve security posture, reduce operational risk, and support audit readiness across the enterprise and Operating Companies (OpCos).
Key Responsibilities
- Administer a multi-domain, multi-forest Active Directory environment including user, group, and computer object lifecycle management, OU structure, delegation models, and trust relationships
- Manage the full lifecycle of Group Policy Objects (GPOs), including design, implementation, auditing, and cleanup
- Maintain AD Sites and Services, DNS integration, subnet mappings, and replication topology
- Monitor and maintain Domain Controller health, replication status, FSMO roles, and SYSVOL/DFS-R consistency
- Manage SPNs, gMSAs, and Kerberos authentication dependencies
- Mentor and coach engineers through design reviews, code reviews, and knowledge sharing, promoting consistent and high-quality delivery.
- Maintain documentation including technical designs, workflows, configurations, and operational procedures.
- Contribute to identity strategy and roadmap planning, identifying opportunities to enhance automation, security, and user experience.
- Use PowerShell as the primary tool for data collection, reporting, bulk operations, and automation
- Develop scripts for auditing, compliance reporting, and operational health monitoring
- Build automation for infrastructure lifecycle processes such as DC replacement and recovery
- Support Active Directory integration with CyberArk for credential vaulting, rotation, and privileged session management
- Manage privileged accounts and service account credentials in alignment with PAM policies
- Collaborate on CPM dependencies, credential policies, and troubleshooting PAM-to-AD integrations
- Partner with PKI teams to ensure AD Certificate Services configurations align with enterprise standards
- Implement tiered administration models and protected group governance
Qualifications
- Bachelor's degree recommended; equivalent experience considered.
- 6 years of hands-on experience administering Active Directory in enterprise environments
- Deep expertise in AD architecture, including object management, GPOs, DNS, replication, and domain controller operations
- Advanced PowerShell scripting and automation capabilities
- Strong understanding of Kerberos, SPNs, gMSAs, and delegation models
- Experience working with CyberArk or similar PAM solutions integrated with Active Directory
- Hands-on experience with AD disaster recovery and multi-domain/multi-forest environments
- Understanding of Active Directory's role within identity governance and IAM ecosystems
- Experience collaborating with PKI teams and supporting AD-integrated certificate services
- Experience with hybrid identity environments (Entra ID / Azure AD Connect)
- Strong knowledge of AD security hardening practices and attack mitigation techniques
- Experience generating audit evidence and supporting compliance requirements
- Experience with SIEM platforms such as CrowdStrike or equivalent
- Experience supporting regulated or customer driven security requirements, including U.S. Government environments; familiarity with CMMC and NIST SP 800-171 aligned expectations preferred.
- Strong communication and documentation skills, with the ability to translate technical concepts into business impact.
- Ability to operate effectively across enterprise and OpCo environments, balancing global consistency with local context across multiple time zones and culture.
- Alignment with Ralliant values and the Ralliant Business System (RBS), including continuous improvement, transparency, and ownership.
About Us
Ralliant, originally part of Fortive, now stands as a bold, independent public company driving innovation at the forefront of precision technology. With a global footprint and a legacy of excellence, we empower engineers to bring next-generation breakthroughs to life — faster, smarter, and more reliably. Our high-performance instruments, sensors, and subsystems fuel mission-critical advancements across industries, enabling real-world impact where it matters most. At Ralliant we're building the future, together with those driven to push boundaries, solve complex problems, and leave a lasting mark on the world.
About the Team
Ralliant, originally part of Fortive, now stands as a bold, independent public company driving innovation at the forefront of precision technology. With a global footprint and a legacy of excellence, we empower engineers to bring next-generation breakthroughs to life — faster, smarter, and more reliably. Our high-performance instruments, sensors, and subsystems fuel mission-critical advancements across industries, enabling real-world impact where it matters most. At Ralliant we're building the future, together with those driven to push boundaries, solve complex problems, and leave a lasting mark on the world. We Are an Equal Opportunity Employer Ralliant Corporation and all Ralliant Companies are proud to be equal opportunity employers. We value and encourage diversity and solicit applications from all qualified applicants without regard to race, color, national origin, religion, sex, age, marital status, disability, veteran status, sexual orientation, gender identity or expression, or other characteristics protected by law. Ralliant and all Ralliant Companies are also committed to providing reasonable accommodations for applicants with disabilities. Individuals who need a reasonable accommodation because of a disability for any part of the employment application process, please contact us at View email address on click.appcast.io.
Job Info
- Job Identification 9311
- Job Category Information Security
- Locations 14150 SW Karl Braun Drive, Beaverton, OR, 97077, US 4114 Center at North Hills St. Suite 400, Raleigh, NC, 27609, US 4114 Center at North Hills St. Suite 400, Raleigh, NC, 27609, US (Hybrid)
- ...FRIEND • I AM A GIVER Touchmark is seeking a Systems Engineer to support and evolve our enterprise infrastructure... ...Azure infrastructure, migrations, and connectivity; manage identity services (Active Directory, Entra ID), DNS, DHCP, and certificate services; optimize...SuggestedFlexible hours
- ...City Sportsnet. Job Summary The KPTV Engineering Manager will report to the Director of... ...with Windows Server environments and Active Directory. Ability to communicate technical concepts... ..., gender, sexual orientation, gender identity or expression, national origin, age,...SuggestedWork experience placementLocal areaAfternoon shift
$63.91 - $108.82 per hour
...Description Senior Security Engineer IS – Identity & Access Management We are seeking a highly motivated Senior Security Engineer... ...experience designing and supporting IAM solutions in hybrid Active Directory and cloud environments (e.g., Microsoft Entra ID/Azure AD...SuggestedMinimum wageFull timeWork at officeRemote workFlexible hoursShift workWeekend work- ...important characteristic of our Onsite Service Engineer is that you use and continuously develop... ...frontline support in key operational activities including installation, commissioning,... ..., genetic information, gender, gender identity, gender expression, age, national origin...SuggestedFlexible hours
- ...is looking for a talented Electrical Engineer to join us! The Electrical Engineer... ...cover or contain a comprehensive listing of activities, duties or responsibilities that are... ...disability, sexual orientation, gender, gender identity and expression, marital status, and any...SuggestedWork experience placementNight shift
$119.83k
...Description: As a Senior Electrical Engineer - Substation Protection & Control (P&C),... ...conditions, sexual orientation, gender identity or gender expression), national origin,... ...are meaningful to you. Where you play an active part in shaping your career journey. Where...Full timeH1bLocal area$134.26k
...Description: As a Senior Substation Engineer – Physical, you’ll lead the design and execution... ...conditions, sexual orientation, gender identity or gender expression), national origin,... ...meaningful to you. Where you play an active part in shaping your career journey....Full timeFor subcontractorH1b$47.28 - $70.8 per hour
...Field Service Engineer Lead - Semiconductor US-OR-Hillsboro Job ID: 34258 Type... ...Maintain accurate documentation of maintenance activities and prepare periodic reports. Manage... ..., sex, sexual orientation, gender identity, national origin, disability or protected...Hourly payFull timeFor contractorsFor subcontractorCasual workWork at officeLocal areaFlexible hoursNight shift$52k - $200k
...Candidates should have hands-on experience managing equipment removal activities while maintaining strict adherence to safety protocols and... ...marital status, pregnancy, gender, gender expression, gender identity, sexual orientation, or any other characteristic protected by...Contract workInternshipLocal areaImmediate startShift work$85k - $110k
...Job Description Job Title Civil Engineer Location Beaverton, Oregon, On-site... ...erosion control design Support permitting activities and coordinate with local, state, and... ...disability, sexual orientation, gender identity, genetic information or any characteristic...Contract workTemporary workWork at officeLocal area$84.3k - $150k
...Position: Field Applications Engineer Job Description: Arrow Electronics is a global... ...sales team across pre-and post-sales activities, providing advanced technical support... ...gender, age, sexual orientation, gender identity, national origin, veteran or disability...Hourly payFull timeTemporary workWork experience placementWork at officeLocal areaRemote workWorldwide- ...experience Bachelor degree in Physics or Engineering. Minimum 4-6 years of relevant work-... ...with related teams Motivated, pro-active, self-driven and flexible Good... ...disability, sexual orientation, or gender identity. We recognize that diversity and inclusion...Immediate startFlexible hours
$163.5k - $214.62k
...updated and .Director, Process Development Engineering page is loaded## Director, Process... ...Module Ownership:** Manage engineering activities for Lithography, Plating, Etch, Metal Deposition... ...to age, race, color, gender, gender identity/expression, national origin, sexual...Live inLocal areaRemote workFlexible hoursShift workDay shift- ...Security Developer Tools Engineer (Static Analysis), Languages & Runtimes Apple's static... ...'s platform and ecosystem. The team actively participates in the Clang/LLVM open source... ...religion, sex, sexual orientation, gender identity, national origin, disability, veteran...
- ...presentations that translate complex power systems engineering into strategic narrative for owner-side... ...preferred. PE License (Required): Active Electrical PE licensure in at least one... ..., sexual orientation, gender, gender identity, gender expression and transgender...Contract workFor contractorsWork at office
$80k - $95k
Quality Engineer 2 Typical Base Salary Range: $80,000 to $95,000 (DOE) For over 100 years... .... Lead and document problem‑solving activities using scientific methods (e.g. 8D). Monitor... ...status, sexual orientation, gender identity, or any other characteristic protected by...Work at office$105.4k
...Work you'll do As a Senior Engineering Management Specialist on the... ...implementation of Customer Identity and Access Management (CIAM)... ...milestones, support pursuit activities, resolve issues, and build... ...with diverse applications, directories, and identity sources. Foster...Visa sponsorship- ..., and deliver with purpose. As a senior engineering authority in our Data Center & Hyperscale... .... PE Licensure (Required). Active Electrical PE in at least one U.S. state... ...status, sexual orientation, gender, gender identity, gender expression and transgender status...For contractorsFor subcontractorWork at officeRemote work
$91.48k
...to delve into many aspects of electrical engineering, including the design of complex power... ...conditions, sexual orientation, gender identity or gender expression), national origin,... ...are meaningful to you. Where you play an active part in shaping your career journey. Where...Full timeH1bLocal areaRelocation packageFlexible hours- ...who thrive in the collaborative spirit of engineering, where their efforts are appreciated,... ...administration Mentor junior-level staff Actively participate in business development,... ..., sex, sexual orientation, gender identity, national origin, disability or veteran...Contract workTemporary workWork at officeLocal areaFlexible hours
$27 - $37.4 per hour
Who We Are Applied Materials is a global leader in materials engineering solutions used to produce virtually every new chip and advanced... ...citizenship, ancestry, religion, creed, sex, sexual orientation, gender identity, age, disability, veteran or military status, or any other...Full timeInternshipRelocation$38 - $53 per hour
...Photolithography Technician 5, Equipment Engineering We are seeking a highly... ...tool performance and drive improvement activities based on findings. ~ Utilize Statistical... ..., sexual orientation, gender, gender identity, gender expression, marital status, pregnancy...Permanent employmentWork at officeShift workNight shift- ...thrive in the collaborative spirit of engineering, where their efforts are appreciated, and... ...other marketing / business development activities Perform other duties as assigned... ...religion, sex, sexual orientation, gender identity, national origin, disability or veteran...Contract workTemporary workWork at officeFlexible hours
- ## Electrical Engineering Intern (MECOP) - 2026Beaverton, OR, United StatesThe intern will... ...veteran status, sexual orientation, gender identity or expression, or other characteristics... ...development, testing, and validation activities for industry-leading test and...Internship
- ...blend risk strategy, digital identity, cyber defense, application... ...an experienced Lenel OnGuard Engineer / Application Support... ...migrations, and platform lifecycle activities Troubleshoot application,... ...integrations with Active Directory, HR systems, video surveillance...Work experience placementLive inWork at officeLocal area
$191.22k - $269.95k
...Description: As a Senior Quality and Reliability Engineer, you will engage with substrate... ...critical risks in technology development activities at the component level, and address... ...pregnancy, gender, gender expression, gender identity, sexual orientation, or any other...Full timeInternshipLocal areaImmediate startShift work$31 - $42.4 per hour
...Who We Are Applied Materials is a global leader in materials engineering solutions used to produce virtually every new chip and... ...citizenship, ancestry, religion, creed, sex, sexual orientation, gender identity, age, disability, veteran or military status, or any other...Full timePart timeWork experience placementRelocation- ...As a Regional Product Support Engineer at Lam, you're the backbone... ...worldwide technical community and actively shares knowledge and takes a... ...Package. Knowledge of the directory structure, and the ability to... ...conditions), gender, gender identity, gender expression, age,...Work experience placementLocal areaRemote workWorldwideFlexible hoursNight shift2 days per week3 days per week1 day per week
- Factory SoC Test Support Engineering Program Manager As an Engineering Program Manager within... ...right audience Self-motivated and pro-active with demonstrated creative and critical... ...religion, sex, sexual orientation, gender identity, national origin, disability, Veteran status...
- ...Hybrid Title: Senior FPGA Engineer Job Description: At Tektronix, we believe innovation... ..., optical and electrical systems. Actively understand customer needs and develop... ...status, sexual orientation, gender identity or expression, or other characteristics...Permanent employmentLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Identity Engineer - Active Directory. Be the first to apply!





