Identity Engineer - Active Directory
Ralliant
Identity Engineer – Active Directory
The Identity Engineer – Active Directory is responsible for administering, engineering, and optimizing Ralliant Corporation's complex, multi-domain Active Directory environment. This role serves as a hands-on technical leader across core AD infrastructure, ensuring stability, security, and scalability while supporting the broader Identity & Access Management (IAM) program.
This position operates within a multi-domain, multi-forest environment (13+ domains) with hybrid identity integration and deep dependencies across enterprise IAM systems. The engineer is expected to operate confidently across all layers of Active Directory, from object lifecycle management and Group Policy to replication topology, authentication mechanisms, and disaster recovery.
The role partners closely with Security, Infrastructure, and Compliance teams to ensure Active Directory functions as a secure and reliable foundation for enterprise identity. It contributes to identity strategy by aligning AD schema, attributes, and configurations with identity governance platforms and access lifecycle processes.
The role embraces the Ralliant Business System (RBS) by embedding operational discipline, documentation, and continuous improvement into tools, workflows, and standard work. The engineer drives repeatable, scalable processes that improve security posture, reduce operational risk, and support audit readiness across the enterprise and Operating Companies (OpCos).
Key Responsibilities
- Administer a multi-domain, multi-forest Active Directory environment including user, group, and computer object lifecycle management, OU structure, delegation models, and trust relationships
- Manage the full lifecycle of Group Policy Objects (GPOs), including design, implementation, auditing, and cleanup
- Maintain AD Sites and Services, DNS integration, subnet mappings, and replication topology
- Monitor and maintain Domain Controller health, replication status, FSMO roles, and SYSVOL/DFS-R consistency
- Manage SPNs, gMSAs, and Kerberos authentication dependenciesMentor and coach engineers through design reviews, code reviews, and knowledge sharing, promoting consistent and high-quality delivery.
- Maintain documentation including technical designs, workflows, configurations, and operational procedures.
- Contribute to identity strategy and roadmap planning, identifying opportunities to enhance automation, security, and user experience.
- Use PowerShell as the primary tool for data collection, reporting, bulk operations, and automation
- Develop scripts for auditing, compliance reporting, and operational health monitoring
- Build automation for infrastructure lifecycle processes such as DC replacement and recovery
- Support Active Directory integration with CyberArk for credential vaulting, rotation, and privileged session management
- Manage privileged accounts and service account credentials in alignment with PAM policies
- Collaborate on CPM dependencies, credential policies, and troubleshooting PAM-to-AD integrations
- Partner with PKI teams to ensure AD Certificate Services configurations align with enterprise standards
- Implement tiered administration models and protected group governance
Qualifications
- Bachelor's degree recommended; equivalent experience considered.
- 6 years of hands-on experience administering Active Directory in enterprise environments
- Deep expertise in AD architecture, including object management, GPOs, DNS, replication, and domain controller operations
- Advanced PowerShell scripting and automation capabilities
- Strong understanding of Kerberos, SPNs, gMSAs, and delegation models
- Experience working with CyberArk or similar PAM solutions integrated with Active Directory
- Hands-on experience with AD disaster recovery and multi-domain/multi-forest environments
- Understanding of Active Directory's role within identity governance and IAM ecosystems
- Experience collaborating with PKI teams and supporting AD-integrated certificate services
- Experience with hybrid identity environments (Entra ID / Azure AD Connect)
- Strong knowledge of AD security hardening practices and attack mitigation techniques
- Experience generating audit evidence and supporting compliance requirements
- Experience with SIEM platforms such as CrowdStrike or equivalent
- Experience supporting regulated or customer driven security requirements, including U.S. Government environments; familiarity with CMMC and NIST SP 800-171 aligned expectations preferred.
- Strong communication and documentation skills, with the ability to translate technical concepts into business impact.
- Ability to operate effectively across enterprise and OpCo environments, balancing global consistency with local context across multiple time zones and culture.
- Alignment with Ralliant values and the Ralliant Business System (RBS), including continuous improvement, transparency, and ownership.
About Us
Ralliant, originally part of Fortive, now stands as a bold, independent public company driving innovation at the forefront of precision technology. With a global footprint and a legacy of excellence, we empower engineers to bring next-generation breakthroughs to life — faster, smarter, and more reliably. Our high-performance instruments, sensors, and subsystems fuel mission-critical advancements across industries, enabling real-world impact where it matters most. At Ralliant we're building the future, together with those driven to push boundaries, solve complex problems, and leave a lasting mark on the world.
About the Team
Ralliant, originally part of Fortive, now stands as a bold, independent public company driving innovation at the forefront of precision technology. With a global footprint and a legacy of excellence, we empower engineers to bring next-generation breakthroughs to life — faster, smarter, and more reliably. Our high-performance instruments, sensors, and subsystems fuel mission-critical advancements across industries, enabling real-world impact where it matters most. At Ralliant we're building the future, together with those driven to push boundaries, solve complex problems, and leave a lasting mark on the world. We Are an Equal Opportunity Employer Ralliant Corporation and all Ralliant Companies are proud to be equal opportunity employers. We value and encourage diversity and solicit applications from all qualified applicants without regard to race, color, national origin, religion, sex, age, marital status, disability, veteran status, sexual orientation, gender identity or expression, or other characteristics protected by law. Ralliant and all Ralliant Companies are also committed to providing reasonable accommodations for applicants with disabilities. Individuals who need a reasonable accommodation because of a disability for any part of the employment application process, please contact us at View email address on click.appcast.io.
Job Info
- Job Identification 9311
- Job Category Information Security
- Locations 14150 SW Karl Braun Drive, Beaverton, OR, 97077, US 4114 Center at North Hills St. Suite 400, Raleigh, NC, 27609, US 4114 Center at North Hills St. Suite 400, Raleigh, NC, 27609, US (Hybrid)
- ...Senior Azure Active Directory/Entra ID Engineer In-depth knowledge of Entra ID (Azure AD) and Azure AD B2C Strong experience with Active Directory and domain services Experience with identity federation and multi-factor authentication (MFA) solutions Proficiency...Suggested
- ...Job Title: Systems Engineer(Windows Active Directory Engineer.) Project Duration: 9 Months Locaton :- 100% Remote Role Description: We are seeking an experienced Windows Active Directory Engineer. The ideal candidate will have a deep understanding...SuggestedRemote work
$114k - $142k
...the future? We are seeking a Cyber Security Architect/Engineer II – Active Directory/IAM to join our team. In this role, you will work remotely... ...responsible for managing the daily operations of our Privilege Identity (PI) applications and monitoring the daily operations of...SuggestedPermanent employmentTemporary workWork experience placementRemote workFlexible hours- ...description: The Technical Lead - Identity Federation, Azure & Access... ...a senior, hands on identity engineer responsible for owning... ...mentioned below. Specific activities may change from time to time... ...Conditional Access. Microsoft Active Directory Strong understanding of...SuggestedFull timePart timeWork experience placementWork at officeShift workDay shift
- ...management. The successful candidate will manage incidents, support desktop applications, and serve as a subject-matter expert in Active Directory. Proven experience and specialized knowledge in service desk operations are essential. #J-18808-Ljbffr Software Technology,...Suggested
$140k - $160k
...Senior Infrastructure Engineer - IAM & Automation At Polsinelli, What a Law Firm Should... ...require demonstrated experience in Identity and Access Management platforms and workflows... ...Access controls through Okta and Entra/Active Directory. Create, support, and maintain Okta...Full timeTemporary workPart timeRemote workFlexible hoursShift work$78.4k - $129.4k
...Integrate SharePoint with related technologies—including Active Directory, SQL Server, IIS, and external line‑of‑business systems—to provide... ...'s race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not...Contract workWork at office$70k - $105k
...looking for a Field Construction Project Engineer (CPE) to support complex engineering and... ...within our Energy business unit at an active project site. This role will focus on day... ...religion, sex, sexual orientation, gender identity, national origin, protected veteran or...Full timeContract workFor contractorsFor subcontractor- ...team that is responsible for the design/engineering/operation of the following... ...infrastructure technology services: Microsoft Active Directory Domain Services Microsoft Active Directory... ...Management Services (KMS) Microsoft Identity Manager (MIM) Microsoft Remote Desktop...Permanent employmentFull timePart timeWork experience placementH1bWork at officeRemote workWork visa
- Automation and Controls Engineering Co-Op Automation and Controls Engineering Co-Op About... ...Engineering co-op to support PLC and HMI/SCADA activities in a high-volume manufacturing... ...religion, sex, sexual orientation, gender identity/expression, national origin, disability...
- ...Companies, is seeking a motivated **Field Engineer** to support electrical construction... ...and coordinating electrical construction activities on-site.* Support project teams with technical... ...HIV status, sexual orientation, gender identity and/or expression, marital, civil union...For contractorsFor subcontractorWork at office
- ...equipment. This person will work with Project Engineers, Process Engineers, Process Mechanics,... ...conditions or practices, unlawful activities and activities which present unreasonable... ..., disability, ethnicity, gender, gender identity and expression, religion, or sexual orientation...Local areaImmediate start
- ...sustainability. As a Protection & Control Engineer, you will design and implement advanced... ...documentation. Coordinate technical activities throughout the project lifecycle. Perform... ...Life and Family (Legal, pet, auto, home, identity theft, etc.), special needs support, and...
- ...Estimating, Project Supervision, and Field Engineering. We offer opportunities in Heavy Civil,... ...protective equipment (PPE) for jobsite activities. Observe and prevent safety incidents.... ...pregnancy, sexual orientation, gender identity, and expression, protected veteran...Internship
- ...0% travel.What’s the role?Field Support Engineer II, with limited supervision, installs,... ...basic to complex technical solutions.IMR activities on international scale possible.Exercises... ..., carrier status, gender expression or identity, including transgender identity, or any...Local areaRemote work
- ...Dewberry is seeking a Senior Electrical Engineer or Senior Instrumentation and Control (I... ...lighting systems, equipment layout and related activities. Provide EI&IC specifications, drawings... ..., protected veteran status, gender identity or sexual orientation. #J-18808-Ljbffr...For contractorsWork at office
- Senior Field Service Engineer Electronic Security - Southern VA Job Description Posted Tuesday... ...distribution centers, data centers, and active construction sites. The position also... ...status, sexual orientation, gender identity, or any other protected characteristic under...Full timeTemporary workLocal areaMonday to FridayFlexible hours
- Mechanical Engineer III - HVAC & Utilities Full-time CRB is a leading provider of sustainable... ...Project work involves directing design activities for all levels of design such as studies... ...status, sex, sexual orientation, gender identity or any other legally protected category....Full timeFor subcontractorWork at office
$105k - $140k
...You Will Do GFT is seeking a Mechanical Engineer (HVAC) in our Raleigh, NC office. The Mechanical... ...training programs, and support for active participation in professional... ...religion, sex, sexual orientation, gender identity, national origin, disability, veterans’...Full timeWork at office- ...RS&H currently seeking a Traffic Control Engineer for our Transportation practice in our... ...assisting with business development/marketing activities, preparation of contract scope and fee... ..., sex, sexual orientation, gender identity, national origin, or protected veteran status...Contract workWork at officeLocal area
- ...which are not mentioned below. Specific activities may change from time to time.... ...through automation. Collaborate with engineering and business teams to align automation... ...prevention systems, network operating systems, identity management, database activity monitoring...Full timePart timeWork experience placementWork at office
$88.52k - $121.72k
Sr. Electrical Controls Engineer Location: Wilmington, NC, US; Harrodsburg, KY, US; Erwin... ...upgrades Lead electrical and controls activities for new and modified equipment Troubleshoot... ...origin, sexual orientation, gender identity or expression, disability, veteran status...- ...-Hattery is a premier architecture and engineering consulting firm headquartered in Cedar... ...applicable ASCE, NCEES, and/or community activities is preferred. Prepare AutoCAD drawings... ..., sex, sexual orientation, gender identity, national origin, disability, or status...Full timeContract workFor contractorsWork at officeLocal areaImmediate startFlexible hours
- ...Principal Information Security Systems Engineer (ISSE) will be working with a dynamic team... ...System Agency (DISA) military cloud.An active U.S. Department of War (DoW) Secret security... ..., sex, sexual orientation, gender identity, national origin, disability, veteran status...Full timeContract workPart timeFor contractorsLocal areaRemote workFlexible hours
- ...important Container as a Service (CaaS) engineering role has a primary focus of supporting... ...as needed to perform platform upgrade activities. This may require working from 7 pm EST... ...origin, age, sexual orientation, gender identity, disability, veteran status, or other classification...Full timePart timeWork at officeRelocationWork visaShift workDay shiftAfternoon shiftEarly shift
$82k - $135k
...: Perform daily project operations and engineering to coordinate project planning, engineering... ...per contract documents. Participate in activities, duties, and responsibilities to ensure... ..., sex, sexual orientation, gender identity, national origin, disability, status as...Permanent employmentContract workTemporary workWork at officeLong distance- End User Services O365 Engineer page is loaded## End User Services O365 Engineerlocations: North Carolina Officetime type: Full timeposted... ...Infrastructure Skills*** Perform basic engineering tasks: Active Directory, Group Policy, schema updates, and certificate renewals.*...Work at officeImmediate startRemote work
$97k - $167k
Senior Designated Services Engineer (Shift: Mon - Fri, 9 a.m. - 6 p.m. EST) Lehi, Utah; Raleigh... ...to scale solutions globally, while actively mentoring and coaching junior support... ...conditions), sexual orientation, gender, gender identity, gender expression, transgender status,...Work at officeMonday to FridayFlexible hoursShift work- .Automation Engineer page is loaded## Automation Engineertime type: Full timeposted on: Posted... ....* Support FAT, SAT, and commissioning activities on-site and remotely.* Troubleshoot and... ...* Family Care: Legal, pet, auto, home, identity theft support, special needs assistance,...Full timeRemote work
- Construction Engineering Intern (Transportation/Heavy Highway) Johnson, Mirmiran & Thompson... ...supporting the inspection and documentation of active construction projects. This position is... ..., sex, sexual orientation, gender identity, national origin, disability, protected...Full timeFor contractorsInternshipH1bWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Identity Engineer - Active Directory. Be the first to apply!

