Demo

Active Directory Engineer – Core Directory Services (Isolation Forests & Domains)

Jobs via Dice
Milpitas, CA Full Time
POSTED ON 4/17/2026
AVAILABLE BEFORE 5/16/2026
Dice is the leading career destination for tech experts at every stage of their careers. Our client, SRI Tech Solutions, is seeking the following. Apply via Dice today!

Role Summary

We are seeking an experienced Active Directory (AD) Engineer to design, build, and operate core Microsoft Active Directory infrastructure, with a strong focus on isolated forests, segregated domains, and security‑driven directory architectures. This role is critical to enabling secure authentication, legacy containment, privilege isolation, and enterprise identity resilience.

The engineer will own the lifecycle of AD forests and domains, partner with security and platform teams, and ensure directory services meet availability, security, and compliance requirements.

Key Responsibilities

Active Directory Architecture & Engineering

  • Design, build, and maintain Active Directory forests, trees, and domains, including additional and isolated forests for security or regulatory purposes
  • Implement resource forests, containment forests, and hardened domains for legacy protocols, privileged access, or application isolation
  • Design and manage inter‑forest and intra‑forest trusts (one‑way, two‑way, selective authentication)
  • Plan and execute domain controller placement, site topology, and replication strategy

Core AD Administration

  • Deploy, patch, and maintain Domain Controllers (Windows Server)
  • Manage FSMO roles, time synchronization, DNS integration, and SYSVOL
  • Administer Group Policy Objects (GPOs) for security baselines and configuration management
  • Manage AD objects: users, groups, computers, service accounts, and delegation models

Security & Hardening

  • Enforce Active Directory security best practices and tiered administration models
  • Build privilege isolation domains for admin accounts and privileged workloads
  • Support initiatives such as:
  • Legacy protocol isolation (NTLM, RC4, LDAP signing exceptions)
  • Service account governance and gMSA implementation
  • AD attack surface reduction (lateral movement prevention, tiering)
  • Partner with security teams during incidents, audits, and risk remediation efforts

Migration & Transformation

  • Lead or support:
  • Domain and forest builds and decompositions
  • Application and server migrations between domains or forests
  • Legacy domain containment and modernization efforts
  • Coordinate with application, server, and IAM teams to minimize disruption

Monitoring, Troubleshooting & Operations

  • Diagnose and resolve:
  • Replication failures
  • Authentication and trust issues
  • DNS and Kerberos‑related problems
  • Maintain AD health using monitoring tools and best practices
  • Create and maintain operational runbooks and SOPs

Experience

Required Qualifications

  • 8 years of hands‑on Active Directory engineering and administration experience
  • Proven experience building new forests and domains, including isolated or segmented environments
  • Deep understanding of AD internals and authentication mechanisms

Technical Expertise

  • Strong knowledge of:
  • Active Directory Domain Services (AD DS)
  • DNS, Kerberos, LDAP, NTLM
  • Forest/domain trusts and authentication boundaries

Salary.com Estimation for Active Directory Engineer – Core Directory Services (Isolation Forests & Domains) in Milpitas, CA
$109,025 to $132,661
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Active Directory Engineer – Core Directory Services (Isolation Forests & Domains)?

Sign up to receive alerts about other jobs on the Active Directory Engineer – Core Directory Services (Isolation Forests & Domains) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$90,059 - $113,247
Income Estimation: 
$78,000 - $102,313
Income Estimation: 
$109,521 - $135,401
Income Estimation: 
$83,089 - $102,314
Income Estimation: 
$109,654 - $138,234
Income Estimation: 
$104,823 - $128,381
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Jobs via Dice

  • Jobs via Dice Sheridan, WY
  • Dice is the leading career destination for tech experts at every stage of their careers. Our client, Varmoda Tech LLC, is seeking the following. Apply via ... more
  • 12 Days Ago

  • Jobs via Dice Alaska, AK
  • job summary: Enterprise Healthcare client has an immediate opening for a highly motivated Project Manager III to join their dynamic and growing team. All q... more
  • 12 Days Ago

  • Jobs via Dice Wilmington, DE
  • Dice is the leading career destination for tech experts at every stage of their careers. Our client, PTR Global, is seeking the following. Apply via Dice t... more
  • 12 Days Ago

  • Jobs via Dice Wilmington, DE
  • Be part of a team that unleashes the power of leading-edge technologies to help improve the health and well-being of those most vulnerable in our country a... more
  • 12 Days Ago


Not the job you're looking for? Here are some other Active Directory Engineer – Core Directory Services (Isolation Forests & Domains) jobs in the Milpitas, CA area that may be a better fit.

  • SRI Tech Solutions Milpitas, CA
  • Role Summary We are seeking an experienced Active Directory (AD) Engineer to design, build, and operate core Microsoft Active Directory infrastructure , wi... more
  • 4 Days Ago

  • Kaseya Sunnyvale, CA
  • Kaseya® is the leading provider of complete IT infrastructure and security management solutions for Managed Service Providers (MSPs) and internal IT organi... more
  • 23 Days Ago

AI Assistant is available now!

Feel free to start your new journey!