Demo

Active Directory Engineer

MEDVACON LIFE SCIENCES, LLC
Houston, TX Full Time
POSTED ON 6/20/2026
AVAILABLE BEFORE 7/18/2026

Role Summary


The Windows Active Directory Engineer is responsible for stabilizing, securing, and modernizing the enterprise Active Directory environment with a strong focus on directory cleanup, identity hygiene, replication health, and security hardening. This role ensures AD remains healthy, compliant, resilient, and aligned with Zero Trust identity principles across on‑prem and hybrid cloud environments.


Key Responsibilities

  1. Active Directory Cleanup & Optimization
  • Perform comprehensive AD cleanup including stale objects, unused OUs, orphaned SIDs, legacy GPOs, and deprecated configurations.
  • Normalize and restructure OU hierarchy, naming standards, and attribute consistency.
  • Identify and remediate duplicate SPNs, conflicting UPNs, and misconfigured service accounts.
  • Clean up old domain controllers, decommission legacy forests/domains, and remove deprecated trust relationships.
  • Conduct ACL cleanup to eliminate excessive permissions and privilege creep.

AD Security Hardening & Identity Protection

  • Implement CIS/NIST/Microsoft security baselines for domain controllers and AD objects.
  • Harden authentication by reducing NTLM, enforcing Kerberos protections, and implementing authentication policies/silos.
  • Deploy and maintain Privileged Access Workstations (PAW) and tiered admin model (Tier 0/1/2).
  • Remediate identity vulnerabilities such as DC Sync exposure, unconstrained delegation, Golden Ticket risks, and weak ACLs.
  • Integrate AD logs with SIEM platforms (Sentinel, Splunk, QRadar) for continuous monitoring.
  • Implement secure service account management, including gMSA adoption and rotation policies.

AD Replication Health & Domain Controller Management

  • Monitor and maintain AD replication topology, site links, and inter‑site connectivity.
  • Troubleshoot replication failures (USN rollback, lingering objects, tombstone issues).
  • Perform authoritative and non‑authoritative restores as needed.
  • Ensure domain controllers are patched, hardened, and compliant with security standards.
  • Validate SYSVOL health (DFSR), replication convergence, and GPO consistency.

Group Policy Management & Cleanup

  • Audit and clean up legacy, conflicting, or redundant GPOs.
  • Standardize GPO structure, naming, and versioning.
  • Implement GPO security baselines for servers, workstations, and privileged accounts.
  • Troubleshoot GPO processing issues and configuration drift.

Hybrid Identity & Azure AD (Entra ID) Integration

  • Support and optimize Azure AD Connect sync, attribute flows, and identity lifecycle.
  • Remediate sync errors, duplicate identities, and hybrid identity conflicts.
  • Implement Conditional Access, MFA enforcement, and modern authentication policies.
  • Support migration toward Zero Trust identity and passwordless authentication.

Documentation, Governance & Continuous Improvement

  • Maintain detailed documentation of AD topology, GPOs, replication, and security configurations.
  • Develop identity governance standards, naming conventions, and lifecycle processes.
  • Provide recommendations for AD modernization, consolidation, and long‑term stability.
  • Participate in audits, compliance reviews, and security assessments.


Required Skills & Experience

  • 5–10 years of hands‑on experience with Active Directory, DNS, DHCP, GPO, and Windows Server.
  • Deep expertise in AD cleanup, replication troubleshooting, and security hardening.
  • Strong PowerShell skills for automation and bulk remediation.
  • Experience with Azure AD / Entra ID, hybrid identity, and AAD Connect.
  • Familiarity with SIEM, identity threat detection, and AD attack paths.
  • Understanding of Kerberos, NTLM, LDAP, SAML, OAuth, and modern auth.


Preferred Qualifications

  • Knowledge of Red Forest / ESAE, Tiered Admin Model, and Zero Trust identity.
  • Certifications: Microsoft Identity & Access Administrator (SC‑300), Azure Administrator

Salary.com Estimation for Active Directory Engineer in Houston, TX
$65,571 to $81,863
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Active Directory Engineer?

Sign up to receive alerts about other jobs on the Active Directory Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$27,838 - $39,876
Income Estimation: 
$44,199 - $55,861
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at MEDVACON LIFE SCIENCES, LLC

  • MEDVACON LIFE SCIENCES, LLC Manassas, VA
  • Job Description: PAY - $20.90 - MARKUP - 45% - TEMP TO HIRE - ONSITE POSITION - DURATION - SIX MONTHS - SHIFT - MON-FRI 2PM - 10:30PM. Complete day to day ... more
  • Just Posted

  • MEDVACON LIFE SCIENCES, LLC Kansas, MO
  • TEMP TO HIRE - DURATION - 6 MONTHS - ONSITE POSITION - SHIFT - MON-FRI 8AM - 4PM. I. Position Overview Associate Scientist II is primarily responsible for ... more
  • 1 Day Ago

  • MEDVACON LIFE SCIENCES, LLC Boston, MA
  • 3-6 MONTHS - ONSITE POSITION - SHIFT - 8AM - 5PM. I. Position Overview The Senior Accountant is responsible for working closely with the Finance team to en... more
  • 1 Day Ago

  • MEDVACON LIFE SCIENCES, LLC Petersburg, FL
  • Job Description: PAY - $23 - $25- ONSITE - SHIFT - MON-FRI 7AM - 4PM WITH BEING ABLE TO BE FLEXIBLE FOR 2ND SHIFT EMPLOYEES AT TIMES - DURATION - 4 MONTHS ... more
  • 1 Day Ago


Not the job you're looking for? Here are some other Active Directory Engineer jobs in the Houston, TX area that may be a better fit.

  • Software Technology Inc. Spring, TX
  • Top Skills' Details 1. Enterprise Active Directory, ADCS, ADFS & PKI ✅ 5 years of hands‑on experience Ben explicitly stated he is looking for candidates wh... more
  • Just Posted

  • NasTech Global, Inc. Spring, TX
  • Job Title: Active Directory Tier 0 Engineer Location: Spring, TX(Onsite) Job Type: Contract W2 EXXON FORMERS required Top Skills' Details 1. Enterprise Act... more
  • 1 Day Ago

AI Assistant is available now!

Feel free to start your new journey!