Demo

Lead Active Directory - SME

Pantheon
Spring, TX Contractor
POSTED ON 9/28/2026
AVAILABLE BEFORE 10/29/2026
Experience relevant to position (ADDS, ADFS, PKI services are core; Keyfactor, Terraform, AWS are a plus)
Overview
We are seeking a highly skilled Enterprise Identity Engineer to manage, support, and secure enterprise identity infrastructure.
This role is responsible for the administration, reliability, and security of Active Directory and related identity services that underpin critical business systems.
The position includes Tier 0 / Enterprise Administrator access, requiring the highest levels of trust, security awareness, and technical expertise.
Due to the elevated cybersecurity risk associated with this role, candidates must be willing to successfully complete an enhanced background check as a condition of assignment.
This is an onsite role based in Houston, TX, supporting a largescale enterprise environment and participating in an oncall rotation for identity and security services.
Responsibilities
  • Administer, maintain, and secure Active Directory (AD) environments, including domain controllers, replication, DNS, and security hardening.
  • Manage Active Directory Certificate Services (ADCS) and enterprise Public Key Infrastructure (PKI), including certificate lifecycle management.
  • Support and maintain Active Directory Federation Services (ADFS) and integrations with internal and external identity providers.
  • Implement and manage Azure Information Protection (AIP) to support enterprise data security and classification initiatives.
  • Configure and manage Hardware Security Modules (HSMs) for cryptographic key protection and secure operations.
  • Design, implement, and enforce Group Policy Objects (GPOs) to meet security, compliance, and operational standards.
  • Ensure secure authentication and authorization through deep expertise in Kerberos, Service Principal Names (SPNs), and keytab management.
  • Utilize Quest tools (Change Auditor, RMAD, GPOAdmin) for auditing, monitoring, disaster recovery, and policy governance.
  • Deploy and manage cloud infrastructure in AWS, leveraging Terraform and InfrastructureasCode (IaC) practices for automation and consistency.
  • Develop and maintain PowerShell automation scripts for operational efficiency, reporting, and security controls.
  • Partner with cybersecurity and compliance teams to ensure adherence to enterprise security standards and best practices.
  • Participate in an oncall rotation to support critical identity and security services and resolve highseverity incidents.
  • Work as part of an Agile team, participating in ceremonies and collaborating with application developers, business stakeholders, and infrastructure teams.
Required Qualifications
  • Strong experience administering Active Directory in complex, enterprisescale environments.
  • Handson expertise with ADCS, PKI, and certificate lifecycle management.
  • Indepth knowledge of Kerberos authentication, SPNs, and keytabs.
  • Advanced experience managing and troubleshooting Group Policy Objects (GPOs).
  • Proficiency in PowerShell scripting for automation, auditing, and reporting.
  • Experience with Terraform and InfrastructureasCode concepts.
  • Familiarity with AWS infrastructure and cloudbased identity integrations.
  • Experience using Quest Change Auditor, RMAD, and GPOAdmin.
  • Solid understanding of enterprise security principles, especially those related to privileged access and identity protection.
  • Ability to meet requirements for enhanced background screening due to Tier 0 access.
Preferred Qualifications
  • Experience with Azure Information Protection (AIP) or Microsoft security and identity services.
  • Knowledge of HSM configuration and cryptographic key management.
  • Experience supporting identity platforms in regulated or highsecurity environments.
  • Prior work in large enterprises or oil & gas scale environments.
Soft Skills
  • Strong analytical and problemsolving skills.
  • Excellent written and verbal communication.
  • Ability to work independently while collaborating effectively with crossfunctional teams.
  • High attention to detail and sound judgment when handling sensitive systems and access.

Hourly Wage Estimation for Lead Active Directory - SME in Spring, TX
$60.00 to $73.00
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Lead Active Directory - SME?

Sign up to receive alerts about other jobs on the Lead Active Directory - SME career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$149,354 - $186,884
Income Estimation: 
$99,619 - $133,787
Income Estimation: 
$129,191 - $164,117
Income Estimation: 
$153,718 - $195,211
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Not the job you're looking for? Here are some other Lead Active Directory - SME jobs in the Spring, TX area that may be a better fit.

  • Lead Origin Company Houston, TX
  • Houston, TX Full-Time Careers > Senior Manager Customer Success Come join one of the fastest growing Digital Marketing Agencies in the country! LeadOrigin ... more
  • 16 Days Ago

  • Active Athlete Inc. Houston, TX
  • About the Role We’re looking for an enthusiastic and reliable Retail Sales Associate to join our team. This role is all about creating an exceptional in-st... more
  • 8 Days Ago

AI Assistant is available now!

Feel free to start your new journey!