Haystack
← Back to Jobs
Technology
RC

Active Directory Architect – Windows AD / IAM / Cloud Security

RealTek ConsultingIrvine, CA🇺🇸United StatesPosted Sep 25, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Irvine, CA, United States
Posted
23 hours ago
AWSEncryptionTCP/IPActive DirectoryAzureDNSGoogle CloudLDAPPKI

Job Description

Key Responsibilities

Active Directory Architecture & Administration

  • Design, maintain, and support enterprise Microsoft Active Directory environments.
  • Architect secure and scalable Active Directory solutions aligned with enterprise security standards.
  • Manage Domain Controllers and Active Directory infrastructure.
  • Perform Domain Controller and AD schema upgrades/migrations, including upgrades from Windows Server 2019/2022 to Windows Server 2025.
  • Troubleshoot Active Directory replication and authentication issues.
  • Manage FSMO (Flexible Single Master Operations) roles.
  • Perform AD health checks and proactively identify infrastructure issues.
  • Support enterprise AD modernization and security initiatives.

IAM & Security

  • Strong experience with Identity and Access Management (IAM).
  • Apply security principles related to:
    • Confidentiality
    • Integrity
    • Authorization
    • Accountability
  • Implement and maintain secure identity and access controls.
  • Support authentication, authorization, and directory security.
  • Identify and remediate Active Directory security vulnerabilities.
  • Develop security standards and controls for enterprise identity infrastructure.

Windows Server Security & Vulnerability Management

  • Perform Windows Server vulnerability remediation.
  • Manage security patching and compliance activities.
  • Implement secure configuration standards across Windows Server environments.
  • Identify vulnerabilities and coordinate remediation activities.
  • Ensure systems meet enterprise security and compliance requirements.

DNS Administration

Strong hands-on experience managing Microsoft DNS, including:

  • A records
  • AAAA records
  • CNAME records
  • MX records
  • TXT records
  • SRV records
  • NS records
  • SOA records
  • PTR records
  • Reverse lookup zones
  • Create and manage reverse DNS zones.
  • Troubleshoot DNS resolution and Active Directory-integrated DNS issues.
  • Manage DNS dependencies associated with Active Directory services.

Group Policy

  • Design, configure, and manage Group Policy Objects (GPOs).
  • Develop and implement enterprise security policies through GPO.
  • Troubleshoot GPO application and inheritance issues.
  • Manage policies related to authentication, security, system configuration, and compliance.

PKI / Certificates / LDAPS

  • Manage enterprise PKI and digital certificates.
  • Configure and troubleshoot SSL/TLS certificates.
  • Manage SSL cipher suites associated with Active Directory.
  • Configure and troubleshoot LDAPS.
  • Troubleshoot certificate trust, expiration, authentication, and connectivity issues.
  • Ensure certificate infrastructure follows enterprise security standards.

Windows Event Auditing & Centralized Logging

  • Configure Windows Event Auditing.
  • Monitor security and authentication events.
  • Configure forwarding of Windows audit events to centralized logging/SIEM platforms.
  • Troubleshoot security and authentication issues using Windows event logs.
  • Support security monitoring and compliance requirements.

Networking

Strong understanding of:

  • TCP/IP
  • TCP / UDP
  • DNS
  • Network connectivity
  • Firewall concepts
  • Active Directory network ports and protocols
  • Troubleshoot connectivity issues between Domain Controllers, clients, applications, and infrastructure services.
  • Understand network dependencies of Microsoft Active Directory services.
  • Troubleshoot authentication, LDAP/LDAPS, DNS, and directory connectivity issues.

Cloud Architecture & Security

AWS / Azure / Google Cloud Platform

  • Experience supporting Windows and Active Directory environments in cloud platforms.
  • Experience with AWS, Azure, and/or Google Cloud Platform.
  • Design secure cloud architectures aligned with enterprise security requirements.
  • Work with cloud-based virtual machines and Windows workloads.
  • Troubleshoot Windows VMs operating within cloud environments.
  • Understand cloud networking and security controls.
  • Apply IAM and access-control principles to cloud environments.

Cloud Security Architecture

  • Create security blueprints and roadmaps for cloud adoption.
  • Design secure, scalable, and compliant cloud architectures.
  • Establish security policies, standards, and guidelines for:
    • Public Cloud
    • Private Cloud
    • Hybrid Cloud
  • Assess cloud environments for vulnerabilities and security risks.
  • Implement technical security controls including:
    • Network security
    • IAM
    • Encryption
    • Access controls
  • Support compliance and risk-management initiatives.

DevSecOps & Collaboration

  • Collaborate with IT, infrastructure, security, cloud, and development teams.
  • Embed security practices into application and infrastructure development.
  • Support DevSecOps initiatives.
  • Provide technical guidance on identity, security, and cloud architecture.
  • Translate business and security requirements into technical solutions.

Required Technical Skills

Active Directory — Must Have

  • Microsoft Active Directory
  • Domain Controllers
  • AD replication
  • AD schema
  • FSMO roles
  • Active Directory security
  • AD troubleshooting
  • AD migrations/upgrades
  • Windows Server 2019 / 2022 / 2025

DNS — Must Have

  • Microsoft DNS
  • A / CNAME / MX / TXT / SRV / NS / SOA records
  • PTR records
  • Reverse zones
  • AD-integrated DNS
  • DNS troubleshooting

Security / IAM — Must Have

  • IAM
  • Identity and access management
  • Authentication / Authorization
  • Windows Server security
  • Vulnerability remediation
  • Security patching
  • Compliance
  • Security auditing

Group Policy — Must Have

  • GPO creation and management
  • Security policies
  • GPO troubleshooting
  • Group Policy inheritance

PKI / Certificates — Must Have

  • PKI
  • Digital certificates
  • SSL/TLS
  • SSL cipher suites
  • LDAPS
  • Certificate troubleshooting

Networking — Must Have

  • TCP/IP
  • TCP / UDP
  • Active Directory ports
  • DNS networking
  • Basic network troubleshooting

Cloud — Required

  • AWS / Azure / Google Cloud Platform
  • Cloud networking
  • IAM
  • Virtual Machines
  • Windows workloads in cloud environments
  • Cloud security

Preferred Qualifications

  • Experience designing enterprise-scale AD architecture.
  • Experience with Active Directory modernization and migration projects.
  • Windows Server 2025 upgrade experience.
  • Experience with hybrid Active Directory environments.
  • Experience integrating on-premises AD with cloud identity platforms.
  • Experience with centralized logging/SIEM solutions.
  • Experience with cloud security architecture.
  • Experience with DevSecOps.
  • Experience working in highly regulated enterprise environments.
  • Strong documentation and architecture-design skills.

 

Similar jobs