Insight Global logo

Active Directory Engineer

Insight Global

Houston, TX · HybridJobSeen 1 day agoSeen in employer's feed today

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
Houston, TXHybrid
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Requirements

Credentials this posting asks for.

Microsoft Identity-Focused Certifications

Job overview

A client of Insight Global seeks a highly skilled Active Directory Engineer to join a Cloud Infrastructure and Identity team, focusing on stabilizing, modernizing, and cleaning up a large, complex on‑prem Active Directory environment that integrates with Entra ID, with responsibilities spanning migration, troubleshooting, automation, security, and cross‑functional collaboration.

Skills & qualifications

RequiredNice to have

Skills

Active DirectoryEntra IDAzure ADAzure AD ConnectPowerShellSailPointQuest Migrator ProBinary TreeWindows Server 2016Azure InfrastructureIntuneSolarWindsManageEngineServiceNowJiraDomain ControllersTrustsSchemaGroup Policy ObjectsFSMO RolesReplicationMulti‑Domain EnvironmentsMulti‑Forest EnvironmentsTiered Security ModelLeast‑Privilege AccessAuditingSecurity Hardening

Qualifications

Microsoft Identity-Focused Certifications

Full job description

Job Description

A client of Insight Global is seeking a highly skilled Active Directory Engineer to join their Cloud Infrastructure / Identity team. This is an engineer-level, hands-on role (not an architect-only position). You’ll step into a large, complex on‑prem Active Directory environment that has grown over many years and includes legacy domains from past acquisitions/mergers. The environment is hybrid (on‑prem AD integrated with Entra ID) and needs stabilization, modernization, and cleanup.

This role is ideal for someone who enjoys “getting into the weeds,” improving imperfect systems, and helping shape how the environment should operate going forward. The team is looking for an engineer who is comfortable with ambiguity, enjoys problem-solving, and is excited to help re-engineer and optimize identity infrastructure.

Key Responsibilities:

  • Clean up, stabilize, and improve an existing enterprise Active Directory environment.
  • Support and execute Active Directory migration and optimization efforts across workstations, servers, and applications with minimal disruption.
  • Troubleshoot and remediate complex AD issues, including replication, DNS, schema, trusts, domain controllers, GPOs, and legacy performance problems.
  • Assess AD health and drive improvements across multi‑domain and multi‑forest environments.
  • Support hybrid identity operations, including on‑prem AD integration with Entra ID and directory synchronization tooling.
  • Build and maintain PowerShell automation to improve AD health, compliance, and operational consistency.
  • Implement and reinforce tiered security / tiered administration practices, least‑privilege access, and auditing standards.
  • Collaborate with cross‑functional teams to assess dependencies, mitigate risk, and execute changes in a controlled manner.
  • Partner with IAM stakeholders to support governance workflows and understand how SailPoint integrates with AD for access lifecycle management (joiner/mover/leaver, provisioning, deprovisioning).

Skills and Requirements

  • 7+ years of hands‑on Active Directory engineering experience in enterprise environments.
  • Strong experience working in multi‑domain and multi‑forest Active Directory environments, including domain controllers, trusts, schema, Group Policy Objects (GPOs), FSMO roles, replication, and advanced troubleshooting.
  • Proven Active Directory migration experience using tools and PowerShell‑based migration and support scripting.
  • Experience supporting hybrid identity environments, with Active Directory integrated with Entra ID, including exposure to Entra ID (Azure AD), Azure AD Connect and directory synchronization concepts, and identity federation tools as applicable.
  • Strong PowerShell automation skills focused on operational improvements and repeatable engineering outcomes.
  • Proven experience leveraging Active Directory migration tools
  • Solid understanding of Active Directory security and controls, including least‑privilege access, auditing, and security hardening practices.
  • A hands‑on, “roll up your sleeves” mindset with comfort working in environments that are mid‑improvement and not perfectly documented.
  • Experience with identity governance tools (strong preference for SailPoint) and understanding of how governance integrates with AD.
  • Hands‑on experience with Quest Migrator Pro for Active Directory (MPAD) or Binary Tree migration tools.
  • Familiarity with tiered security model concepts (Tier 0/1/2 administration patterns).
  • Experience supporting environments impacted by M&A, legacy consolidation, or recovery from migration issues.
  • Exposure to:
  • Windows Server 2016○ Azure infrastructure and/or Intune
  • Monitoring / AD tooling (e.g., SolarWinds, ManageEngine)
  • ITSM tools (ServiceNow) and Agile tooling (Jira)

Relevant certifications: Microsoft identity-focused certifications or equivalent experience.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to [email protected].

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.