Active Directory (AD) Engineer

Posted Yesterday
Be an Early Applicant
7 Locations
In-Office or Remote
Mid level
Food • Logistics
The Role
Design, secure, and maintain enterprise Active Directory and hybrid Microsoft Entra ID environments. Manage domain controllers, replication, GPOs, authentication (Kerberos/NTLM), DNS, and AD Connect. Automate via PowerShell, lead upgrades/migrations, implement hardening and disaster recovery, and collaborate with security, cloud, and application teams to ensure identity service availability and compliance.
Summary Generated by Built In
JOB DESCRIPTION
The Active Directory Engineer is responsible for designing, implementing, securing, and maintaining enterprise-level Active Directory Domain Services (AD DS) and hybrid Microsoft Entra ID environments. This role ensures the availability, performance, security, and recoverability of identity infrastructure across complex, multi-domain and multi-forest environments. The engineer manages domain controllers, Group Policy Objects, directory replication, authentication services, and synchronization between on-premises Active Directory and Microsoft Entra ID. The position leads or supports upgrades, migrations, forest consolidations, automation, and disaster recovery initiatives while resolving advanced Kerberos, NTLM, DNS, and replication issues. The role partners closely with Cybersecurity, Identity and Access Management, Cloud, Network, Service Desk, and application teams to deliver secure and reliable identity services.Key Responsibilities
  • Design, install, configure, and maintain Active Directory forests, domains, organizational units, trusts, sites, subnets, and domain controllers.
  • Administer and optimize Active Directory Domain Services, including replication topology, Flexible Single Master Operations (FSMO) roles, schema, global catalog, and directory health.
  • Develop, implement, and enforce Group Policy Objects (GPOs) to support security, configuration management, access controls, and enterprise standards.
  • Harden Active Directory environments by applying security baselines, privileged access controls, tiered administration practices, auditing, and remediation of identified vulnerabilities.
  • Manage hybrid identity services and synchronization between on-premises Active Directory and Microsoft Entra ID using Microsoft Entra Connect / Azure AD Connect.
  • Troubleshoot and resolve complex authentication, authorization, replication, trust, DNS, Kerberos, NTLM, LDAP, and directory performance issues.
  • Create and maintain advanced PowerShell scripts to automate user and group provisioning, object lifecycle management, reporting, health checks, and routine administration.
  • Plan and execute Active Directory upgrades, domain or forest migrations, forest consolidations, tenant integration activities, and decommissioning initiatives.
  • Develop, test, and maintain disaster recovery procedures for domain controllers, schema, trusts, DNS-integrated zones, and critical identity services.
  • Monitor Active Directory capacity, availability, security events, and service health; identify trends and implement preventive or corrective actions.
  • Provide technical leadership and subject-matter expertise for identity-related incidents, problems, changes, and major infrastructure projects.
  • Produce and maintain accurate technical documentation, including architecture diagrams, operating procedures, configuration standards, recovery plans, and knowledge articles.
  • Collaborate with Cybersecurity, IAM, Cloud, Network, Server, Service Desk, and application teams to ensure identity solutions meet business, operational, and compliance requirements.
  • Participate in change management, incident response, root-cause analysis, and continuous improvement activities in accordance with established IT service management practices.

Qualifications
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field; equivalent relevant professional experience may be considered.
  • 3 years of hands-on experience administering and engineering Microsoft Active Directory in enterprise environments.
  • Excellent communication skills in English (B2+ or higher) and ability to collaborate across functions and geographies.
  • Experience supporting large-scale, multi-domain, multi-forest, or geographically distributed Active Directory environments.
  • Experience managing Active Directory infrastructure, including domain controllers, forests, trusts, organizational units, replication, and Group Policy.
  • Experience supporting hybrid identity environments that integrate on-premises Active Directory with Microsoft Entra ID.
  • Experience troubleshooting complex authentication, replication, DNS, Kerberos, NTLM, LDAP, and directory service issues.
  • Experience planning or executing Active Directory upgrades, migrations, consolidations, or disaster recovery activities.
  • Experience operating within formal incident, problem, change, and configuration management processes.
Skills
  • Advanced knowledge of Active Directory Domain Services (AD DS), Group Policy Objects (GPOs), organizational units, trusts, sites and services, replication, and FSMO roles.
  • Strong knowledge of Microsoft Windows Server operating systems and core infrastructure services, including Domain Name System (DNS) and Dynamic Host Configuration Protocol (DHCP).
  • Advanced PowerShell scripting skills for administration, automation, reporting, provisioning, and remediation.
  • Hands-on experience with Microsoft Entra ID, Microsoft Entra Connect / Azure AD Connect, and hybrid identity architecture.
  • Working knowledge of Active Directory Federation Services (AD FS), modern authentication, single sign-on, and identity federation concepts.
  • Strong understanding of Kerberos, NTLM, LDAP/LDAPS, Public Key Infrastructure (PKI), certificates, and authentication flows.
  • Knowledge of Active Directory security hardening, privileged access management, least privilege, audit controls, and security baselines.
  • Ability to use monitoring, diagnostic, and administrative tools to evaluate directory health, replication, performance, and security events.
  • Ability to create and maintain architecture diagrams, technical standards, runbooks, recovery procedures, and support documentation.

Soft Skills
  • Excellent written and verbal communication skills, with the ability to explain complex technical concepts to technical and non-technical audiences.
  • Strong analytical, troubleshooting, and root-cause analysis capabilities.
  • Ability to prioritize competing incidents, project activities, and operational responsibilities in a high-availability environment.
  • Strong collaboration skills and the ability to work effectively across infrastructure, cybersecurity, cloud, IAM, and application teams.
  • High level of accountability, attention to detail, documentation discipline, and security awareness.
  • Ability to make sound technical decisions under pressure and during service restoration or disaster recovery events.
  • Continuous improvement mindset with a focus on automation, reliability, standardization, and operational excellence.

Preferred Qualifications
  • Microsoft Certified: Azure Administrator Associate, Azure Solutions Architect Expert, Identity and Access Administrator Associate, MCSE, or a comparable Microsoft certification.
  • ITIL Foundation or higher certification.
  • Experience with Microsoft Entra ID governance, Conditional Access, Privileged Identity Management, or identity protection capabilities.
  • Experience with Active Directory security assessment and monitoring tools.
  • Experience supporting multinational or global organizations and highly regulated environments.
  • Experience with infrastructure-as-code, configuration management, or additional automation tools.
  • Experience supporting cloud migrations, mergers and acquisitions, domain integrations, or enterprise transformation programs.
Benefits:
  • This is a hybrid position based in Ultra Park II, Lagunilla (Heredia). On-site presence is required only when necessary, such as for meetings, trainings, or collaborative activities, in alignment with the company’s telework agreement, which currently requires employees to work on-site three (3) days per week)
  • Private Medical Insurance
  • Asociacion Solidarista
  • Life Insurance
  • Personal Day Off
Note: Only candidates with Costa Rican nationality or valid immigration status will be considered; applicants residing outside Costa Rica will not be considered, and relocation is not available

Skills Required

  • Bachelor's degree in Computer Science, IT, Cybersecurity, Engineering, or related field (or equivalent experience)
  • 3 years hands-on experience administering and engineering Microsoft Active Directory in enterprise environments
  • Experience supporting large-scale, multi-domain, multi-forest, or geographically distributed Active Directory environments
  • Experience managing AD infrastructure including domain controllers, forests, trusts, OUs, replication, and Group Policy
  • Experience supporting hybrid identity environments integrating on-premises AD with Microsoft Entra ID (Azure AD)
  • Experience with Microsoft Entra Connect / Azure AD Connect
  • Advanced PowerShell scripting skills for automation, provisioning, reporting, and remediation
  • Strong knowledge of Microsoft Windows Server operating systems and core infrastructure services (DNS, DHCP)
  • Experience troubleshooting complex authentication, replication, DNS, Kerberos, NTLM, LDAP/LDAPS, and directory performance issues
  • Experience planning or executing Active Directory upgrades, migrations, consolidations, or disaster recovery activities
  • Experience operating within formal incident, problem, change, and configuration management processes
  • Excellent communication skills in English (B2+ or higher) and ability to collaborate across functions and geographies
  • Working knowledge of Active Directory Federation Services (AD FS), modern authentication, SSO, and identity federation concepts
  • Understanding of PKI, certificates, and authentication flows

Sysco Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Sysco and has not been reviewed or approved by Sysco.

  • Healthcare Strength Multiple national medical plan options with telehealth, behavioral health resources, and targeted programs indicate broad coverage and support. Preventive care access and ancillary offerings (dental, vision, Rx advocacy) further reinforce the package.
  • Retirement Support A 401(k) with automatic company contributions plus a match, alongside an employee stock purchase plan, underscores solid retirement support. At union locations, enhanced pension terms add to perceived long‑term value.
  • Pay Growth & Progression Recent collective bargaining outcomes with substantial wage increases demonstrate meaningful pay progression where contracts apply. In high‑volume markets, incentive structures can amplify earnings beyond base rates.

Sysco Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Houston, TX
24,120 Employees

What We Do

Sysco is the global leader in selling, marketing and distributing food and related products to customers who prepare meals away from home. This includes restaurants, healthcare and educational facilities, lodging establishments, entertainment venues, and more. Sysco operates almost 340 distribution centers, in over 10 countries, with 76,000 colleagues serving approximately 730,000 customer locations. The company generated sales of more than $81 billion in fiscal year 2025 that ended June 28, 2025. As the world’s largest food-away-from-home distributor, Sysco offers customized supply chain solutions, bespoke specialty product offerings, and culinary support to drive customers to innovate and optimize their operations. We act as a trusted business partner to our customers, helping them grow through our industry-leading portfolio that includes fresh produce, premium proteins, specialty products, sustainably focused items, equipment and supplies, and innovative culinary solutions. For more information, visit www.sysco.com. For important news and key information for Sysco investors, visit the Investor Relations section of the company’s website at investors.sysco.com.

Similar Jobs

In-Office or Remote
7 Locations
24120 Employees

Atlassian Logo Atlassian

Account Executive

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Remote
Canada
11000 Employees

Forward Financing Logo Forward Financing

Analytics Engineer

Fintech • Financial Services
Remote
Ontario, ON, CAN
529 Employees
160K-185K Annually

Forward Financing Logo Forward Financing

Senior Analytics Engineer

Fintech • Financial Services
Remote
Ontario, ON, CAN
529 Employees
145K-165K Annually

Similar Companies Hiring

HERE Technologies Thumbnail
Artificial Intelligence • Automotive • Computer Vision • Information Technology • Internet of Things • Logistics • Software
Amsterdam, NL
6000 Employees
Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account