Active Directory Architecture & Management: Design, deploy, configure, and maintain enterprise AD Domain Services (AD DS) , including managing forests, domains, trusts, schemas, and organizational units (OUs).Identity & Access Control: Oversee user authentication, security groups, role-based access controls (RBAC), and permissions alignment. Implement and manage AD Federation Services (AD FS) and AD Certificate Services (AD CS / PKI infrastructure) .Policy & Device Governance: Architect, deploy, and troubleshoot complex Group Policy Objects (GPOs) to enforce security controls, desktop standards, compliance rules, and system configuration profiles across the enterprise network.Operating System Engineering: Install, configure, and administer Windows Server operating systems (Server 2016 through Server 2022/2025). Execute OS hardening utilizing industry-standard security baselines (such as CIS benchmarks).Infrastructure Health & Maintenance: Monitor system operations, analyze system performance metrics, and diagnose complex domain controller replication or authentication errors. Own the maintenance lifecycle via regular updates, security patches ( WSUS/MECM ), and automated system backups.Core Network Services: Administer and support critical infrastructural network services integrated with AD, including DNS resolution , DHCP deployment, and IP address management.Automation & Scripting: Leverage PowerShell scripting to automate repetitive administrative workflows, bulk account updates, audit logging, and data migrations.Required Technical Skills & Qualifications:Experience: Minimum of 5+ years of dedicated experience as a Windows Systems Engineer or Active Directory Engineer within an enterprise environment.Active Directory Expertise: In-depth, practical knowledge of logical AD structures (forests, trees, domains, OUs), FSMO roles, replication topologies, and authentication protocols (Kerberos, NTLM, LDAP).OS & Server Mastery: Deep operational proficiency with Microsoft Windows Server infrastructure, OS deployment lifecycle, server hardware maintenance, and patch management methodologies.Core Networking: Robust understanding of network protocols and infrastructure dependencies, specifically DNS configuration and DHCP .Automation: Proven capability writing and maintaining PowerShell 7.x scripts for systems management and automation.Physical/Onsite Capability: Willingness and capability to work daily on-premise, including managing physical server deployments or hardware rack-ups as required.#J-18808-Ljbffr