Design, secure, and maintain enterprise Active Directory and hybrid Microsoft Entra ID environments. Manage domain controllers, replication, GPOs, authentication (Kerberos/NTLM), DNS, and AD Connect. Automate via PowerShell, lead upgrades/migrations, implement hardening and disaster recovery, and collaborate with security, cloud, and application teams to ensure identity service availability and compliance.
JOB DESCRIPTION
- Design, install, configure, and maintain Active Directory forests, domains, organizational units, trusts, sites, subnets, and domain controllers.
- Administer and optimize Active Directory Domain Services, including replication topology, Flexible Single Master Operations (FSMO) roles, schema, global catalog, and directory health.
- Develop, implement, and enforce Group Policy Objects (GPOs) to support security, configuration management, access controls, and enterprise standards.
- Harden Active Directory environments by applying security baselines, privileged access controls, tiered administration practices, auditing, and remediation of identified vulnerabilities.
- Manage hybrid identity services and synchronization between on-premises Active Directory and Microsoft Entra ID using Microsoft Entra Connect / Azure AD Connect.
- Troubleshoot and resolve complex authentication, authorization, replication, trust, DNS, Kerberos, NTLM, LDAP, and directory performance issues.
- Create and maintain advanced PowerShell scripts to automate user and group provisioning, object lifecycle management, reporting, health checks, and routine administration.
- Plan and execute Active Directory upgrades, domain or forest migrations, forest consolidations, tenant integration activities, and decommissioning initiatives.
- Develop, test, and maintain disaster recovery procedures for domain controllers, schema, trusts, DNS-integrated zones, and critical identity services.
- Monitor Active Directory capacity, availability, security events, and service health; identify trends and implement preventive or corrective actions.
- Provide technical leadership and subject-matter expertise for identity-related incidents, problems, changes, and major infrastructure projects.
- Produce and maintain accurate technical documentation, including architecture diagrams, operating procedures, configuration standards, recovery plans, and knowledge articles.
- Collaborate with Cybersecurity, IAM, Cloud, Network, Server, Service Desk, and application teams to ensure identity solutions meet business, operational, and compliance requirements.
- Participate in change management, incident response, root-cause analysis, and continuous improvement activities in accordance with established IT service management practices.
Qualifications- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field; equivalent relevant professional experience may be considered.
- 3 years of hands-on experience administering and engineering Microsoft Active Directory in enterprise environments.
- Excellent communication skills in English (B2+ or higher) and ability to collaborate across functions and geographies.
- Experience supporting large-scale, multi-domain, multi-forest, or geographically distributed Active Directory environments.
- Experience managing Active Directory infrastructure, including domain controllers, forests, trusts, organizational units, replication, and Group Policy.
- Experience supporting hybrid identity environments that integrate on-premises Active Directory with Microsoft Entra ID.
- Experience troubleshooting complex authentication, replication, DNS, Kerberos, NTLM, LDAP, and directory service issues.
- Experience planning or executing Active Directory upgrades, migrations, consolidations, or disaster recovery activities.
- Experience operating within formal incident, problem, change, and configuration management processes.
- Advanced knowledge of Active Directory Domain Services (AD DS), Group Policy Objects (GPOs), organizational units, trusts, sites and services, replication, and FSMO roles.
- Strong knowledge of Microsoft Windows Server operating systems and core infrastructure services, including Domain Name System (DNS) and Dynamic Host Configuration Protocol (DHCP).
- Advanced PowerShell scripting skills for administration, automation, reporting, provisioning, and remediation.
- Hands-on experience with Microsoft Entra ID, Microsoft Entra Connect / Azure AD Connect, and hybrid identity architecture.
- Working knowledge of Active Directory Federation Services (AD FS), modern authentication, single sign-on, and identity federation concepts.
- Strong understanding of Kerberos, NTLM, LDAP/LDAPS, Public Key Infrastructure (PKI), certificates, and authentication flows.
- Knowledge of Active Directory security hardening, privileged access management, least privilege, audit controls, and security baselines.
- Ability to use monitoring, diagnostic, and administrative tools to evaluate directory health, replication, performance, and security events.
- Ability to create and maintain architecture diagrams, technical standards, runbooks, recovery procedures, and support documentation.
Soft Skills- Excellent written and verbal communication skills, with the ability to explain complex technical concepts to technical and non-technical audiences.
- Strong analytical, troubleshooting, and root-cause analysis capabilities.
- Ability to prioritize competing incidents, project activities, and operational responsibilities in a high-availability environment.
- Strong collaboration skills and the ability to work effectively across infrastructure, cybersecurity, cloud, IAM, and application teams.
- High level of accountability, attention to detail, documentation discipline, and security awareness.
- Ability to make sound technical decisions under pressure and during service restoration or disaster recovery events.
- Continuous improvement mindset with a focus on automation, reliability, standardization, and operational excellence.
Preferred Qualifications- Microsoft Certified: Azure Administrator Associate, Azure Solutions Architect Expert, Identity and Access Administrator Associate, MCSE, or a comparable Microsoft certification.
- ITIL Foundation or higher certification.
- Experience with Microsoft Entra ID governance, Conditional Access, Privileged Identity Management, or identity protection capabilities.
- Experience with Active Directory security assessment and monitoring tools.
- Experience supporting multinational or global organizations and highly regulated environments.
- Experience with infrastructure-as-code, configuration management, or additional automation tools.
- Experience supporting cloud migrations, mergers and acquisitions, domain integrations, or enterprise transformation programs.
- This is a hybrid position based in Ultra Park II, Lagunilla (Heredia). On-site presence is required only when necessary, such as for meetings, trainings, or collaborative activities, in alignment with the company’s telework agreement, which currently requires employees to work on-site three (3) days per week)
- Private Medical Insurance
- Asociacion Solidarista
- Life Insurance
- Personal Day Off
Similar Jobs
Food • Logistics
Designs, implements, secures, and maintains enterprise Active Directory and hybrid Microsoft Entra ID environments. Manages domain controllers, GPOs, replication, authentication, and synchronization; leads upgrades, migrations, consolidations, automation, disaster recovery, and complex troubleshooting. Partners with security, cloud, network, and application teams, produces technical documentation, and enforces identity security and operational best practices.
Top Skills:
Active Directory Domain Services (Ad Ds)Ad FsAzure Ad ConnectCertificatesDhcpDnsFsmoGlobal CatalogGroup Policy (Gpo)KerberosLdap/LdapsMicrosoft Entra IdNtlmPkiPowershellWindows Server
Artificial Intelligence • Information Technology • Professional Services • Software • Analytics • Generative AI • Big Data Analytics
Serve as the platform consultant for CDP implementations (primarily Adobe RTCDP), lead discovery and requirements gathering, translate business needs into technical CDP specifications, define activation strategies across channels, support implementation and enablement, and ensure data governance and security/privacy compliance to drive measurable marketing outcomes.
Top Skills:
A/B Testing ToolsAdobe Experience PlatformAdobe Real-Time CdpAdobe RtcdpAdobe Tags (Launch)Aep SdkCustomer Data PlatformCustomer Journey AnalyticsGoogle AnalyticsMarketing Automation PlatformsPower BITableau
Cloud • Security • Software • Cybersecurity • Automation
Lead technical direction and architecture for DAP Repository Flows, design and ship autonomous and scheduled agents that operate on customer repositories, improve DAP onboarding, collaborate across teams on platform interfaces, mentor engineers, and solve high-scale technical problems to raise engineering quality.
Top Skills:
Autonomous AgentsDuo Agent Platform (Dap)GitlabLarge Language Models (Llms)RubyRuby On RailsSlack
What you need to know about the Seattle Tech Scene
Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.
Key Facts About Seattle Tech
- Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Amazon, Microsoft, Meta, Google
- Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
- Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Madrona, Fuse, Tola, Maveron
- Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute


