Active Directory (AD) and Tier-0 Infrastructure Automation Engineer

Apply for

Active Directory (AD) and Tier-0 Infrastructure Automation Engineer

Apply for this position

Allowed Type(s): .pdf, .doc, .docx

Company Description

A leading global commercial vehicle manufacturer specializing in trucks and buses, with a strong presence across North America, Europe, and Asia. The company is recognized for its engineering excellence, strong brand portfolio, and focus on delivering reliable and efficient transportation solutions at scale.

Job Summary

The Active Directory (AD) and Tier-0 Infrastructure Automation Engineer is responsible for designing, securing, automating, and modernizing enterprise authentication platforms. The role focuses on Tier-0 security hardening, identity infrastructure resilience, Active Directory modernization, Infrastructure-as-Code, self-healing automation, and AI-assisted identity operations while maintaining strict security controls for privileged environments.


Key Responsibilities

  • Own and improve Tier-0 identity infrastructure including AD DS forests/domains, Domain
  • Controllers, DNS, PKI dependencies, ADFS where applicable, and privileged access pathways.
  • Implement Tier-0 security hardening through secure administration tiers, PAW/SAW strategies, GPO baselines, authentication policies, and privileged group governance.
  • Design and execute AD modernization initiatives including domain restructuring, consolidation/separation, trust management, and authentication redesign.
  • Ensure business continuity through backup/restore drills, authoritative restores, Domain Controller recovery, tombstone/lingering object prevention, and disaster recovery readiness.
  • Perform Tier-0 risk assessments and remediate delegation risks, unconstrained delegation, weak ACLs, stale privileged accounts, and legacy authentication protocols.
  • Build AD operational automation using advanced PowerShell and Python, including user/group/OU lifecycle workflows, GPO deployment validation, DC health monitoring, DNS and replication checks, and privileged group reviews.
  • Implement Infrastructure-as-Code patterns through automation pipelines, configuration baselines, and golden templates.
  • Develop self-service identity capabilities with approval workflows, audit trails, and rollback mechanisms.
  • Integrate AI-assisted workflows for incident triage, root-cause analysis, runbook recommendations, and internal knowledge management.
  • Establish AI guardrails for Tier-0 environments, including data classification, redaction, privileged-secret protection, auditability, and approval gates.
  • Own identity logging pipelines using platforms such as Microsoft Sentinel, Splunk, ELK, or Log Analytics.
  • Develop dashboards and alerts covering AD health, authentication anomalies, replication issues, and privileged-access abuse.
  • Support SOX, ISO/IEC, and industry compliance audits through evidence collection, control mapping, and remediation tracking.
  • Collaborate with Cybersecurity, IAM, Networking, Endpoint Engineering, and GRC teams.
  • Provide technical documentation, runbooks, architecture diagrams, and executive summaries.
  • Participate in on-call and major incident bridge support for Tier-0 services when required.

Required Skills & Experience

  • 5+ years of experience in Active Directory engineering/operations within large enterprise environments.
  • Strong hands-on expertise in:
    AD DS
    Domain Controllers
    Sites & Services
    DNS
    Kerberos / NTLM
    Active Directory trusts
  • Strong understanding of Tier-0 security concepts, privileged administration models, and GPO security baselines.
  • Experience troubleshooting AD replication, authentication failures, and Domain Controller recovery.
  • Advanced PowerShell automation skills, including scripting standards, modules, and CI/CD integration.
  • Familiarity with Python.
  • Experience with security monitoring, identity analytics, and log analysis.

Preferred Qualifications

  • Python automation experience.
  • Experience implementing Infrastructure-as-Code and self-healing automation.
  • Experience integrating AI-assisted operations into identity/security environments.
  • Experience with Microsoft Sentinel, Splunk, ELK, or Log Analytics.
  • Exposure to PAM, hybrid identity, and enterprise compliance environments.

Other Requirements

  • Strong understanding of privileged/Tier-0 security boundaries.
  • Ability to work with multiple security and infrastructure teams.
  • Strong documentation and technical communication skills.
  • Ability to participate in on-call and major incident support.
  • Ability to implement AI solutions while maintaining security, compliance, auditability, and approval controls.

Similar Jobs

Don't see an opportunity that's a fit?

Join our Talent Community to stay updated on Reed & Willlow’s latest news and job openings. New opportunities arise often, and we’d love to stay connected!

More opportunities

Discover job opportunities curated to match your interests.

Apply for

Active Directory (AD) and Tier-0 Infrastructure Automation Engineer

Apply for this position

Allowed Type(s): .pdf, .doc, .docx

Send us a message

Got questions? Need to chat with an expert?

Send us a message

Got questions? Need to chat with an expert?