Active Directory Customer Engineer

Sonata Software — Germany · Posted ~3 hours ago

Senior Full-time Remote

Skills

Active Directory AD DS Azure AD Entra ID PowerShell Group Policy identity management LDAP

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A senior identity engineering role designing and managing enterprise directory environments. Responsibilities include architecture, security governance, automation, and support for complex hybrid identity solutions.

Highlights

Fully remote senior infrastructure role focused on enterprise identity architecture, security, and large-scale directory environments.

Description

Position: Active Directory Domain Services Engineer Location: Germany Work Mode: Remote Experience: 10+ years Role Overview We are seeking an experienced Active Directory Domain Services (AD DS) Engineer with strong expertise in designing, architecting, and managing enterprise-scale AD environments. The ideal candidate will have deep knowledge of hybrid identity (Entra ID / Azure AD), multi-domain forest design, and governance best practices. Key Responsibilities Design & Architecture Design and manage multi-domain forest architectures.Plan and implement forest trusts and domain controller capacity.Define FSMO role placement and OU topology design.Develop Active Directory site topology and Group Policy (GPO) strategies.Establish privileged account management following the Tier Model.Design and implement delegation of permissions and group management best practices.Integrate third-party LDAP applications with AD.Deploy and manage Read-Only Domain Controllers (RODCs).Utilize PowerShell scripting for automation and configuration management.Hybrid Identity & Synchronization Implement and manage Microsoft Entra Connect for hybrid identity.Maintain synchronization between Active Directory and Entra ID (Azure AD).Troubleshooting & Performance Troubleshoot GPO policy processing, SYSVOL, and AD replication issues.Diagnose Domain Controller performance and authentication failures, including cross-forest authentications.Upgrade & Maintenance Plan and execute Domain Controller OS upgrades.Manage functional level upgrades and ensure compatibility.Operational Governance Adhere to change control and patch management best practices.Ensure compliance with operational governance standards.Recovery & Continuity Perform Active Directory forest and object recovery operations.Maintain disaster recovery readiness for directory services.Networking & Infrastructure Strong understanding of IPv4/IPv6, Active Directory–integrated DNS, and secure dynamic updates.Manage DHCP design, deployment, and operations.Configure Windows Firewall in alignment with best practices.Ensure compliance with port and protocol requirements for Active Directory services. Qualifications Proven hands-on experience with Active Directory Domain Services in large-scale enterprise environments.Strong background in Microsoft Entra ID / Azure AD integration and hybrid identity solutions.Proficiency in PowerShell scripting for automation.In-depth knowledge of networking fundamentals and Windows Server administration.Excellent problem-solving and troubleshooting skills. Why join Sonata Software? At Sonata, you´ll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what´s possible. To build never seen before solutions to some of the world’s toughest problems. You´ll be challenged, but you will not be alone. You´ll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next. Sonata Software is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity, age, religion, disability, sexual orientation, veteran status, marital status, or any other characteristics protected by law