Active Directory Remediation Architect
About the role
Job Summary
We are looking for a hands-on Active Directory expert who can assess, remediate, and where necessary redesign and rebuild Active Directory across a complex, multi-forest enterprise estate. This is a high-technical-risk, high-visibility role at the center of a broader identity and infrastructure security modernization effort - a healthy, correctly redesigned AD is the foundation everything else depends on.
Domain Controllers in the environment span a wide range of Windows Server versions, including legacy, end-of-life DCs that will require greenfield rebuilds rather than in-place remediation. You will own the full arc - from diagnosis of schema, replication, and DNS health, through account cleanup and least-privilege RBAC design, to standing up a clean, defensible AD foundation.
This is a delivery role for someone who is equally comfortable writing the automation and rolling up their sleeves for the manual rebuilds that automation can't safely touch.
What you'll do
● Assess and remediate multiple Active Directory forests across a segmented network estate; produce clear remediation-versus-rebuild recommendations per environment.
● Diagnose and fix schema health, replication, and DNS alignment issues across forests.
● Perform greenfield rebuilds of legacy Domain Controllers where in-place remediation is not safe, with a documented cutover plan and no unplanned outages to line-of-business applications.
● Design and implement a least-privilege RBAC role model; conduct a full account audit and map ownership for every user, service, and privileged account.
● Eliminate shared, unnamed, and orphaned accounts; document exceptions where accounts cannot be cleanly remediated.
● Enforce password and authentication policy via Group Policy; deploy and validate hardening GPOs without breaking LOB applications.
● Build and run automation and diagnostic tooling - AD health scripts, replication diagnostics, account audit tooling, DNS cleanup scripting - and handle manual remediation where automation cannot be applied.
● Produce as-built and account-audit documentation: forests healthy, replication clean, no EOL DCs without a documented plan, and zero unnamed or shared accounts without a documented exception.
What we're looking for
● 8+ years of hands-on Active Directory engineering, with deep, demonstrable experience remediating and rebuilding multi-forest, multi-domain environments.
● Proven track record of Domain Controller rebuilds and migrations, including retiring legacy DCs and modernizing to current Windows Server.
● Strong command of AD internals: schema, FSMO roles, replication (repadmin/dcdiag), sites and services, trusts, and integrated DNS/DHCP.
● Expertise in RBAC and least-privilege design, tiered administration models, and privileged account cleanup.
● Fluency in Group Policy design, hardening, and troubleshooting (CIS benchmarks a plus).
● Strong PowerShell automation skills; experience with AD assessment tooling such as ADRecon, PingCastle, or equivalent.
● Experience delivering to a compliance framework - NIST 800-171 / CMMC 2.0 and/or ISO/IEC 27001:2022.
● Ability to work independently over VPN, document rigorously, and communicate risk clearly to technical and program stakeholders.
● Must be a U.S. person (U.S. citizen or lawful permanent resident) - required for access to controlled systems.
Nice to have
● Experience with modern identity and privileged-access tooling (MFA, PAM, identity-protection platforms) integrated against Active Directory.
● Familiarity with Linux/AD integration (SSSD, realm join) and hybrid identity.
● Exposure to enterprise security monitoring and audit tooling.
● Prior work in regulated / defense-adjacent or manufacturing environments.
● Relevant certifications (e.g., Microsoft Identity & Access, security certifications).
Engagement details
This is a project-based contract. Work is primarily remote and delivered via VPN, with occasional on-site travel as required (travel agreed and reimbursed separately). Hours will scale with the AD topology and the extent of greenfield rebuilds required.
If you are an AD specialist who is energized by untangling and rebuilding a real, messy, multi-forest estate the right way, we'd like to talk.
This role is restricted to U.S. persons (U.S. citizens or lawful permanent residents). Applicants must be authorized to work in the U.S. This role involves access to sensitive systems; background screening may apply.
Pay: $50.00 - $65.00 per hour
Application Question(s):
Are you a U.S. person (U.S. citizen or lawful permanent resident)? This role requires access to controlled systems and is restricted to U.S. persons.
How many years of hands-on experience do you have remediating and rebuilding multi-forest / multi-domain Active Directory environments, including greenfield Domain Controller rebuilds and retiring legacy/EOL DCs? Share an example.
Have you designed a least-privilege RBAC / tiered-admin model AND deployed hardening Group Policy at scale, using PowerShell and AD assessment tooling (e.g., ADRecon, PingCastle)?
Are you 1099 or you have an employer?
Work Location: Hybrid remote in Seattle, WA 98101
Compensation
This Other role pays $50k-$65k/yr. Within typical range for other roles in United States.
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.