Intone Networks logo

Active Directory SME (Identity Security)

Intone Networks

RemoteFull timeMid levelPosted today
Apply with JobAssist

About the role

Job Description:
Cargill's Identity Security team is seeking a highly experienced Active Directory Subject Matter Expert (SME) to help modernize and optimize its enterprise Active Directory environment. This is a senior-level engineering role for someone who can independently design, implement, and improve large-scale AD environments while extending Active Directory into AWS and other cloud platforms. The ideal candidate is a hands-on Active Directory expert who thrives in complex enterprise environments, is comfortable working with minimal direction, and can balance engineering execution with long-term architecture and strategy.

Required Experience
• 8+ years of hands-on Active Directory engineering experience (6 years minimum)
• Extensive enterprise Active Directory design, implementation, and administration
• Experience building new AD environments and decommissioning legacy environments
• Strong understanding of hybrid identity and cloud integrations
• Ability to lead technical initiatives with minimal supervision

Core Technical Skills
Active Directory (Highest Priority)
• Active Directory architecture and engineering
• Domain and forest design, migrations, and consolidations
• Domain controller deployment, promotions, and demotions
• Organizational Units (OUs)
• Group Policy (GPO)
• Sites & Services
• User and computer administration
• Domain joins
• AD health, performance, and troubleshooting

Cloud Identity
• AWS Managed Microsoft AD / Active Directory integration (highest priority after AD)
• Microsoft Entra ID (Azure AD)
• Google Cloud Platform (nice to have)

Modern Infrastructure & Automation
Experience with modern infrastructure engineering practices is highly preferred, including:
• Infrastructure as Code (IaC)
• Terraform
• Ansible
• GitHub
• CI/CD pipelines
• Jenkins
• DevOps / SecDevOps practices

Key Responsibilities
• Design, implement, and modernize enterprise Active Directory environments
• Build and decommission Active Directory domains and forests
• Improve hybrid connectivity between on-premises Active Directory and AWS
• Manage domain controllers, GPOs, Sites & Services, and overall AD health
• Automate Active Directory administration and operational tasks
• Partner with Identity & Access Management teams on AD integrations
• Support Identity Governance (IGA) and Privileged Access Management (PAM) initiatives
• Troubleshoot complex AD issues and perform root cause analysis
• Mentor engineers and share technical knowledge across the team

Role Evolution
Early in the Engagement
• 80% hands-on Active Directory engineering
• 20% architecture and strategy

As the Engagement Progresses
• 80% architecture, modernization, and technical leadership
• 20% hands-on engineering
• Mentor Cargill engineers and help shape long-term AD strategy

Ideal Candidate Profile
We're looking for candidates with experience in:
• 8–15+ years of Active Directory engineering
• Large enterprise Active Directory environments
• AD migrations, consolidations, and modernization initiatives
• AWS Managed Microsoft AD or hybrid Active Directory
• Microsoft Entra ID
• Infrastructure as Code (Terraform, Ansible)
• GitHub and CI/CD automation
• Architecture and hands-on engineering
• Leading technical initiatives and mentoring engineers

Preferred Qualifications
• Experience supporting Identity Governance (IGA) or Privileged Access Management (PAM) solutions (specific platforms not required)
• Microsoft, AWS, CyberArk, or SailPoint certifications are a plus, but hands-on experience is valued more than certifications

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at Intone Networks was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.