Job Description
A major client of Insight Global is seeking a Senior IT Infrastructure Engineer focused on Active Directory. This role requires deep expertise in AD DS, Group Policy, DNS/DHCP, PKI alignment, replication, and hybrid identity integration—with Zero Trust architecture instincts and the security depth to back them up. You'll serve as the technical leader for identity operations and collaborate closely with security, cloud, application, and infrastructure peers.
Responsibilities
Identity, Active Directory, and hybrid directory
Design, implement, and maintain Active Directory (sites, replication, OU/GPO models, trust relationships) and closely coupled services (DNS, DHCP) with clear standards and change control.
Implement and evolve hybrid identity patterns (for example Microsoft Entra ID / Connect, hybrid join, federation concepts, conditional access alignment) in partnership with security and cloud teams.
Enforce identity, privileged access, and Group Policy practices that meet audit and risk expectations; support certificate and authentication models where they touch AD.
Lead recovery and forest/domain health scenarios with documented playbooks and measurable recovery objectives.
Infrastructure and cloud operations
Design and maintain hybrid infrastructure spanning on-premises and cloud platforms, with identity as the integration layer across workloads.
Operate and support VMware ESXi and vCenter environments that host directory-related and dependent workloads.
Support enterprise storage (SAN/NAS) for performance, redundancy, and recoverability of identity and infrastructure services.
Collaborate with the Citrix team to ensure AD authentication, GPO policies, and session delivery integration are correctly configured—you influence identity behavior here, not platform administration.
Manage enterprise backup and recovery for critical identity and infrastructure targets; validate restores and retention against policy.
Perform routine maintenance, upgrades, and patching across servers, virtualization, and cloud-connected systems with minimal customer impact.
Service optimization and cost management
Evaluate and optimize resource utilization across on-premises and cloud platforms.
Recommend and implement cost-aware strategies for compute, storage, and cloud consumption.
Analyze trends and propose improvements that increase service efficiency and availability.
Security, compliance, and risk management
Drive security hardening across AD, servers, virtualization, and connected cloud services—including Tiered Administration (PAW model), LAPS deployment, and Microsoft Defender for Identity for real-time threat detection across the directory.
Monitor and remediate vulnerabilities through patching, configuration management, and risk mitigation aligned to SLAs.
Maintain compliance with corporate policies, audit requirements, and industry standards.
Technical leadership and support
Serve as a senior escalation point for infrastructure incidents and problems with an identity-centric lens.
Lead technical root cause analysis and implement durable corrective actions.
Mentor junior engineers and contribute to infrastructure engineering standards and patterns.
Participate in planning and executing major projects, migrations, and deployments.
Performance monitoring, capacity, and documentation
Monitor performance across servers, virtualization, storage, and cloud services; conduct capacity planning for compute, storage, and network resources.
Implement monitoring and alerting for proactive detection of directory and platform issues.
Create and maintain technical documentation, diagrams, build guides, SOPs, and compliance evidence; report on health, performance, and posture.
Collaboration and stakeholder engagement
Partner with application, security, cloud, and networking teams for end-to-end solutions.
Work with business stakeholders to translate requirements into scalable, supportable designs
Communicate clearly to technical and non-technical audiences.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Required Skills & Experience
7–10+ years in IT infrastructure engineering or systems administration roles.
Proven experience supporting large, enterprise-scale Active Directory and hybrid cloud environments.
Experience with AD DS, Group Policy, OU design, replication, DNS/DHCP, RBAC models, PKI integration points, Tiered Administration (PAW model), and LAPS.
Hybrid Cloud infrastructure: on-premises to cloud integrations, identity federation patterns, hybrid join, conditional access alignment with security
Strong hands-on experience with VMware virtualization, storage systems, and enterprise backup solutions.
Vmware: ESXi, vCenter, clustering, vMotion, HA/DRS, templates, snapshots (used responsibly).
Storage systems: SAN/NAS management, iSCSI/FC, performance tuning, redundancy strategies.
Backup and recovery: enterprise backup platforms (for example Veeam, Commvault, Rubrik), DR strategies, offsite retention.
Demonstrated experience in Citrix environments and remote desktop or VDI infrastructure.
Background in high-availability, security, and compliance-conscious environments.
Nice to Have Skills & Experience
Cloud platforms: Microsoft Entra / Azure AD, Azure IaaS/PaaS services, identity lifecycle, cloud networking.
Citrix technologies: Virtual Apps and Desktops, StoreFront, Citrix Gateway, profile management, licensing.
Scripting and automation: PowerShell, automation workflows, configuration-as-code familiarity.
Monitoring and observability: tools such as SolarWinds, SCOM, vROps, Azure Monitor, Log Analytics.
Networking fundamentals: TCP/IP, firewalls, load balancing, VLANs, routing basics, zero trust principles.
Strong communicator with the ability to navigate stakeholder relationships across technical and non-technical audiences, maintain rigorous documentation discipline, and drive outcomes through cross-team collaboration.
Familiarity with approved LLM or AIOps tooling applied to identity telemetry and runbook quality is a plus.
Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.