1

Active Directory Migration Engineer Jobs in California

L3 Active Directory Engineer

San Francisco, CA ยท On-site

$62.25 - $81.25/hr

Job Role: L3 Active Directory Engineer / AD SME Location: SFO, CA (Hybrid) Type: Fulltime L3 ... Perform AD migration, consolidation, restructuring, and domain/forest trust design. * DNS, DHCP ...

Plan, schedule, and execute device migration waves from on-premises Active Directory / hybrid ... Entra ID Engineering Support (Primary Focus):Provide engineering-level administration and ...

Staff Security Operations Engineer

Irvine, CA ยท On-site

$127K - $216K/yr

Plan, schedule, and execute device migration waves from on-premises Active Directory / hybrid ... Entra ID Engineering Support (Primary Focus): * Provide engineering-level administration and ...

Plan, schedule, and execute device migration waves from on-premises Active Directory / hybrid ... Entra ID Engineering Support (Primary Focus): * Provide engineering-level administration and ...

... Active Directory migration for the Department of Human Assistance. Candidate should have the ability to: * Operate, maintain, and perform repairs on information technology equipment and software.

next page

Showing results 1-20

Active Directory Migration Engineer information

What is the difference between Active Directory Migration Engineer vs Active Directory Administrator?

AspectActive Directory Migration EngineerActive Directory Administrator
Primary FocusPlanning and executing Active Directory migrations and upgradesManaging and maintaining Active Directory environments daily
Required SkillsMigration tools, scripting, troubleshooting migration issuesUser account management, group policies, security settings
CertificationsMicrosoft Certified: Windows Server, MCSEMicrosoft Certified: Windows Server, MCSA
Work EnvironmentProject-based, migration-specific tasksOperational, ongoing management of AD

While both roles require strong Windows Server and Active Directory knowledge, the Active Directory Migration Engineer specializes in migration projects, whereas the Active Directory Administrator focuses on daily management and support of AD environments.

What are popular job titles related to Active Directory Migration Engineer jobs in California? For Active Directory Migration Engineer jobs in California, the most frequently searched job titles are:
What job categories do people searching Active Directory Migration Engineer jobs in California look for? The top searched job categories for Active Directory Migration Engineer jobs in California are:
What cities in California are hiring for Active Directory Migration Engineer jobs? Cities in California with the most Active Directory Migration Engineer job openings:

L3 Active Directory Engineer

HCLTech

San Francisco, CA โ€ข On-site

$62.25 - $81.25/hr

Other

Posted 19 days ago


Job description

Job Role: L3 Active Directory Engineer / AD SME

Location: SFO, CA (Hybrid)

Type: Fulltime

Job Description: L3 Engineer / SME Active Directory (OnPremise)

Experience: 7 12+ years

Domain: Identity & Access Management, Windows Infrastructure

Role Summary

We are looking for a highly skilled L3 Active Directory (OnPremise) SME with deep experience in designing, managing, and troubleshooting complex AD environments. The candidate will be the highest escalation point for AD issues, lead architectural improvements, perform RCA, and ensure AD security, availability, and performance in a large enterprise environment.

Key Responsibilities

  1. L3 Escalation & Technical Support

Serve as the toptier escalation for Active Directory and Windows infrastructure issues.

Troubleshoot complex authentication, replication, DNS, GPO, policy processing, and trust issues.

Perform advanced RCA, log analysis, and performance debugging.

Develop L3 SOPs, KB articles, scripts, and automation for operations teams.

  1. Active Directory Administration & Architecture

Manage and maintain large multidomain, multiforest onprem AD environments.

Oversee FSMO roles, domain controllers (DC health), AD sites, replication topology.

Install, upgrade, and harden domain controllers (physical/virtual).

Implement AD schema updates, forest/domain functional level upgrades.

Perform AD migration, consolidation, restructuring, and domain/forest trust design.

  1. DNS, DHCP, & Windows Core Infrastructure

Troubleshoot AD-integrated DNS issues (zones, scavenging, forwarding, delegation).

Manage and secure DHCP scopes, reservations, failover.

Deep understanding of Kerberos, NTLM, LDAP, LDAPS, SPNs, tickets, token bloat.

Ensure GPO performance tuning, inheritance control, WMI filters, controlled rollouts.

  1. Security & Hardening

Implement AD security baselines, CIS benchmarks, and Microsoft security best practices.

Periodically audit domain controllers, replication, delegations, privileged groups.

Manage tiered admin model, least privilege, JustInTime (JIT) & JustEnoughAdministration (JEA).

Enforce password policies, PAM/Privileged Identity controls, and secure service account management.

Perform logs and event analysis through SIEM (Splunk, Sentinel, QRadar).

  1. High Availability & DR

Build and validate disaster recovery procedures for AD, DNS, and DHCP.

Maintain backup/restore strategies using tools like AD Recycle Bin, Authoritative Restore, System State, VM snapshots.

Ensure site resiliency, replication health, and multisite availability.

  1. Automation & Scripting

Automate AD operations using PowerShell (mandatory).

Build scripts for:

User provisioning/deprovisioning

Group management

GPO backup/restore

ACL/permissions

Health monitoring & reporting

  1. Integration & Identity Services

Expertise integrating AD with:

ADFS

Azure AD Connect (Sync rules, writeback, filtering)

SSO solutions

LDAPbased applications

PKI/Certification Services

Understand hybrid identity dependencies (even though this role is onprem focused).

Required Skills & Qualifications

7 12+ years handson experience in enterprise Active Directory environments.

Deep knowledge of:

AD architecture, design & security

DNS, DHCP, Sites & Services

Kerberos, LDAP, GPO, trusts, replication

Experience troubleshooting large, distributed Windows Server infrastructures.

Strong PowerShell automation skills.

Experience implementing AD hardening, security baselines, RBAC delegation.

Knowledge of backup/restore and DR strategies for domain controllers.

Strong understanding of networking fundamentals (TCP/IP, firewall rules, ports).

Preferred Skills

Microsoft certifications (AZ800, AZ801, MS100/101, SC300, MCSA/MCSE).

Experience with Azure AD and hybrid identity models.

Experience with IAM/PAM tools (Delinea, CyberArk, BeyondTrust).

Familiarity with virtualization (VMware/HyperV).

Experience with enterprise SIEM and security monitoring tools.