← Back to all positions

Windows Escalation Engineer — Directory Services

Full-time

IT Infrastructure · Remote (US, Pacific Time) · Posted 2026-05-04

When our Tier 2 support team exhausts their playbook on a replication issue or a Kerberos authentication failure, it lands on your desk. We need someone who has run dcdiag more times than they've had hot meals and can tell you the USN of the last successful inbound replication without looking at the screen.

Responsibilities

  • Serve as Tier 3 escalation point for Active Directory, DNS, Kerberos, and Group Policy issues across a 12-domain controller environment
  • Diagnose and resolve replication failures — lingering objects, USN rollbacks, strict replication consistency violations
  • Manage FSMO role placement, transfer, and seizure procedures — including forest recovery planning
  • Operate and maintain internal AD CS PKI: CRL publication, OCSP responder health, certificate template governance, key archival and recovery
  • Own the forest functional level upgrade plan from Windows Server 2016 to 2025 — including schema updates, prep commands, and rollback strategy
  • Maintain Privileged Access Management: tiered admin model enforcement, PAW compliance monitoring, LAPS rotation verification
  • Document root cause analysis for all escalated incidents — timeline, diagnostic evidence, resolution, preventive measures

Requirements

  • 8+ years of Active Directory administration, with at least 3 in an escalation/engineering role
  • Expert-level diagnosis skills: dcdiag, repadmin, nltest, ntdsutil, ldifde, csvde, netdom query fsmo
  • Deep understanding of AD replication internals: USN, high-watermark vectors, up-to-dateness vectors, linked value replication
  • Experience with AD forest recovery — authoritatively restoring deleted objects, recovering from USN rollback
  • Strong knowledge of Kerberos: TGT, service tickets, PAC, SID filtering, claims, FAST, armoring
  • Experience with Group Policy troubleshooting — gpupdate /force, gpresult /h, RSoP logging, slow link detection
  • Comfortable with packet-level network analysis (Wireshark) for Kerberos and LDAP traffic

Nice to Have

  • Microsoft Certified Master: Directory Services (if you're that old) or equivalent deep expertise
  • Experience with Azure AD Connect troubleshooting — duplicate attribute errors, metaverse search, connector space analysis, MIISClient
  • Knowledge of SCOM management packs for Active Directory monitoring
  • Experience with Active Directory Migration Tool (ADMT) for inter-forest migrations

Apply for this position

Send us your resume and a brief cover letter. We review every application.

Apply Now

We respond within 5 business days.