FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Windows Platform Engineer
Tech Holding. Improve Active Directory and DNS resilience, including replication topology and health, FSMO roles, DFS-R, NTDS, AD-integrated DNS, and cloud-instance domain controllers .
Tech Stack
Tools & technologiesAnsibleChefCloudDNS
About the role
Key responsibilities & impact- Improve Active Directory and DNS resilience, including replication topology and health, FSMO roles, DFS-R, NTDS, AD-integrated DNS, and cloud-instance domain controllers
- Support migration from NTLM to Kerberos without an outage during the transition
- Work with SPNs, constrained delegation, encryption types, managed service accounts, group managed service accounts, and reverse DNS
- Support identity integration across Windows and non-Windows environments, including LDAP, desktop and cloud single sign-on, and brokered application identity
- Support and improve golden image and patch pipelines, including automated image builds, CI scheduling, promotion, deprecation, deregistration, and CVE-driven rebuilds
- Improve Windows observability through infrastructure agents, service and event-channel collection, script-derived metrics, health monitoring, replication status, and log forwarding
- Develop and maintain PowerShell automation for Windows platform operations and resiliency
- Support Infrastructure as Code and configuration management using Chef, Ansible, Systems Manager, guardrail policies, pipeline validation, and OpenTofu
- Support multi-account rebuilds, guardrail policies, and module compliance
- Strengthen security and data-protection controls, including block-storage encryption, key management, web-tier protection, and instance metadata hardening
- Improve PKI and certificate-services resilience
- Support disaster recovery design, cloud platforms, and file services, including RTO/RPO planning, recovery strategies, failover testing, and divisional cloud accounts
- Support file-services resilience and legacy distributed-file-system decommissioning targeting zero RPO and sub-five-minute RTO
- Define, test, and document Active Directory backup, restore, and forest recovery
- Define the NTLM decommission path and audit remaining NTLM use
- Establish certificate inventory and expiry alerting
- Address or document the future state of the directory privileged-access model
- Exercise directory-specific recovery testing
- Rationalize the Windows image catalogue and multi-tenant configuration
- Confirm whether Group Policy is unused or unmanaged
Requirements
What you’ll need- Expert-level experience with Active Directory and DNS resilience, including replication topology and health, FSMO roles, DFS-R, NTDS, AD-integrated DNS, and domain controllers
- Expert-level knowledge of Kerberos authentication, including SPNs, duplicate-SPN failure modes, constrained delegation, AES/RC4 encryption, managed service accounts, group managed service accounts, and reverse DNS dependencies
- Strong experience with identity integration across Windows and non-Windows environments, including LDAP and single sign-on
- Expert-level experience with golden image and patch pipelines, including image bake automation, CI-scheduled builds, promotion, deprecation, deregistration, and CVE-driven rebuilds
- Strong Windows observability and PowerShell experience
- Strong experience with Infrastructure as Code and configuration management, including OpenTofu and tools such as Chef, Ansible, and Systems Manager
- Strong understanding of cloud infrastructure, security, data-protection controls, and infrastructure automation
- Strong experience with PKI and certificate services
- Strong experience with disaster recovery design, including RTO/RPO, recovery strategies, failover testing, and Windows file services
- Ability to work as a platform and automation engineer in a code-managed Windows environment rather than relying on traditional Windows administration practices
- Ability to work independently across complex, business-critical Windows infrastructure and communicate technical decisions clearly
- Applicants must be authorized to work for any employer in the U.S.; visa sponsorship is unavailable
Benefits
Comp & perks- Equal Opportunity Employer committed to a diverse and inclusive workplace
- Application-process accommodations available upon request