CPI International

Sr. System Engineer - Active Directory Infrastructure

CPI International$110K — $130K *
Plano, TX 75025In-Person
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • U.S. Citizenship is required; no employment authorization through EAD or visa will be considered.
  • Advanced knowledge of Active Directory (AD) in multi-forest/domain/tenant environments.
  • Experience with AD consolidation, migration, and cleanup.
  • Advanced Windows Server administration and troubleshooting skills.
  • Strong expertise in Windows patch management using MECM/Configuration Manager or Intune.
  • Proficiency in PowerShell scripting and automation.
  • Hands-on experience with Microsoft Entra ID and hybrid identity management.

Responsibilities

  • Serve as primary administrator and technical SME for Microsoft Active Directory Domain Services (AD DS) in a complex environment.
  • Design and optimize Group Policy Objects (GPOs) and security filtering.
  • Lead Active Directory cleanup and restructuring, addressing stale accounts and unnecessary policies.
  • Administer Microsoft Entra ID, including directory synchronization and authentication.
  • Troubleshoot complex issues related to AD, Group Policy, and DNS.
  • Oversee Windows Server and endpoint patching processes and compliance reporting.
  • Collaborate with security and infrastructure teams on hardening efforts and disaster recovery planning.

Benefits

  • Opportunity to work remotely with a small, collaborative team.
  • Hands-on involvement in critical infrastructure projects and modernization efforts.
  • Engagement with advanced technologies including hybrid identity management and AI infrastructure.
  • Focus on security hardening practices and compliance in regulated environments.
  • Opportunity for continuous learning and improvement in a senior technical role.
Full Job Description
CPI is seeking a Senior Systems Engineer - Active Directory & Infrastructure to join our three-person infrastructure team. This remote position is a hands-on senior role and the primary technical owner for Microsoft Active Directory Domain Services (AD DS), Group Policy, hybrid identity, and Windows patching.

The successful candidate will have deep experience with enterprise Active Directory and Windows environments and will lead efforts involving AD consolidation, directory and Group Policy cleanup and maintenance, security hardening, lifecycle management, and patching. The role also provides cross-functional backup for virtualization, compute, storage, backup, and other infrastructure platforms.

U.S. Citizenship is required. Candidates requiring employment authorization through an EAD, visa, or other non-citizen work authorization are not eligible for consideration.

Primary Responsibilities

  • Serve as the primary administrator and technical SME for Microsoft Active Directory Domain Services (AD DS), in a multi-forest, multi-domain, and multi-tenant environment.

  • Design, implement, maintain, troubleshoot, and optimize Group Policy Objects (GPOs), security/WMI filtering, and policy performance.

  • Lead Active Directory consolidation, cleanup, restructuring, and modernization, including remediation of stale accounts/objects, legacy configurations, unnecessary policies, excessive privileges, and other directory complexity.

  • Administer and support Microsoft Entra ID and hybrid identity, including directory synchronization and authentication/authorization across on-premises and cloud environments.

  • Troubleshoot complex AD, Group Policy, DNS, Kerberos, NTLM, certificates, authentication, authorization, and replication issues.

  • Own and improve Windows Server and endpoint patching, using MECM/Configuration Manager and Intune including patch planning, deployment, compliance reporting, troubleshooting failed updates, and remediation of vulnerable or unsupported systems.

  • Provide senior-level backup and troubleshooting support for VMware compute/virtualization, NetApp storage, Rubrik backup and recovery, and related infrastructure.

  • Work with security and infrastructure teams on AD security hardening, privileged access, least privilege, vulnerability remediation, disaster recovery, and business continuity.


Required Qualifications & Technical Skills

  • U.S. Citizenship is required. Candidates requiring employment authorization through an EAD, visa, or other non-citizen work authorization are not eligible for consideration.

  • Advanced knowledge of AD with strong hands-on experience administering and troubleshooting multi-forest/domain/tenant environments

  • Experience with AD consolidation, migration, cleanup, restructuring, or modernization.

  • Advanced Windows Server administration and troubleshooting experience.

  • Strong experience with Windows patch management, vulnerability remediation, and systems lifecycle management leveraging MECM/Configuration Manager and/or Intune.

  • Strong PowerShell scripting and automation skills.

  • Hands-on experience with Microsoft Entra ID, hybrid identity, and directory synchronization.

  • Working knowledge of Kerberos, NTLM, SAML, OAuth/OIDC, AD CS, DNS, DHCP, and networking dependencies.

  • Ability to troubleshoot across infrastructure layers and work independently in a small, collaborative infrastructure team.

  • Strong documentation, communication, troubleshooting, and root-cause analysis skills.

  • Security and Compliance perspective, NIST 800-43, 171, CMMC, CUI, ITAR, ECI


Preferred Qualifications

  • Bachelor's degree in Computer Science, Information Technology, or similar.

  • Experience with Active Directory security hardening, privileged access management, and least-privilege design.

  • Experience supporting VMware, NetApp, and/or Rubrik environments.

  • Experience with disaster recovery, business continuity, infrastructure monitoring, and enterprise lifecycle management.

  • Microsoft certifications related to Windows Server, Azure/Entra Identity, or Security.

  • Experience supporting regulated, defense, aerospace, or other security-sensitive environments.

  • Strong Linux administration experience and familiarity with Docker/containerized workloads.

  • Familiarity with Microsoft Azure Government / GCC High, including identity, security, networking, and compliance considerations.

  • Experience supporting AI infrastructure, agentic AI platforms, MCP (Model Context Protocol), AI gateways, or enterprise integration of AI workloads with identity and access controls.


Ideal Candidate

The ideal candidate is a hands-on infrastructure engineer who takes ownership, understands Active Directory at a deep technical level, and can independently diagnose and resolve difficult identity and Windows problems. You should enjoy cleaning up and improving environments, not simply maintaining them, and be comfortable balancing AD engineering, patching, security, automation, and broader infrastructure support in a small team.

About CPI International

CPI International is a leading provider of microwave, radio frequency, power and control solutions for critical defense, communications, medical, scientific and other applications. The company has a long history of innovation and has been at the forefront of many technological advancements in its field. CPI International is committed to providing its customers with the highest quality products and services, and has a strong reputation for reliability and performance. The company is headquartered in Palo Alto, California, and has operations in the United States, Europe and Asia.
Learn more about CPI International
Industry
Founded
1948

Similar Jobs

More Jobs at CPI International

More Information Technology Jobs

Find similar Sr. System Engineer - Active Directory Infrastructure jobs: