{"id":1629113,"url":"https://alion.io/job/ralliant-identity-engineer-active-directory","title":"Identity Engineer - Active Directory","company":{"id":2241821,"name":"Ralliant","domain":"ralliant.com","url":"https://alion.io/company/ralliant","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":{"grade":"B","score":75,"open_postings":19,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-06T05:45:30Z"}},"role":"Industrial Engineering","role_family":"Industrial Engineering","seniority":"staff","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":21000,"max_usd":47000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1251},"experience_years_min":10,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"DNS","optional":false},{"name":"GCP","optional":false},{"name":"ISO 27001","optional":false},{"name":"LDAP","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"PCI DSS","optional":false},{"name":"PKI","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"Rest API","optional":false},{"name":"SIEM","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-09-30T11:39:28Z","employer_posted_date":"2026-09-30","last_verified_at":"2026-10-06T21:11:14Z","board_verified":true,"closed_at":null,"days_open":6,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":6},"description":"Role description\nThe Identity Engineer is responsible for administering, securing, and supporting the enterprise's directory services and public key infrastructure (PKI) environment, with a primary focus on Microsoft Active Directory Certificate Services (AD CS), certificate lifecycle management, and hybrid directory architecture (multiple Active Directory domains and Microsoft Entra ID). This role ensures secure, reliable identity infrastructure that underpins authentication, encryption, and trust across the enterprise.\nThis role acts as both a platform administrator and a technical troubleshooter, resolving complex directory, certificate, and authentication issues across on-premises, cloud, and hybrid environments. The engineer partners closely with Security, Infrastructure, and Application teams to maintain a healthy directory and PKI foundation, issue and manage certificates, and respond quickly to incidents affecting directory availability or certificate trust.\nThe role is hands-on and execution-focused while embracing the Ralliant Business System (RBS) by embedding operational discipline, staff training, and continuous improvement into tools, workflows, and standard work so endpoint management is scalable, measurable, and repeatable. The role operates in service to the enterprise and operating companies, ensuring standardized Identity practices while adapting to regional and business-specific needs.\nKey responsibilities\nAdminister and maintain Active Directory Certificate Services (AD CS), including root and issuing certificate authorities, certificate templates, and enrollment policies.\n\nManage the end-to-end certificate lifecycle, including issuance, renewal, revocation (CRL/OCSP), and expiration monitoring across internal and public-facing systems.\n\nAdminister and maintain directory services (Active Directory, LDAP), including forest/domain architecture, replication health, group policy, OU structure, and schema management.\n\nManage hybrid identity synchronization via Azure AD Connect/Entra Connect, including sync rules, attribute flow, and troubleshooting synchronization failures.\n\nSupport Microsoft Entra ID administration where it intersects with directory and certificate-based authentication, including certificate-based authentication (CBA), conditional access, and device trust.\n\nConfigure and manage SSL/TLS certificate deployment for servers, applications, and network devices, ensuring proper chain validation and trust store management.\n\nTroubleshoot and resolve complex directory and certificate-related connectivity issues, including DNS resolution, Kerberos/NTLM authentication, LDAPS binding, and certificate chain validation.\n\nSupport authentication and authorization troubleshooting across Active Directory/LDAP, SAML, MFA, and SSO integrations as they relate to directory and certificate trust.\n\nDevelop PowerShell and Python/REST API scripts to automate certificate issuance/renewal, directory reporting, and PKI health monitoring.\n\nMonitor and analyze AD CS, directory, and network logs, supporting SIEM integration, PKI health monitoring, and incident response.\n\nApply directory and PKI security best practices, supporting compliance with frameworks such as SOX, PCI-DSS, NIST, and ISO 27001.\n\nPartner with Security, Infrastructure, and Application teams to plan certificate authority hierarchy, directory architecture changes, and migrations across enterprise and OpCo environments.\n\nDocument procedures, configurations, and incident reports, and train end users and application teams on certificate request processes and directory best practices.\n\nPlan and execute directory and PKI disaster recovery procedures, including CA backup/restore and directory forest recovery readiness.\n\nQualifications\nBachelor's degree recommended; equivalent experience considered.\n\n10+ years of experience in cybersecurity, systems administration, or identity and access management, with 5 + years hands-on experience administering Active Directory Certificate Services (AD CS) and enterprise PKI.\n\nStrong understanding of PKI architecture, including certificate authority hierarchy (root/issuing CAs), certificate templates, CRL/OCSP, and key management.\n\nDeep working knowledge of Active Directory and LDAP, including forest/domain design, replication, group policy, and schema administration.\n\nExperience with hybrid identity synchronization (Entra Connect or equivalent) and Microsoft Entra ID, including conditional access and certificate-based authentication.\n\nProficiency in DNS, Kerberos/NTLM authentication, and certificate chain troubleshooting across on-premises and cloud environments (AWS, Azure, GCP).\n\nExperience with SAML, MFA, and SSO authentication and authorization troubleshooting as it relates to directory and certificate trust.\n\nScripting experience in PowerShell and Python, with working knowledge of REST APIs and certificate automation tooling.\n\nExperience with log analysis and SIEM integration, incident response, and root cause analysis for directory and PKI environments.\n\nKnowledge of compliance frameworks (SOX, PCI-DSS, NIST, ISO 27001) and zero trust security principles.\n\nMicrosoft Certified: Identity and Access Administrator (SC-300) or equivalent certification preferred; cloud platform or security certifications (AWS, Azure, GCP, CISSP, CISM, Security+) a plus.\n\nStrong communication and documentation skills, with the ability to explain technical concepts to non-technical stakeholders and train end users and application teams.\n\nAbility to operate effectively across enterprise and OpCo environments, balancing global consistency with local context across multiple time zones and cultures.\n\nAlignment with Ralliant values and the Ralliant Business System (RBS), including continuous improvement, transparency, and ownership.","description_format":"text","description_chars":5816,"description_truncated":false,"requirements":{"experience_years_min":10,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":[],"lifecycle":[{"event":"open","at":"2026-10-01T21:16:28Z"}],"visa":[],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":5,"expected_fill_days":49,"reasons":["conf:1","stale_co","velocity","win:early","comp:brand"],"computed_at":"2026-10-06T05:45:30Z"},"pay":null,"html_url":"https://alion.io/job/ralliant-identity-engineer-active-directory","json_url":"https://alion.io/job/ralliant-identity-engineer-active-directory.json","meta":{"generated_at":"2026-10-06T23:03:36Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3992,"day_limit":5000,"remaining_today":1008,"minute_limit":60,"resets_at":"2026-10-07T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":2241821},"rest":"https://alion.io/mcp/rest/get_company?id=2241821"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fralliant-identity-engineer-active-directory"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fralliant-identity-engineer-active-directory"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fralliant-identity-engineer-active-directory"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/ralliant-identity-engineer-active-directory\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fralliant-identity-engineer-active-directory"}]}