Relomote
Remote JobsRelocation Jobs
Add companySaved
Relomote

Relomote is a job board for remote, hybrid, and relocation jobs — every listing AI-classified for the countries it actually hires from, or the visa and relocation support it offers.

LinkedInCrunchbase

Remote jobs by category

  • Remote Engineering & Development jobs
  • Remote Customer Support jobs
  • Remote Design jobs
  • Remote Marketing jobs
  • Remote Sales jobs
  • Remote Product jobs
  • Remote Data & Analytics jobs
  • Remote People & Talent jobs
  • Remote Writing & Content Creation jobs
  • Remote Finance jobs
  • Remote Legal & Compliance jobs
  • Remote Operations & Admin jobs
  • Remote Data Entry jobs
  • Remote Virtual Assistant jobs
  • Remote Education/Training jobs
  • Remote Healthcare/Clinical jobs
  • Remote Other jobs

Remote jobs by location

  • Work from anywhere jobs
  • Remote jobs in Africa
  • Remote jobs in Asia
  • Remote jobs in Europe
  • Remote jobs in Latin America
  • Remote jobs in Middle East
  • Remote jobs in North America
  • Remote jobs in Oceania
  • All remote jobs →

Relocation & visa sponsorship

  • Visa sponsorship jobs
  • Relocation package jobs
  • Relocate to Europe
  • Relocate to Germany
  • Relocate to Netherlands
  • Relocate to Spain
  • Relocate to Portugal
  • Relocate to Greece
  • Relocate to United Kingdom
  • Relocate to Canada
  • Relocate to Australia
  • Relocate to Sweden
  • Relocate to Switzerland
  • Relocate to Japan
  • Relocate to United Arab Emirates
  • All relocation jobs →

© 2026 RelomoteAboutPrivacyTerms

Contact [email protected] · Built by Mahmoud

Relomote
Remote JobsRelocation Jobs
Add companySaved
Astra North logo

Windows Active Directory L3 Support Engineer

Astra North
Posted 2 hours ago
🇨🇦Canada🏢Hybrid📁Engineering & Development
Is this job info correct?

Job Description Windows Active Directory L3 Support Engineer – NTLM, PowerShell, AD, LDAP Signing, Zero Trust, CyberArk Toronto, ON - Hybrid (4 Days WFO) This role is responsible for strengthening and modernizing Active Directory services across production and disaster recovery environments. The engineer will manage domain controller expansion and replacement, improve authentication and directory security controls, remediate privileged-access weaknesses, and harden Group Policy and network configurations to reduce attack paths and support resilient enterprise identity services. Key Responsibilities • Deploy and configure additional domain controllers across primary and disaster recovery sites, including DC01 and DC02, to improve availability, resilience, and site-level recovery readiness. • Replace legacy Windows Server 2016 domain controllers and support platform modernization activities with minimal service disruption. • Implement production and development network segmentation to reduce lateral movement risk and align identity services with Zero Trust principles. • Maintain Active Directory health across replication, authentication, DNS integration, and Group Policy processing. Security Hardening and Access Control • Enable Extended Protection for Authentication (EPA) and require SSL/TLS for privileged HTTP-based services such as AD CS and ADWS to reduce credential relay and man-in-the-middle exposure. • Enforce SMB signing to help prevent tampering and NTLM relay over SMB sessions. • Disable NTLMv1 and strengthen LDAP protections by enforcing LDAP signing and channel binding / LDAPS for directory communications. • Implement Kerberos armoring, restrict unconstrained delegation, tighten delegation permissions on privileged accounts, and address unknown delegation entries. • Remediate excessive privilege findings, including AdminCount issues, GPO-deployed file exposure, missing protective ACLs, and privileged accounts not enrolled in Protected Users. • Remove insecure legacy access patterns such as Pre-Windows 2000 compatible group usage and administrator logon allowances through Group Policy. • Enforce stronger password and privileged account controls, including a 12-character minimum complexity baseline, password expiration where appropriate, and smartcard password rotation requirements. • Identify and remediate risky account configurations such as PASSWD_NOTREQD, password never expires, admin accounts with email usage, and missing delegation restrictions. Group Policy, Logging, and Compliance • Harden Group Policy baselines by enforcing event audit logging, PowerShell logging, supported encryption types, remote desktop best-practice settings, and secure administrator sign-in controls. • Review and remediate LDAP signing and channel binding gaps, privileged HTTP service protection gaps, and other domain-level weak configurations identified through assessments. • Document remediation plans, implementation standards, and operational procedures to support audit readiness and ongoing compliance. • Partner with infrastructure, cybersecurity, and application teams to validate compatibility, sequence change windows, and reduce operational risk during security enforcement activities. Required Technical Skills • Hands-on experience administering Active Directory Domain Services in multi-domain or multi-site enterprise environments. • Strong knowledge of domain controllers, replication, DNS, Group Policy, authentication flows, and disaster recovery design for AD. • Practical experience implementing Microsoft security controls such as EPA, LDAP signing, channel binding, Kerberos hardening, SMB signing, and privileged account protections. • Experience with Active Directory Certificate Services, Active Directory Web Services, Windows Server hardening, and identity-related remediation programs. • Ability to analyze and remediate privilege escalation paths, insecure account settings, and policy-based configuration weaknesses. • Proficiency with PowerShell for audit, remediation, automation, and operational reporting. • Experience planning and executing infrastructure upgrades, domain controller replacement, and controlled production changes. Preferred Qualifications • Experience supporting regulated or highly controlled enterprise environments with strong audit, change management, and documentation expectations. • Familiarity with Zero Trust architecture, privileged access management, and identity security assessments. • Relevant Microsoft certifications in Windows Server, Active Directory, security, or identity administration are advantageous.

Similar jobs

Similar jobs

Sanity logo

Senior Support Engineer, NORAM

Sanity

🇨🇦Canada10 hours ago
Giatec Scientific Inc. logo

Lead Support Engineer, Bedrock

Giatec Scientific Inc.

🇨🇦CanadaYesterday
Rewind logo

Senior Technical Support Engineer (T3)

Rewind

🇨🇦Canada2 days ago
Careers Inc logo

Production Support Engineer-REMOTE-Vancouver

Careers Inc

🇨🇦Canada3 days ago
GitLab logo

Senior Assigned Support Engineer (AMER)

GitLab

🌍Canada, United States1 weeks ago
Tailscale logo

Customer Support Engineer (Tier 2)

Tailscale

🌍Canada, United States1 weeks ago