🇨🇿 Liberec, Czechia · 14h ago
Senior Microsoft Active Directory Engineer
UCT Fluid Delivery Solutions s.r.o. Liberec
LinkedInseniorEnglish-friendly
Senior Microsoft Active Directory EngineerUltra Clean Holdings (UCT) is a leading provider of critical subsystems, components, and ultra-high-purity cleaning services for the semiconductor industry — helping the world's top chipmakers build the technology behind everything from smartphones to AI. Headquartered in Hayward, California.Ultra Clean doesn't manufacture AI directly, but it's a critical infrastructure supplier without which AI chips couldn't be produced.The OpportunityWe're looking for a Senior Active Directory Engineer to serve as the technical authority behind our entire identity backbone. This is a role for someone who thinks in trusts and forests, not just accounts — you'll architect resilience into the systems everyone else depends on without thinking twice, spanning multi-domain, multi-forest, and hybrid cloud environments.If you want ownership over something foundational — where every design decision ripples across the whole organization — and you're ready to mentor the next wave of engineers along the way, this is your seat.What You'll OwnActive Directory Architecture & OperationsAct as senior technical owner of AD DS across multiple domains and forests — designing domain controllers, managing trusts, replication topology, and Global Catalog placement, and leading the full domain controller lifecycle.Hybrid Identity & Cloud IntegrationDesign and operate hybrid identity configurations, bridging on-prem AD with Microsoft Entra ID / Azure AD Connect, and partner with cloud engineering to extend identity into IaaS and hybrid environments.Group Policy, DNS & Core ServicesArchitect GPOs that enforce security baselines, maintain AD-integrated DNS, and be the Tier 3/4 escalation point for the gnarliest Kerberos, LDAP, and replication issues.Security, Resilience & GovernanceStrengthen AD security through least-privilege models and auditing, design backup/DR procedures, and partner with security teams to stay ahead of identity-based threats.Automation & LeadershipBuild PowerShell automation that scales operations, mentor junior engineers, and own the architecture diagrams and standards that keep everyone aligned.What You Bring:5–8+ years engineering Active Directory in enterprise environments, with proven multi-domain/multi-forest experienceHands-on production experience with Windows Server domain controllersDeep knowledge of AD DS, DNS, Group Policy, and replicationSolid grasp of hybrid identity and directory synchronizationStrong PowerShell skills for automationNice to have: hybrid cloud AD architecture experience, identity federation/SSO/modern IAM familiarity, Microsoft certifications in Windows Server or identity technologies, and background in large, distributed enterprise environments.3 days a week on site in Liberec is there normal work expectationsInterview process: (2 total interviews)1 hour with the manager and one engineer who are in Liberec30-minute final interview with the VP who runs the department who's here in the USSourced from LinkedIn. Relocantly aggregates public job postings; apply on the original site.