Skip to content

Open nowPosted 12 days ago

Senior Windows Platform Engineer | Contract | Remote

Tech Holding14 open roles

Where
USA, Remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Windows Platform Engineer | Contract | RemoteTech Holding · USA, Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Tech Holding's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Tech Holding postings stay open a median of 33 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted 12 days ago

Tech Holding median: 33 days open

The posting

About us:

Working at Tech Holding isn't just a job, it's an opportunity to be a part of something bigger. We are a full-service consulting firm that was founded on the premise of delivering predictable outcomes and high-quality solutions to our clients. Our founders and team members have industry experience and have held senior positions in a wide variety of companies – from emerging startups to large Fortune 50 firms – and we have taken our combined experiences and developed a unique approach that is supported by the principles of deep expertise, integrity, transparency, and dependability.

The Role:

We are looking for a Senior Windows Engineer for a project-based assignment to strengthen the stability and resiliency of a business-critical Windows environment across Active Directory, DNS, authentication, automation, observability, security, and disaster recovery. This is a hands-on platform engineering role that combines deep Active Directory and Kerberos expertise with Windows automation, cloud infrastructure, and Infrastructure as Code. You will work across directory services, authentication, golden image and patching pipelines, PowerShell automation, PKI, configuration management, and recovery capabilities while helping improve the reliability and resilience of the overall Windows platform. The ideal candidate is a Windows platform and automation engineer rather than a traditional Windows administrator, with strong cloud fluency and experience managing infrastructure through code and automation.

Key Responsibilities:

  • Improve Active Directory and DNS resilience, including replication topology and health, FSMO roles, DFS-R, NTDS, AD-integrated DNS, and domain controllers running as cloud instances.
  • Support the estate's migration from NTLM to Kerberos, ensuring both protocols can operate without an outage during the transition.
  • Work with service principal names and duplicate-SPN failure modes, constrained delegation, AES over RC4 through the supported-encryption-types attribute, managed and group managed service accounts, and reverse DNS.
  • Support identity integration across the estate, including LDAP for non-Windows hosts, desktop single sign-on via Kerberos passthrough with constrained delegation, cloud single sign-on, and brokered application identity.
  • Support and improve the golden image and patch pipeline, including image bake automation, CI-scheduled builds, promotion, deprecation, deregistration, and CVE-driven rebuilds.
  • Improve Windows observability, including infrastructure agents, Windows service and event-channel collection, script-derived metrics, domain controller service health, replication status, and operational log-channel forwarding.
  • Develop and maintain PowerShell automation supporting Windows platform operations and resiliency.
  • Support Infrastructure as Code and configuration management, including Chef, Ansible, Systems Manager, guardrail policies, pipeline pre-deploy validation, and OpenTofu.
  • Support multi-account rebuild, guardrail policies, and module compliance.
  • Strengthen security and data-protection controls, including encryption by default on block storage, key management, web-tier protection, and instance metadata hardening.
  • Improve PKI and certificate services resilience, including certificate authority recovery posture.
  • Support disaster recovery design, cloud platform, and file services, including recovery tiering with defined RTO and RPO, pilot light versus active-passive trade-offs, non-disruptive failover testing, and divisional cloud accounts.
  • Support file-services resilience and legacy distributed file system decommissioning targeting zero RPO and sub-five-minute RTO.

Additional Areas of Focus:

  • Active Directory backup and forest recovery: Define, test, and document backup, restore, and forest recovery, including the achievable RTO.
  • NTLM decommission path: Define when NTLM can be retired and how remaining NTLM use will be audited.
  • Certificate authority recovery posture: Define recovery requirements and establish certificate inventory and expiry alerting.
  • Privileged access model for the directory: Address the RBAC transition or document the decision regarding its future state.
  • Directory-specific recovery testing: Exercise domain controller and directory recovery as part of resiliency testing.
  • Windows image catalogue rationalisation: Review the image catalogue and multi-tenant configuration.
  • Group Policy surface: Confirm whether Group Policy is genuinely unused or currently unmanaged.

Requirements:

  • Expert-level experience with Active Directory and DNS resilience, including replication topology and health, FSMO roles, DFS-R, NTDS, AD-integrated DNS, and domain controllers.
  • Expert-level knowledge of Kerberos authentication, including SPNs, duplicate-SPN failure modes, constrained delegation, AES/RC4 encryption, managed service accounts, group managed service accounts, and reverse DNS dependencies.
  • Strong experience with identity integration across Windows and non-Windows environments, including LDAP and single sign-on.
  • Expert-level experience with golden image and patch pipelines, including image bake automation, CI-scheduled builds, promotion, deprecation, deregistration, and CVE-driven rebuilds.
  • Strong Windows observability and PowerShell experience.
  • Strong experience with Infrastructure as Code and configuration management, including OpenTofu and tools such as Chef, Ansible, and Systems Manager.
  • Strong understanding of cloud infrastructure, security, data-protection controls, and infrastructure automation.
  • Strong experience with PKI and certificate services.
  • Strong experience with disaster recovery design, including RTO/RPO, recovery strategies, failover testing, and Windows file services.
  • Ability to work as a platform and automation engineer in a code-managed Windows environment rather than relying on traditional
  • Windows administration practices.
  • Ability to work independently across complex, business-critical Windows infrastructure and communicate technical decisions clearly.

Location:

  • Remote, USA
  • Must be available to work with the team until at least 3:00 PM Pacific Time.

Employment type:

  • Contract

*Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time

Tech Holding is proud to be an Equal Opportunity Employer and is committed to fostering a diverse and inclusive workplace. We welcome applicants from all backgrounds and experiences, and we consider qualified applicants without regard to race, color, religion, gender, sexual orientation, gender identity, national origin, disability, veteran status, or any other legally protected characteristic. If you require accommodation in the application process, please contact our HR

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Tech Holding's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Tech Holding's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Tech Holding's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.