Senior R&D Engineer

Il y a 1 jour

France, Auvergne-Rhône-Alpes Nicholson Search and Selection Ltd Temps plein

Remote (Europe) - Reports directly to the CTO

Note: this posting is deliberately anonymized: company name, HQ city and exact financials are withheld until later stages.

About us

We're a fast-growing, SOC2 Type II-certified B2B SaaS company headquartered in Europe, serving enterprise customers worldwide. We already built and scaled a category-defining resilience product for a major cloud identity platform — and we're now applying that same expertise to a much bigger, harder problem: Active Directory disaster recovery.

Active Directory is the identity backbone of virtually every enterprise IT environment. When it goes down, nothing works — no logins, no file access, no email, no applications. When it's compromised by ransomware, the entire organization is paralyzed. We're building a purpose-built, cyber-first AD backup and recovery product: a European alternative to the handful of established players in this space, focused on the intelligence of AD data recovery, not generic VM backup.

The role

We're looking for a senior, deeply hands-on engineer to build the technical core of our AD DR product: NTDS.dit parsing, granular recovery, authoritative restore, and Forest Recovery orchestration.

This is not a role where you attend meetings, review architecture diagrams, and delegate the hard problems. You will design the solutions, prototype them on real domain controllers in the lab, debug the tricky edge cases, and own the end-to-end technical quality of the product.

Depending on your background, you may write production code yourself or work closely with our developers to translate your AD expertise into shipped features.

You will report directly to the CTO and work closely with the Product Manager, with a significant say in the technical roadmap and the freedom to shape the product from the ground up. If you're looking for a management role, this isn't it.

Two backgrounds we welcome

Path A: The AD DR product veteran.

You've built or significantly contributed to a commercial backup/disaster-recovery product with a dedicated Active Directory module. You've shipped features touching NTDS.dit parsing, authoritative restore, or Forest Recovery orchestration, and you know the real pitfalls of the domain — not just what the documentation says.

Path B: The AD reconstructor.

You're a senior AD administrator or consultant who has actually built — and, more importantly, rebuilt — Active Directory environments in large organizations. You've run real Forest Recoveries, handled post-ransomware AD restorations, driven migrations or domain consolidations. Your product experience may be lighter, but your AD depth is what we can't teach.

What you'll need

  • Deep understanding of AD internals: NTDS.dit, the ESE storage engine, partitions (Domain, Configuration, Schema, Application), multi‑master replication, FSMO roles, Kerberos, DNS integration.
  • Hands‑on experience with authoritative restore, Forest Recovery procedures, metadata cleanup, FSMO seizing, krbtgt rotation, USN mechanics.
  • Strong PowerShell skills, fluent with ntdsutil, dcdiag, repadmin, dsacls and other native AD tooling.
  • Practical understanding of AD security: pass‑hash, Golden Ticket, DCSync, AdminSDHolder, AD tiering.
  • Comfort scripting in PowerShell and reading code written by others (Python, C#, or Go) — writing production code yourself is a plus.
  • Comfort working in a lab: spinning up VMs, breaking and repairing test forests, running disaster scenarios end to end.

Nice to have

  • Direct experience with DSInternals (the open‑source library for offline NTDS.dit parsing) - contributions to it are a strong plus.
  • Hands‑on experience with the ESE format at a low level, or writing/adapting an ESE parser.
  • Familiarity with VSS and Windows snapshot mechanisms.
  • Understanding of AD Certificate Services (AD CS), DFS‑R, and advanced Kerberos features (constrained delegation, S4U).
  • Public contributions: open‑source projects related to AD, conference talks (TEC, Microsoft Ignite, BSides), blog posts on AD internals.
  • Recent Microsoft certifications on AD / Windows Server / Identity.

This probably isn't for you if

  • You have no hands‑on Active Di