- Company Name
- Software Technology Inc.
- Job Title
- Senior Active Directory (On-prem) Engineer
- Job Description
-
**Job Title**
Senior Active Directory (On‑Prem) Engineer
**Role Summary**
Design, implement, secure, and maintain on‑prem AD, Azure AD, and hybrid identity solutions for a global enterprise. Lead tier‑3 support, automation, and security compliance for identity services.
**Expectations**
- Deliver robust, scalable AD architecture aligned with zero‑trust principles.
- Maintain high availability and performance of AD, ADFS, Azure AD Connect, and PKI.
- Drive automation and modernization of identity operations.
- Ensure regulatory compliance (SOX, HIPAA, GDPR, etc.).
- Mentor junior staff and influence cross‑functional identity initiatives.
**Key Responsibilities**
- Architect and enhance enterprise AD, OU structures, GPOs, DNS/DHCP integration, and replication.
- Provide tier‑3 engineering support for AD, ADFS, Azure AD Connect, and related issues.
- Monitor, troubleshoot, and optimize authentication, authorization, and replication flows.
- Manage PKI, certificate services, secure LDAP, and privileged access controls.
- Conduct security audits, vulnerability assessments, and remediation in collaboration with security teams.
- Develop PowerShell/Python scripts for AD administration, reporting, and automation.
- Champion adoption of modern IAM, SaaS integrations (Microsoft 365, SaaS, SAML, OAuth, SCIM), and Zero Trust.
- Collaborate with IT Security, Cloud, and Application teams on migrations, upgrades, and integrations.
- Mentor junior engineers and contribute to knowledge sharing initiatives.
**Required Skills**
- 8+ years of on‑prem AD experience; 7+ enterprise hands‑on years.
- Deep expertise in Windows Server 2016/2019/2022, DNS, DHCP, PKI, ADFS, Azure AD Connect, Conditional Access, SSO/Federation.
- Advanced PowerShell scripting and automation; familiarity with Python.
- Strong command of GPO management, Kerberos, LDAP, NTLM, MFA, Zero Trust, PAM.
- Experience integrating Microsoft 365, SaaS apps, SAML/OAuth/SCIM.
- Knowledge of regulatory compliance (SOX, HIPAA, GDPR).
- Proven ability to design, troubleshoot, and secure identity infrastructure.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, IT, or related field (or equivalent experience).
- Microsoft Certified: Identity and Access Administrator Associate or equivalent.
- Optional: Okta, Ping, or other IAM platform certifications.
- Strong background in cybersecurity, incident response, and directory hardening.