- Company Name
- TekNavigators Staffing
- Job Title
- Active Directory Specialist
- Job Description
-
**Job Title:** Active Directory Specialist
**Role Summary:**
Senior Active Directory professional responsible for designing, implementing, and maintaining enterprise AD DS, AD FS, and Azure AD environments. Ensures AD infrastructure complies with CMMC and other security frameworks, supports hybrid identity, and automates routine tasks.
**Expectations:**
- Minimum 5 + years experience managing enterprise‑scale AD.
- US citizenship required.
- Ability to work occasional evenings/weekends for outages or upgrades.
- Strong troubleshooting, scripting, and documentation skills.
**Key Responsibilities:**
- Design, deploy, and sustain AD DS across multi‑site environments.
- Manage GPOs, OUs, user/computer accounts, DNS, and DHCP.
- Monitor replication, performance, and health; implement disaster recovery and backup plans.
- Configure and support AD FS and Azure AD integration, including hybrid identity scenarios.
- Enforce security best practices: RBAC, auditing, hardening, and compliance (CMMC, NIST 800‑171/172).
- Develop and maintain PowerShell scripts for automation.
- Collaborate with security and compliance teams on identity governance, access control, and Zero Trust initiatives.
- Perform domain migrations, trust configurations, and forest redesign as needed.
**Required Skills:**
- Enterprise AD DS, AD FS, Azure AD, DNS, DHCP, LDAP.
- Advanced PowerShell scripting and automation.
- Identity federation, SSO, conditional access.
- Security baselines, audit, and compliance frameworks (CMMC, NIST).
- Analytical troubleshooting and clear documentation.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Technology, or related field (or equivalent experience).
- Preferred Microsoft certifications: MCSA/MCSE, Microsoft Certified: Identity and Access Administrator Associate, Azure Solutions Architect.
- Additional preferred: certifications or experience with AD Manager Plus, Quest, Zero Trust, PAM, IGA, Okta, Ping Identity, SailPoint.