- Company Name
- TalentOla
- Job Title
- Active Directory Specialist
- Job Description
-
Job title: Senior Active Directory (On‑Prem) Engineer
Role Summary:
Design, implement, secure, and maintain on‑prem Active Directory, Azure AD, and hybrid identity solutions for a global enterprise. Lead architecture, automation, and compliance initiatives, while providing Tier‑3 support and mentoring junior staff.
Expectations:
- Deliver secure, scalable AD infrastructure with high availability.
- Resolve complex AD, ADFS, Azure AD Connect, and PKI incidents promptly.
- Produce clear documentation and automation scripts.
- Collaborate with security, cloud, and application teams on migrations and upgrades.
Key Responsibilities:
- Lead design, implementation, and enhancement of AD, Azure AD, and hybrid solutions.
- Develop and maintain OU structures, Group Policies, DNS/DHCP integration, and replication.
- Provide Tier‑3 engineering support for AD, ADFS, Azure AD Connect, and identity-related issues.
- Monitor, troubleshoot, and optimize authentication, authorization, and replication processes.
- Manage PKI, certificate services, and secure LDAP.
- Implement security best practices (PAM, conditional access, MFA, Zero Trust).
- Conduct audit support, vulnerability assessments, and remediation.
- Develop PowerShell/Python scripts for automation, reporting, and reporting.
- Drive adoption of modern identity technologies and cloud‑based IAM services.
- Mentor junior engineers and contribute to knowledge sharing.
Required Skills:
- 8+ years of on‑prem AD experience, including AD, ADFS, Azure AD Connect, Conditional Access, and SSO/Federation.
- Expertise in Windows Server (2016/2019/2022), DNS, DHCP, PKI, LDAP, Kerberos, NTLM.
- Advanced PowerShell scripting and automation.
- Proficiency with Group Policy Management, authentication protocols, Zero Trust, PAM, MFA.
- Experience with cloud integrations (Microsoft 365, SaaS apps, SAML, OAuth, SCIM).
- Knowledge of SOX, HIPAA, GDPR compliance and security audit processes.
- Familiarity with Okta, Ping, or other IAM platforms (plus).
- Strong cybersecurity, incident response, and directory hardening background.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Technology, or related field (or equivalent experience).
- Microsoft Certified: Identity and Access Administrator Associate (preferred).
- Additional certifications (e.g., Microsoft Certified: Azure Administrator Associate, CISSP, CISM) are a plus.