We are looking for an experienced Active Directory Engineer (5+ years) to manage and enhance enterprise AD infrastructure with a strong focus on operations, Tier-0 (T0) environment security, migrations, change management, and automation.
The role will ensure secure, stable, and scalable identity services, while driving automation-led efficiency and maintaining strict control over privileged (Tier-0) assets and access pathways.
Key Responsibilities
1. Active Directory Operations
- Manage and support Active Directory Domain Services (AD DS) in enterprise environments.
- Perform BAU activities:
- User, group, and OU management
- GPO administration
- DNS and authentication services
- Monitor and troubleshoot:
- Replication issues
- Kerberos / NTLM authentication failures
- GPO processing issues
- Domain Controller health & performance
- Maintain AD hygiene:
- Cleanup of stale objects
- Privileged group monitoring
- Standardized OU and naming structures
2. Tier-0 (T0) Environment Management
- Manage and secure Tier-0 identity infrastructure, including:
- Domain Controllers
- Privileged admin accounts
- Built-in admin groups (Domain Admins, Enterprise Admins)
- Enforce Tier-0 security controls:
- Least privilege access
- Privileged account segregation
- Controlled administrative access
- Access reviews and recertification
- Identify and remediate risks:
- Stale or excessive privileged access
- Weak delegations and ACL misconfigurations
- Unauthorized access pathways
- Support Tier-0 governance, hardening, and compliance requirements.
3. AD Migrations & Transformation
- Plan and execute AD migration projects, including:
- Domain/forest migrations
- Consolidation or separation initiatives
- Perform:
- Pre-migration assessments and dependency analysis
- Risk evaluation and rollback planning
- Migration execution and post-validation
- Manage:
- Trust relationships
- SID history
- Authentication continuity for applications
4. Change Management & Governance
- Execute AD changes through structured ITIL-based change management:
- Standard, Normal, and Emergency changes
- Prepare detailed change artifacts:
- Impact analysis
- Risk assessment
- Rollback strategy
- Validation steps
- Coordinate with CAB and stakeholders to ensure smooth execution.
- Maintain detailed documentation:
- RFCs, implementation plans, post-change reports
- Ensure compliance with audit, security, and governance standards.
5. Automation & Process Optimization
- Identify and automate repetitive AD and operational tasks using PowerShell (mandatory).
- Develop automation for:
- User and group lifecycle management
- GPO and OU operations
- Health monitoring and alert validation
- Migration validation and reporting
- Privileged access tracking and reporting
- Build reusable scripts with:
- Error handling
- Logging and audit traceability
- Approval-based execution (where required)
- Drive standardization and efficiency through automation-first approach.
6. Incident & Problem Management
- Provide L2/L3 support for AD-related incidents.
- Participate in major incident bridges for authentication or AD outages.
- Perform root cause analysis (RCA) and implement preventive measures.
- Ensure minimal downtime and quick recovery for critical identity services.
7. Documentation & Compliance
- Maintain runbooks, SOPs, and architecture documentation.
- Support audit and compliance activities by providing:
- Access control evidence
- Change records
- Operational logs
- Ensure adherence to enterprise security policies and governance frameworks.
Required Qualifications
- Bachelor’s degree in IT / Computer Science or related field.
- 5+ years of experience in Active Directory administration/engineering.
- Strong expertise in:
- AD DS, Domain Controllers, GPO, DNS
- AD Sites & Services, replication troubleshooting
- Authentication protocols (Kerberos / NTLM)
- Proven experience in:
- Tier-0 / privileged environment management
- AD migrations (domain/forest level)
- Change management (ITIL processes, CAB)
- Strong scripting skills in PowerShell.
Technical Skills
- Active Directory (AD DS)
- Tier-0 / Privileged Infrastructure Security
- AD Migration (ADMT or equivalent)
- Group Policy (GPO)
- DNS & Authentication Troubleshooting
- PowerShell Automation
- Replication & DC Health Management
- Change Management (ITIL)
- Incident & Problem Management
Preferred / Good to Have
- Hybrid identity experience: Entra ID / Azure AD Connect
- Experience with PAM/PIM tools (CyberArk, BeyondTrust, Entra PIM)
- Familiarity with ServiceNow or ITSM tools
- Understanding of Zero Trust and Tiering models (T0/T1/T2)
- Experience in large enterprise or global AD environments
Key Competencies
- Strong ownership and accountability
- Structured thinking with risk assessment mindset
- Attention to detail in change execution
- Strong troubleshooting and analytical skills
- Effective communication and stakeholder management
- Ability to perform in high-pressure situations

