Daimler Truck Banner Image contains multiple vehicles that represent each company

DTICI_IAM_ActiveDirectory_Senior Conultant_T8

We are looking for an experienced Active Directory Engineer (5+ years) to manage and enhance enterprise AD infrastructure with a strong focus on operations, Tier-0 (T0) environment security, migrations, change management, and automation.

The role will ensure secure, stable, and scalable identity services, while driving automation-led efficiency and maintaining strict control over privileged (Tier-0) assets and access pathways.

 

Key Responsibilities

1. Active Directory Operations

  • Manage and support Active Directory Domain Services (AD DS) in enterprise environments.
  • Perform BAU activities:
    • User, group, and OU management
    • GPO administration
    • DNS and authentication services
  • Monitor and troubleshoot:
    • Replication issues
    • Kerberos / NTLM authentication failures
    • GPO processing issues
    • Domain Controller health & performance
  • Maintain AD hygiene:
    • Cleanup of stale objects
    • Privileged group monitoring
    • Standardized OU and naming structures

2. Tier-0 (T0) Environment Management

  • Manage and secure Tier-0 identity infrastructure, including:
    • Domain Controllers
    • Privileged admin accounts
    • Built-in admin groups (Domain Admins, Enterprise Admins)
  • Enforce Tier-0 security controls:
    • Least privilege access
    • Privileged account segregation
    • Controlled administrative access
    • Access reviews and recertification
  • Identify and remediate risks:
    • Stale or excessive privileged access
    • Weak delegations and ACL misconfigurations
    • Unauthorized access pathways
  • Support Tier-0 governance, hardening, and compliance requirements.

3. AD Migrations & Transformation

  • Plan and execute AD migration projects, including:
    • Domain/forest migrations
    • Consolidation or separation initiatives
  • Perform:
    • Pre-migration assessments and dependency analysis
    • Risk evaluation and rollback planning
    • Migration execution and post-validation
  • Manage:
    • Trust relationships
    • SID history
    • Authentication continuity for applications

4. Change Management & Governance

  • Execute AD changes through structured ITIL-based change management:
    • Standard, Normal, and Emergency changes
  • Prepare detailed change artifacts:
    • Impact analysis
    • Risk assessment
    • Rollback strategy
    • Validation steps
  • Coordinate with CAB and stakeholders to ensure smooth execution.
  • Maintain detailed documentation:
    • RFCs, implementation plans, post-change reports
  • Ensure compliance with audit, security, and governance standards.

5. Automation & Process Optimization

  • Identify and automate repetitive AD and operational tasks using PowerShell (mandatory).
  • Develop automation for:
    • User and group lifecycle management
    • GPO and OU operations
    • Health monitoring and alert validation
    • Migration validation and reporting
    • Privileged access tracking and reporting
  • Build reusable scripts with:
    • Error handling
    • Logging and audit traceability
    • Approval-based execution (where required)
  • Drive standardization and efficiency through automation-first approach.

6. Incident & Problem Management

  • Provide L2/L3 support for AD-related incidents.
  • Participate in major incident bridges for authentication or AD outages.
  • Perform root cause analysis (RCA) and implement preventive measures.
  • Ensure minimal downtime and quick recovery for critical identity services.

7. Documentation & Compliance

  • Maintain runbooks, SOPs, and architecture documentation.
  • Support audit and compliance activities by providing:
    • Access control evidence
    • Change records
    • Operational logs
  • Ensure adherence to enterprise security policies and governance frameworks.

 

We are looking for an experienced Active Directory Engineer (5+ years) to manage and enhance enterprise AD infrastructure with a strong focus on operations, Tier-0 (T0) environment security, migrations, change management, and automation.

The role will ensure secure, stable, and scalable identity services, while driving automation-led efficiency and maintaining strict control over privileged (Tier-0) assets and access pathways.

 

Key Responsibilities

1. Active Directory Operations

  • Manage and support Active Directory Domain Services (AD DS) in enterprise environments.
  • Perform BAU activities:
    • User, group, and OU management
    • GPO administration
    • DNS and authentication services
  • Monitor and troubleshoot:
    • Replication issues
    • Kerberos / NTLM authentication failures
    • GPO processing issues
    • Domain Controller health & performance
  • Maintain AD hygiene:
    • Cleanup of stale objects
    • Privileged group monitoring
    • Standardized OU and naming structures

2. Tier-0 (T0) Environment Management

  • Manage and secure Tier-0 identity infrastructure, including:
    • Domain Controllers
    • Privileged admin accounts
    • Built-in admin groups (Domain Admins, Enterprise Admins)
  • Enforce Tier-0 security controls:
    • Least privilege access
    • Privileged account segregation
    • Controlled administrative access
    • Access reviews and recertification
  • Identify and remediate risks:
    • Stale or excessive privileged access
    • Weak delegations and ACL misconfigurations
    • Unauthorized access pathways
  • Support Tier-0 governance, hardening, and compliance requirements.

3. AD Migrations & Transformation

  • Plan and execute AD migration projects, including:
    • Domain/forest migrations
    • Consolidation or separation initiatives
  • Perform:
    • Pre-migration assessments and dependency analysis
    • Risk evaluation and rollback planning
    • Migration execution and post-validation
  • Manage:
    • Trust relationships
    • SID history
    • Authentication continuity for applications

4. Change Management & Governance

  • Execute AD changes through structured ITIL-based change management:
    • Standard, Normal, and Emergency changes
  • Prepare detailed change artifacts:
    • Impact analysis
    • Risk assessment
    • Rollback strategy
    • Validation steps
  • Coordinate with CAB and stakeholders to ensure smooth execution.
  • Maintain detailed documentation:
    • RFCs, implementation plans, post-change reports
  • Ensure compliance with audit, security, and governance standards.

5. Automation & Process Optimization

  • Identify and automate repetitive AD and operational tasks using PowerShell (mandatory).
  • Develop automation for:
    • User and group lifecycle management
    • GPO and OU operations
    • Health monitoring and alert validation
    • Migration validation and reporting
    • Privileged access tracking and reporting
  • Build reusable scripts with:
    • Error handling
    • Logging and audit traceability
    • Approval-based execution (where required)
  • Drive standardization and efficiency through automation-first approach.

6. Incident & Problem Management

  • Provide L2/L3 support for AD-related incidents.
  • Participate in major incident bridges for authentication or AD outages.
  • Perform root cause analysis (RCA) and implement preventive measures.
  • Ensure minimal downtime and quick recovery for critical identity services.

7. Documentation & Compliance

  • Maintain runbooks, SOPs, and architecture documentation.
  • Support audit and compliance activities by providing:
    • Access control evidence
    • Change records
    • Operational logs
  • Ensure adherence to enterprise security policies and governance frameworks.

 

Required Qualifications

  • Bachelor’s degree in IT / Computer Science or related field.
  • 5+ years of experience in Active Directory administration/engineering.
  • Strong expertise in:
    • AD DS, Domain Controllers, GPO, DNS
    • AD Sites & Services, replication troubleshooting
    • Authentication protocols (Kerberos / NTLM)
  • Proven experience in:
    • Tier-0 / privileged environment management
    • AD migrations (domain/forest level)
    • Change management (ITIL processes, CAB)
  • Strong scripting skills in PowerShell.

Technical Skills

  • Active Directory (AD DS)
  • Tier-0 / Privileged Infrastructure Security
  • AD Migration (ADMT or equivalent)
  • Group Policy (GPO)
  • DNS & Authentication Troubleshooting
  • PowerShell Automation
  • Replication & DC Health Management
  • Change Management (ITIL)
  • Incident & Problem Management

Preferred / Good to Have

  • Hybrid identity experience: Entra ID / Azure AD Connect
  • Experience with PAM/PIM tools (CyberArk, BeyondTrust, Entra PIM)
  • Familiarity with ServiceNow or ITSM tools
  • Understanding of Zero Trust and Tiering models (T0/T1/T2)
  • Experience in large enterprise or global AD environments

Key Competencies

  • Strong ownership and accountability
  • Structured thinking with risk assessment mindset
  • Attention to detail in change execution
  • Strong troubleshooting and analytical skills
  • Effective communication and stakeholder management
  • Ability to perform in high-pressure situations

 

Required Qualifications

  • Bachelor’s degree in IT / Computer Science or related field.
  • 5+ years of experience in Active Directory administration/engineering.
  • Strong expertise in:
    • AD DS, Domain Controllers, GPO, DNS
    • AD Sites & Services, replication troubleshooting
    • Authentication protocols (Kerberos / NTLM)
  • Proven experience in:
    • Tier-0 / privileged environment management
    • AD migrations (domain/forest level)
    • Change management (ITIL processes, CAB)
  • Strong scripting skills in PowerShell.

Technical Skills

  • Active Directory (AD DS)
  • Tier-0 / Privileged Infrastructure Security
  • AD Migration (ADMT or equivalent)
  • Group Policy (GPO)
  • DNS & Authentication Troubleshooting
  • PowerShell Automation
  • Replication & DC Health Management
  • Change Management (ITIL)
  • Incident & Problem Management

Preferred / Good to Have

  • Hybrid identity experience: Entra ID / Azure AD Connect
  • Experience with PAM/PIM tools (CyberArk, BeyondTrust, Entra PIM)
  • Familiarity with ServiceNow or ITSM tools
  • Understanding of Zero Trust and Tiering models (T0/T1/T2)
  • Experience in large enterprise or global AD environments

Key Competencies

  • Strong ownership and accountability
  • Structured thinking with risk assessment mindset
  • Attention to detail in change execution
  • Strong troubleshooting and analytical skills
  • Effective communication and stakeholder management
  • Ability to perform in high-pressure situations

 

At Daimler Truck, we promote diversity and foster an inclusive corporate culture. We value the individual strengths of our employees, as these lead to the best team performance and thus to the success of our company. Inclusion and Equal opportunities are important to us – regardless of where you come from and who you are. We look forward to receiving applications from people of all cultures and genders, parents, people with disabilities and people from the LGBTIQ+ community.
At Daimler Truck, we promote diversity and foster an inclusive corporate culture. We value the individual strengths of our employees, as these lead to the best team performance and thus to the success of our company. Inclusion and Equal opportunities are important to us – regardless of where you come from and who you are. We look forward to receiving applications from people of all cultures and genders, parents, people with disabilities and people from the LGBTIQ+ community.
DAIMLER TRUCK CAREER FACEBOOK DAIMLER TRUCK CAREER INSTAGRAM