Role Summary:
We are looking for a skilled Active Directory (AD) and Tier-0 ILM specialist to own and improve identity lifecycle processes for privileged and high-impact identities in a complex enterprise environment. This role will focus on secure Joiner–Mover–Leaver (JML) operations, Tier-0 account governance, privileged group control, and automation-driven compliance to strengthen security posture, reduce operational risks, and ensure audit readiness.
The candidate will partner with IAM, Cybersecurity, GRC, and infrastructure teams to implement least privilege, strong approval controls, access reviews, and standardized workflows across Tier-0 environments.
Key Responsibilities
1) Tier-0 Identity Lifecycle Management (ILM / JML)
- Own end-to-end Joiner–Mover–Leaver (JML) lifecycle for Tier-0 / privileged identities, including:
- Admin account provisioning, modifications, de-provisioning
- Role-based access changes based on org movement or job changes
- Emergency access workflows with strict governance
- Implement and maintain time-bound access and just-in-time principles where feasible.
- Ensure lifecycle controls cover:
- Identity proofing, approvals, segregation of duties (SoD)
- Re-certification and removal of stale/unused privileges
- Consistent naming standards & lifecycle tagging for privileged accounts
2) Privileged Access Governance (Tier-0 Focus)
- Manage and govern Tier-0 AD groups and delegated rights, including:
- Domain Admins, Enterprise Admins, Schema Admins, built-in privileged groups
- GPO delegated permissions, OU ACLs, admin role delegation
- Drive least privilege and role engineering for Tier-0 operations:
- Convert “broad admin” models into role-based admin groups
- Reduce permanent membership and enforce approvals/expiry
- Own privileged identity hygiene:
- Remove orphaned accounts, stale memberships, excessive ACLs
- Identify and remediate privilege escalation paths
3) Automation & Workflow Enablement
- Build automation for ILM workflows using PowerShell (and/or Python), including:
- Provisioning/de-provisioning privileged accounts
- Group membership changes with approval controls
- Scheduled access review reports & evidence generation
- Automated detection of privilege drift and policy violations
- Integrate workflows with ITSM tools (e.g., ServiceNow) and approval gates.
- Maintain audit-friendly logs, traceability, rollback, and change history for all ILM actions.
4) Compliance, Controls & Audit Readiness
- Ensure Tier-0 ILM controls align to enterprise security policies and audit expectations:
- Access review cycles, periodic recertifications, and evidence packages
- SOX/ISO/internal audit support, control testing, remediation tracking
- Maintain documentation:
- Standard Operating Procedures (SOPs), runbooks, control mappings
- “Who has access to what” traceability for Tier-0 privileges
5) Monitoring, Risk, and Continuous Improvement
- Continuously improve Tier-0 posture by tracking:
- Privileged membership changes
- Unauthorized access attempts and abnormal activity indicators
- Failures in joiner/mover/leaver execution (missed removals, delays)
- Work with cybersecurity teams to support investigations and incident response for identity events.
Required Skills & Experience
- 5+ years experience in Active Directory operations/engineering in enterprise scale environments.
- Strong expertise in:
- AD DS, DCs, Sites & Services, trusts, DNS basics
- AD security fundamentals: privileged groups, GPO, delegation, ACLs
- Identity lifecycle fundamentals: JML, approvals, access governance
- Strong scripting / automation:
- PowerShell (advanced): modules, error handling, structured logging
- Experience working with audit/compliance teams:
- Evidence collection, control validation, remediation execution

