We are looking for an experienced Active Directory Engineer (5+ years) to manage and enhance enterprise AD infrastructure with a strong focus on operations, Tier-0 (T0) environment security, migrations, change management, and automation.
The role will ensure secure, stable, and scalable identity services, while driving automation-led efficiency and maintaining strict control over privileged (Tier-0) assets and access pathways.
Key Responsibilities
1. Active Directory Operations
-
Manage and support Active Directory Domain Services (AD DS) in enterprise environments.
-
Perform BAU activities:
-
User, group, and OU management
-
GPO administration
-
DNS and authentication services
-
Monitor and troubleshoot:
-
Replication issues
-
Kerberos / NTLM authentication failures
-
GPO processing issues
-
Domain Controller health & performance
-
Maintain AD hygiene:
-
Cleanup of stale objects
-
Privileged group monitoring
-
Standardized OU and naming structures
2. Tier-0 (T0) Environment Management
-
Manage and secure Tier-0 identity infrastructure, including:
-
Domain Controllers
-
Privileged admin accounts
-
Built-in admin groups (Domain Admins, Enterprise Admins)
-
Enforce Tier-0 security controls:
-
Least privilege access
-
Privileged account segregation
-
Controlled administrative access
-
Access reviews and recertification
-
Identify and remediate risks:
-
Stale or excessive privileged access
-
Weak delegations and ACL misconfigurations
-
Unauthorized access pathways
-
Support Tier-0 governance, hardening, and compliance requirements.
3. AD Migrations & Transformation
-
Plan and execute AD migration projects, including:
-
Domain/forest migrations
-
Consolidation or separation initiatives
-
Perform:
-
Pre-migration assessments and dependency analysis
-
Risk evaluation and rollback planning
-
Migration execution and post-validation
-
Manage:
-
Trust relationships
-
SID history
-
Authentication continuity for applications
4. Change Management & Governance
-
Execute AD changes through structured ITIL-based change management:
-
Standard, Normal, and Emergency changes
-
Prepare detailed change artifacts:
-
Impact analysis
-
Risk assessment
-
Rollback strategy
-
Validation steps
-
Coordinate with CAB and stakeholders to ensure smooth execution.
-
Maintain detailed documentation:
-
RFCs, implementation plans, post-change reports
-
Ensure compliance with audit, security, and governance standards.
5. Automation & Process Optimization
-
Identify and automate repetitive AD and operational tasks using PowerShell (mandatory).
-
Develop automation for:
-
User and group lifecycle management
-
GPO and OU operations
-
Health monitoring and alert validation
-
Migration validation and reporting
-
Privileged access tracking and reporting
-
Build reusable scripts with:
-
Error handling
-
Logging and audit traceability
-
Approval-based execution (where required)
-
Drive standardization and efficiency through automation-first approach.
6. Incident & Problem Management
-
Provide L2/L3 support for AD-related incidents.
-
Participate in major incident bridges for authentication or AD outages.
-
Perform root cause analysis (RCA) and implement preventive measures.
-
Ensure minimal downtime and quick recovery for critical identity services.
7. Documentation & Compliance
-
Maintain runbooks, SOPs, and architecture documentation.
-
Support audit and compliance activities by providing:
-
Access control evidence
-
Change records
-
Operational logs
-
Ensure adherence to enterprise security policies and governance frameworks.