- Position Summary: Lead the engineering, security hardening, and operational support of large-scale on-premises Active Directory and cloud-based Microsoft Entra ID (formerly Azure AD) environments. [1, 2, 3, 4, 5, 6]
Key Responsibilities
- Hybrid Identity Management: Design, configure, and maintain hybrid synchronization using Microsoft Entra Connect Sync. [1, 2]
- Active Directory Administration: Manage Active Directory Domain Services (AD DS), Domain Controllers, Global Catalog services, replication health, and Group Policy Objects (GPOs). [1]
- Cloud & Access Security: Configure Conditional Access Policies, Multi-Factor Authentication (MFA), and Single Sign-On (SSO) integrations for enterprise and SaaS apps. [1, 2]
- Identity Governance: Implement Privileged Identity Management (PIM), periodic access reviews, and enforce least-privilege access models. [1, 2]
- Automation & Scripting: Develop PowerShell scripts and workflows to automate user provisioning, de-provisioning, and routine directory cleanups. [1, 2]
- Migrations & Upgrades: Lead tenant-to-tenant (T2T) migrations, domain consolidations, and cloud transformations. [1, 2]
Required Qualifications
- Experience: 5+ years of hands-on enterprise IT experience focusing on Active Directory and cloud identity platforms.
- Core Technical Skills: Deep expertise in AD DS, DNS, GPO troubleshooting, and replication.
- Cloud Knowledge: Extensive experience with Microsoft Entra ID, RBAC/ABAC models, and Microsoft 365 integration.
- Scripting Proficiency: Strong command of PowerShell or infrastructure-as-code tools (Terraform) for automation.
- Certifications: Microsoft Certified: Identity and Access Administrator Associate (SC-300) or equivalent Windows Server / Directory Services credentials. [1, 2, 3, 4, 5]