Architect – Active Directory (AD)
Farnborough, Erskine, Newcastle
We are seeking a highly skilled Microsoft Active Directory (AD) Architect to lead the design, implementation, and optimisation of enterprise directory services within secure, high-assurance environments.
This role requires deep technical expertise in Active Directory architecture, strong delivery experience, and the ability to operate both strategically and hands-on. The successful candidate will support a UK secure account, working closely with stakeholders and delivering solutions on customer sites.
Key Responsibilities :
- Lead the architecture, design , and evolution of Microsoft Active Directory environments (on-premises)
- Act as the technical SME for Active Directory, providing expert guidance on best practices, policies, and standards
- Design and implement secure AD architectures, including domains, forests, trusts, and replication strategies
- Develop and enforce Group Policy (GPO) strategies aligned with security and operational requirements
- Deliver identity services integration, including federation (ADFS)
- Define and implement tiered administration models, privileged access controls, Integration with Privileged access Management tooling, and secure identity design patterns
- Conduct health checks, security assessments, and remediation planning for AD environments
- Support incident resolution and root cause analysis relating to identity and authentication services
- Produce and maintain comprehensive design and operational documentation
- Work closely with security, infrastructure, and application teams to ensure secure and efficient identity services
- Engage directly with Tech Lead, Programme Manager and customers on-site, supporting delivery and building trusted relationships
Required Skills & Experience :
- Proven experience in an Active Directory Architect or Senior SME role
- Deep hands-on expertise with:
- Microsoft Active Directory (multi-domain/forest environments)
- Group Policy design and management
- DNS, DHCP, and core supporting infrastructure
- Strong experience in designing and implementing enterprise-scale AD environments
- Demonstrable experience producing high-quality design documentation, including:
- High-Level Designs (HLDs)
- Low-Level Designs (LLDs)
- Security architecture documentation
- Operational procedures and runbooks
- Strong understanding of identity security, including:
- Tiered administration models
- Least privilege access
- Privileged Access Workstations (PAWs)
- Privileged access Management Toolset
- Knowledge of authentication protocols (Kerberos, NTLM, LDAP, SAML, OAuth)
- Experience with PowerShell scripting and automation
- Familiarity with integrating AD into enterprise security and monitoring tooling (e.g., SIEM)
- Excellent stakeholder engagement, communication, and documentation skills