- Company Name
- Natsoft
- Job Title
- Active Directory Specialist
- Job Description
-
**Job Title**
Senior Active Directory Engineer (On‑Prem)
**Role Summary**
Design, implement, secure, and maintain enterprise Active Directory and hybrid identity solutions. Provide tier‑3 support, automate administration, enforce security controls, and mentor junior staff to ensure a robust, scalable, and compliant identity infrastructure.
**Expectations**
- Deliver high‑availability, secure AD environments for a global organization.
- Apply industry‑best practices for security, compliance, and automation.
- Lead migration, upgrade, and integration projects with minimal supervision.
- Foster collaboration with IT Security, Cloud, and Application teams.
- Maintain operational excellence and continuous improvement of identity services.
**Key Responsibilities**
- Architect and implement AD, Azure AD, and hybrid identity solutions.
- Design OU hierarchy, Group Policies, DNS/DHCP integration, and replication topology.
- Provide tier‑3 support for AD, ADFS, Azure AD Connect, PKI, and secure LDAP.
- Monitor, troubleshoot, and optimize authentication and authorization flows.
- Enforce privileged access management, conditional access, MFA, and Zero‑Trust principles.
- Conduct audits, vulnerability assessments, and remediation activities.
- Develop and maintain PowerShell/Python automation for AD administration and reporting.
- Lead migrations, upgrades, and integrations with cloud and SaaS platforms.
- Mentor junior engineers and contribute to knowledge‑sharing initiatives.
**Required Skills**
- 8+ years of on‑prem Active Directory experience (Windows Server 2016‑2022).
- Deep expertise in Azure AD, ADFS, Azure AD Connect, Conditional Access, SSO/Federation.
- Advanced PowerShell scripting and automation proficiency.
- Strong knowledge of Group Policy, Kerberos, LDAP, NTLM, and authentication protocols.
- Experience with PKI, certificate services, secure LDAP, DNS, and DHCP.
- Familiarity with identity security frameworks: Zero Trust, PAM, MFA.
- Cloud integrations: Microsoft 365, SaaS apps, SAML, OAuth, SCIM.
- Incident response and directory security hardening.
- Excellent analytical, communication, leadership, and documentation abilities.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, IT, or equivalent experience.
- Microsoft Certified: Identity and Access Administrator Associate (or similar) preferred.
- Certifications in Azure AD, IAM (Okta, Ping), or cybersecurity frameworks highly valued.
Jersey city, United states
On site
Senior
31-10-2025