freehire launches on Product Hunt on 26 August.

Follow →

DTICI_IAM_ActiveDirectory_Senior Conultant_T8

Open 21d
This position is no longer accepting applications(closed Aug 17, 2026).

Summary

Senior consultant responsible for managing and securing enterprise Active Directory infrastructure, including Tier-0 environments, migrations, automation, and compliance in a large corporate setting.

We are looking for an experienced Active Directory Engineer (5+ years) to manage and enhance enterprise AD infrastructure with a strong focus on operations, Tier-0 (T0) environment security, migrations, change management, and automation.

The role will ensure secure, stable, and scalable identity services, while driving automation-led efficiency and maintaining strict control over privileged (Tier-0) assets and access pathways.

Key Responsibilities

1. Active Directory Operations

  • Manage and support Active Directory Domain Services (AD DS) in enterprise environments.
  • Perform BAU activities:
    • User, group, and OU management
    • GPO administration
    • DNS and authentication services
  • Monitor and troubleshoot:
    • Replication issues
    • Kerberos / NTLM authentication failures
    • GPO processing issues
    • Domain Controller health & performance
  • Maintain AD hygiene:
    • Cleanup of stale objects
    • Privileged group monitoring
    • Standardized OU and naming structures

2. Tier-0 (T0) Environment Management

  • Manage and secure Tier-0 identity infrastructure, including:
    • Domain Controllers
    • Privileged admin accounts
    • Built-in admin groups (Domain Admins, Enterprise Admins)
  • Enforce Tier-0 security controls:
    • Least privilege access
    • Privileged account segregation
    • Controlled administrative access
    • Access reviews and recertification
  • Identify and remediate risks:
    • Stale or excessive privileged access
    • Weak delegations and ACL misconfigurations
    • Unauthorized access pathways
  • Support Tier-0 governance, hardening, and compliance requirements.

3. AD Migrations & Transformation

  • Plan and execute AD migration projects, including:
    • Domain/forest migrations
    • Consolidation or separation initiatives
  • Perform:
    • Pre-migration assessments and dependency analysis
    • Risk evaluation and rollback planning
    • Migration execution and post-validation
  • Manage:
    • Trust relationships
    • SID history
    • Authentication continuity for applications

4. Change Management & Governance

  • Execute AD changes through structured ITIL-based change management:
    • Standard, Normal, and Emergency changes
  • Prepare detailed change artifacts:
    • Impact analysis
    • Risk assessment
    • Rollback strategy
    • Validation steps
  • Coordinate with CAB and stakeholders to ensure smooth execution.
  • Maintain detailed documentation:
    • RFCs, implementation plans, post-change reports
  • Ensure compliance with audit, security, and governance standards.

5. Automation & Process Optimization

  • Identify and automate repetitive AD and operational tasks using PowerShell (mandatory).
  • Develop automation for:
    • User and group lifecycle management
    • GPO and OU operations
    • Health monitoring and alert validation
    • Migration validation and reporting
    • Privileged access tracking and reporting
  • Build reusable scripts with:
    • Error handling
    • Logging and audit traceability
    • Approval-based execution (where required)
  • Drive standardization and efficiency through automation-first approach.

6. Incident & Problem Management

  • Provide L2/L3 support for AD-related incidents.
  • Participate in major incident bridges for authentication or AD outages.
  • Perform root cause analysis (RCA) and implement preventive measures.
  • Ensure minimal downtime and quick recovery for critical identity services.

7. Documentation & Compliance

  • Maintain runbooks, SOPs, and architecture documentation.
  • Support audit and compliance activities by providing:
    • Access control evidence
    • Change records
    • Operational logs
  • Ensure adherence to enterprise security policies and governance frameworks.

Required Qualifications

  • Bachelor’s degree in IT / Computer Science or related field.
  • 5+ years of experience in Active Directory administration/engineering.
  • Strong expertise in:
    • AD DS, Domain Controllers, GPO, DNS
    • AD Sites & Services, replication troubleshooting
    • Authentication protocols (Kerberos / NTLM)
  • Proven experience in:
    • Tier-0 / privileged environment management
    • AD migrations (domain/forest level)
    • Change management (ITIL processes, CAB)
  • Strong scripting skills in PowerShell.

Technical Skills

  • Active Directory (AD DS)
  • Tier-0 / Privileged Infrastructure Security
  • AD Migration (ADMT or equivalent)
  • Group Policy (GPO)
  • DNS & Authentication Troubleshooting
  • PowerShell Automation
  • Replication & DC Health Management
  • Change Management (ITIL)
  • Incident & Problem Management

Preferred / Good to Have

  • Hybrid identity experience: Entra ID / Azure AD Connect
  • Experience with PAM/PIM tools (CyberArk, BeyondTrust, Entra PIM)
  • Familiarity with ServiceNow or ITSM tools
  • Understanding of Zero Trust and Tiering models (T0/T1/T2)
  • Experience in large enterprise or global AD environments

Key Competencies

  • Strong ownership and accountability
  • Structured thinking with risk assessment mindset
  • Attention to detail in change execution
  • Strong troubleshooting and analytical skills
  • Effective communication and stakeholder management
  • Ability to perform in high-pressure situations

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available