L3 Active Directory Engineer – Identity Security (IAM, PAM, AD DS)
Job Summary
Senior Active Directory L3 Support Engineer
Work Model Hybrid 4 Days Work From Office
Job Summary
We are seeking an experienced Senior Active Directory L3 Support Engineer to strengthen and modernize enterprise Active Directory services across production and disaster recovery environments. The ideal candidate will have extensive experience in Active Directory administration infrastructure modernization identity security and PowerShell automation while supporting highly available and secure enterprise environments.
The role will focus on Active Directory modernization security hardening privileged access remediation Group Policy optimization and Zero Trust initiatives.
Key Responsibilities
Active Directory Infrastructure & Modernization
- Deploy and configure additional Domain Controllers across production and disaster recovery environments.
- Replace legacy Windows Server 2016 Domain Controllers with modern infrastructure while minimizing business disruption.
- Support Active Directory platform modernization initiatives.
- Implement network segmentation to align with Zero Trust architecture and reduce lateral movement risks.
- Maintain Active Directory health including replication DNS integration authentication services and Group Policy processing.
Security Hardening & Identity Protection
- Implement Extended Protection for Authentication (EPA).
- Enforce SSL/TLS for privileged Active Directory services.
- Configure SMB Signing to prevent NTLM relay attacks.
- Disable NTLMv1 and enforce LDAP Signing and LDAPS.
- Implement Kerberos Hardening and secure delegation controls.
- Remediate excessive privilege findings including:
- AdminCount issues
- Missing ACL protections
- Protected Users enrollment
- GPO-based security exposures
- Strengthen privileged account management and password policies.
- Identify and remediate insecure account configurations.
Group Policy & Compliance
- Harden enterprise Group Policy configurations.
- Enable PowerShell logging and advanced audit policies.
- Configure secure encryption standards and Remote Desktop settings.
- Review and remediate LDAP authentication and domain security weaknesses.
- Document implementation standards remediation plans and operational procedures for audit compliance.
Collaboration & Operational Support
- Partner with Infrastructure Security and Application teams during security remediation projects.
- Support controlled production deployments and change management activities.
- Participate in infrastructure upgrades and domain controller migration projects.
- Automate administrative tasks using PowerShell scripting.
Required Skills
- Extensive experience administering Active Directory Domain Services (AD DS) in enterprise environments.
- Strong knowledge of:
- Active Directory Administration
- Domain Controllers
- Active Directory Replication
- DNS
- Group Policy (GPO)
- Authentication protocols
- Disaster Recovery
- Hands-on experience implementing:
- Extended Protection for Authentication (EPA)
- LDAP Signing
- LDAPS
- Kerberos Hardening
- SMB Signing
- Privileged Account Protection
- Experience with:
- Active Directory Certificate Services (AD CS)
- Active Directory Web Services (ADWS)
- Windows Server Hardening
- Identity Security Remediation
- Strong PowerShell scripting and automation skills.
- Experience executing infrastructure modernization and Active Directory migration projects.
- Ability to analyze and remediate privilege escalation paths and identity security risks.
Preferred Qualifications
- Experience supporting highly regulated enterprise environments.
- Knowledge of:
- Zero Trust Architecture
- Privileged Access Management (PAM)
- CyberArk
- Identity Security Assessments
- Audit & Compliance
- Change Management
- Microsoft certifications related to Windows Server Active Directory Security or Identity Administration are highly desirable.
Required Technologies
- Active Directory Domain Services (AD DS)
- Active Directory Administration
- Domain Controllers
- Active Directory Replication
- DNS
- Group Policy (GPO)
- LDAP Signing
- LDAPS
- Kerberos
- SMB Signing
- Extended Protection for Authentication (EPA)
- PowerShell
- Windows Server
- Active Directory Certificate Services (AD CS)
- Active Directory Web Services (ADWS)
- Disaster Recovery
- Identity Security
Nice to Have
- CyberArk
- Privileged Access Management (PAM)
- Zero Trust Security
- Infrastructure Modernization
- Audit & Compliance
- Identity Governance
Required Skills:
60-70
Required Education:
Backend Engineer Kotlin Microservices & AKSRole Overview:We are seeking a highly skilled backend developer with strong experience in modern programming languages and frameworks with primary expertise in Kotlin and exposure to Java microservices and cloud Skills:Proficiency in Kotlin with additional experience in Java (Spring Boot Spring Security) and JavaScript () 5 years of backend development experience including: oUnit testing frameworks (e.g.