Summary
We are seeking an experienced L2 Active Directory Engineer to support and administer enterprise Identity and Access Management (IAM) services. The role is responsible for managing Microsoft Active Directory, Microsoft Entra ID (Azure AD), user provisioning, authentication, and access management while serving as the Level 2 escalation point for identity-related incidents and service requests. The successful candidate will ensure secure, reliable, and compliant directory services through effective administration, troubleshooting, automation, and continuous improvement.
Responsibilities
- Administer and maintain Microsoft Active Directory, Microsoft Entra ID (Azure AD), and Azure AD Connect.
- Manage user, group, computer, and Organizational Unit (OU) administration, including Joiner, Mover, and Leaver (JML) processes.
- Create, maintain, and troubleshoot Group Policies (GPOs), directory replication, and authentication services.
- Support identity synchronization, Conditional Access, Multi-Factor Authentication (MFA), Self-Service Password Reset (SSPR), and hybrid identity environments.
- Provision, modify, and revoke user access in accordance with IAM policies and role-based access controls (RBAC).
- Investigate and resolve complex identity-related incidents, including account lockouts, authentication failures, access issues, and synchronization problems.
- Develop and maintain PowerShell scripts to automate user provisioning, reporting, and routine administrative tasks.
- Maintain technical documentation, standard operating procedures (SOPs), runbooks, and operational reports.
- Collaborate with infrastructure, security, and application teams to ensure service availability, security compliance, and continuous service improvement.
Requirements
- Bachelor's degree in Computer Science, Information Technology, or a related discipline.
- Minimum 5 years of experience supporting enterprise Microsoft Active Directory environments.
- Strong knowledge of Microsoft Active Directory, Microsoft Entra ID (Azure AD), Azure AD Connect, Group Policy, LDAP, DNS, Windows Server Administration, and IAM.
- Experience with PowerShell scripting and automation.
- Familiarity with MFA, Conditional Access, RBAC, and user lifecycle management.
- Microsoft Identity, Azure Administrator, or related certifications are an advantage.