Active Directory Architect/SME

Lucid Support Services Ltd
Corsham, UK
5 days ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Microsoft Access Active Directory Active Directory Federation Services Authentication Protocols Cyber Security Dynamic Host Configuration Protocol Software Design Patterns Domain Name System (DNS) High-Level Architecture Identity and Access Management Javaserver Pages Kerberos (Protocol)
+9 more
Lightweight Directory Access Protocols (LDAP) Windows Servers NT LAN Manager OAuth Windows PowerShell Runbook Security Assertion Markup Language (SAML) Security Information and Event Management Togaf

Job description

  • We are seeking a highly skilled Microsoft Active Directory Subject Matter Expert (SME) to lead the design, implementation, and optimisation of enterprise directory services within secure, high-assurance environments.
  • This role requires deep technical expertise in Active Directory architecture, strong delivery experience, and the ability to operate both strategically and hands-on. The successful candidate will support a UK secure account, working closely with stakeholders and delivering solutions on customer sites., * Lead the architecture, design, and evolution of Microsoft Active Directory environments (on premises)
  • Act as the technical SME for Active Directory, providing expert guidance on best practices, policies, and standards
  • Design and implement secure AD architectures, including domains, forests, trusts, and replication strategies
  • Develop and enforce Group Policy (GPO) strategies aligned with security and operational requirements
  • Deliver identity services integration, including federation (ADFS)
  • Define and implement tiered administration models, privileged access controls, Integration with Privileged access Management tooling, and secure identity design patterns
  • Conduct health checks, security assessments, and remediation planning for AD environments
  • Support incident resolution and root cause analysis relating to identity and authentication services
  • Produce and maintain comprehensive design and operational documentation
  • Work closely with security, infrastructure, and application teams to ensure secure and efficient identity services
  • Engage directly with Tech Lead, Programme Manager and customers on-site, supporting delivery and building trusted relationships

Requirements

  • Proven experience in an Active Directory Architect or Senior SME role

Deep hands-on expertise with:

  • Microsoft Active Directory (multi-domain/forest environments)
  • Group Policy design and management
  • DNS, DHCP, and core supporting infrastructure
  • Strong experience in designing and implementing enterprise-scale AD environments

Demonstrable experience producing high-quality design documentation, including:

  • High-Level Designs (HLDs)
  • Low-Level Designs (LLDs)
  • Security architecture documentation
  • Operational procedures and runbooks

Strong understanding of identity security, including:

  • Tiered administration models
  • Least privilege access
  • Privileged Access Workstations (PAWs)
  • Privileged access Management Toolset
  • Knowledge of authentication protocols (Kerberos, NTLM, LDAP, SAML, OAuth)
  • Experience with PowerShell Scripting and automation
  • Familiarity with integrating AD into enterprise security and monitoring tooling (eg, SIEM)
  • Excellent stakeholder engagement, communication, and documentation skills

Industry Experience:

  • Experience working within the Defence and/or Aerospace sector is highly desirable
  • Familiarity with policies, standards, and security frameworks (eg, JSP series, NCSC guidance)
  • Familiarity with high-security, regulated environments and secure system delivery

Desirable Certifications

  • Microsoft certifications (eg, Identity and Access Administrator, Windows Server)
  • CISSP, CISM, or equivalent security certifications
  • TOGAF or other architecture frameworks (desirable)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerboard.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:08 min

Managing complex structures and corporate guidelines

Alexandra Petri · WWC 2023

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · WWC Europe 2026

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all