active directory sme - dv cleared.

Randstad UK
Erskine, UK
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£104,000.0 - £130,000.0
Working hours
Regular working hours

Tech stack

Microsoft Access Active Directory Authentication Protocols Cloud Computing Cyber Security Dynamic Host Configuration Protocol Domain Name System (DNS) High-Level Architecture Identity and Access Management Javaserver Pages Kerberos (Protocol) Lightweight Directory Access Protocols (LDAP)
+11 more
Windows Servers NT LAN Manager OAuth Windows PowerShell Cloud Services Runbook Security Assertion Markup Language (SAML) Security Information and Event Management Cloudformation Togaf Servicenow

Job description

We are seeking a highly skilled Microsoft Active Directory Subject Matter Expert (SME) to lead the design, implementation, and optimization of enterprise directory services within secure, high-assurance environments. As a key member of our build engineering team, you will be responsible for implementing sophisticated cloud solutions and ensuring the integrity of identity services for a critical UK secure account., * Lead the architecture, design, and evolution of on-premises Microsoft Active Directory environments.

  • Implement secure AD architectures, including domains, forests, trusts, and replication strategies.
  • Create Cloud landing zones and develop CloudFormation templates for base infrastructure.
  • Develop and enforce Group Policy (GPO) strategies aligned with high-security requirements.
  • Define and implement tiered administration models and privileged access controls.
  • Onboard customer accounts to Service Now and publish standard/custom templates., * Lead the architecture, design, and evolution of on-premises Microsoft Active Directory environments.
  • Implement secure AD architectures, including domains, forests, trusts, and replication strategies.
  • Create Cloud landing zones and develop CloudFormation templates for base infrastructure.
  • Develop and enforce Group Policy (GPO) strategies aligned with high-security requirements.
  • Define and implement tiered administration models and privileged access controls.
  • Onboard customer accounts to Service Now and publish standard/custom templates.

The role is idealaly based on-site in Erskine but we can also consider appliacnts who can work hybrisd form Farnborough, Corsham or Newcastle.

So if you have the required level of Clearance to DV level then apply today as I have interview slots ready to be filled.

Requirements

  • Proven experience in an Active Directory Architect or Senior SME role
  • Deep hands-on expertise with:
  • Microsoft Active Directory (multi-domain/forest environments)
  • Group Policy design and management
  • DNS, DHCP, and core supporting infrastructure
  • Strong experience in designing and implementing enterprise-scale AD environments
  • Demonstrable experience producing high-quality design documentation, including:

  • High-Level Designs (HLDs)
  • Low-Level Designs (LLDs)
  • Security architecture documentation
  • Operational procedures and runbooks

Strong understanding of identity security, including:

  • Tiered administration models
  • Least privilege access
  • Privileged Access Workstations (PAWs)
  • Privileged access Management Toolset

Knowledge of authentication protocols (Kerberos, NTLM, LDAP, SAML, OAuth)

Experience with PowerShell scripting and automation

Familiarity with integrating AD into enterprise security and monitoring tooling (e.g., SIEM)

Excellent stakeholder engagement, communication, and documentation skills

Industry Experience

  • Experience working within the Defence and/or Aerospace sector is highly desirable
  • Familiarity with policies, standards, and security frameworks (e.g., JSP series, NCSC guidance)
  • Familiarity with high-security, regulated environments and secure system delivery

Desirable Certifications

  • Microsoft certifications (e.g., Identity and Access Administrator, Windows Server)
  • CISSP, CISM, or equivalent security certifications
  • TOGAF or other architecture frameworks (desirable)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.randstad.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:08 min

Managing complex structures and corporate guidelines

Alexandra Petri · WWC 2023

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · WWC Europe 2026

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all