Microsoft Security Active Directory Senior Consultant

Deloitte T.T.L.
Miami, FL, United States
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Active Directory Domain Controllers Cyber Security Dynamic Host Configuration Protocol Domain Name System (DNS) Identity and Access Management Intrusion Detection and Prevention Lightweight Directory Access Protocols (LDAP) Microsoft Security Essentials Role-Based Access Control Information Technology

Job description

Experteer Overview In this role you drive identity and access security initiatives within Deloitte’s Cyber team, focusing on Active Directory architecture, security enhancements, and hybrid identity integrations. You will lead engagements across assessment, design, migration, and stabilization, influencing enterprise identity environments for clients. You will work with cross-functional teams to deliver resilient, secure identity platforms and enable seamless digital interactions. This is a hands-on leadership role with a clear impact on client security posture and identity strategy. Compensation / Benefits * Lead Active Directory and identity infrastructure engagements across assessment, design, migration, implementation, stabilization, and post-implementation phases * Conduct and oversee Active Directory assessments covering architecture components (DNS/DHCP, Domain Controllers, replication, trusts, GPOs, service accounts, LDAP) and administrative processes * Design and implement AD security hardening (tiering, RBAC, service account governance, GPO controls, identity threat detection and recovery) * Architect and support enterprise AD environments with hybrid identity (Entra ID, federation, synchronization, app dependencies) * Lead or support domain/forest migrations, including discovery, dependency analysis, cutover planning, validation, rollback, and post-migration stabilization Tasks * Bachelor’s degree in Computer Science, Cybersecurity, Information Security, Engineering, Information Technology, or another technical field * 4+ years of technical consulting, enterprise infrastructure, identity security, or AD engineering experience * 4+ years hands-on experience designing, securing, assessing, migrating, or operating Microsoft Active Directory environments * Experience with enterprise AD services: domain/forest architecture, domain controllers, DNS, DHCP, Sites and Services, Group Policy, trusts, service accounts, LDAP, and recovery * Experience leading or supporting AD domain/forest migrations, separations, or consolidations * Experience with migration tooling (Quest ODM or Semperis) * Experience with identity threat detection, identity resilience, cyber recovery, or recovery tooling (Semperis, Rubrik, Microsoft Defender for Identity) * Ability to travel up to 50% * Limited immigration sponsorship may be available Key requirements * Discretionary annual incentive program

Requirements

security hardening (tiering, RBAC, service account governance, GPO controls, identity threat detection and recovery) * Architect and support enterprise AD environments with hybrid identity (Entra ID, federation, synchronization, app dependencies) * Lead or support domain/forest migrations, including discovery, dependency analysis, cutover planning, validation, rollback, and post-migration stabilization Tasks * Bachelor’s degree in Computer Science, Cybersecurity, Information Security, Engineering, Information Technology, or another technical field * 4+ years of technical consulting, enterprise infrastructure, identity security, or AD engineering experience * 4+ years hands-on experience designing, securing, assessing, migrating, or operating Microsoft Active Directory environments * Experience with enterprise AD services: domain/forest architecture, domain controllers, DNS, DHCP, Sites and Services, Group Policy, trusts, service accounts, LDAP, and recovery * Experience leading or supporting AD domain/forest migrations, separations, or consolidations * Experience with migration tooling (Quest ODM or Semperis) * Experience with identity threat detection, identity resilience, cyber recovery, or recovery tooling (Semperis, Rubrik, Microsoft Defender for Identity) * Ability to travel up to 50% * Limited immigration sponsorship may be available Key requirements * Discretionary annual incentive program

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman Ā· WWC 2022

1:45 min

Evolution from manual setups to automated monolith deployments

Axel Barbier Ā· WWC 2023

2:14 min

Custom domain controllers and vehicle communication networks

Denis Grahovac Ā· WWC 2021

1:45 min

Transitioning from software development to security roles

Stefania Chaplin Ā· WWC 2022

4:16 min

In-vehicle and off-vehicle software control architecture components

Denis Grahovac Ā· WWC 2021

3:18 min

Eliminating passwords using Azure managed identities

Markus Möller · WWC 2021

Videos

See all

Related articles

See all