Microsoft Security Active Directory Senior Consultant

Deloitte T.T.L.
Morristown, NJ, United States
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Active Directory Domain Controllers User Authentication Cyber Security Dynamic Host Configuration Protocol Domain Name System (DNS) Identity and Access Management Intrusion Detection and Prevention Lightweight Directory Access Protocols (LDAP) Microsoft Security Essentials Role-Based Access Control Azure Active Directory
+2 more
Cloud Platform System Information Technology

Job description

Experteer Overview In this role, you will lead and shape Active Directory and identity infrastructure initiatives for clients, aligning with Deloitte Cyber’s mission to strengthen identity, access, and platform security. You will work across assessment, design, migration, and stabilization phases, guiding secure, scalable AD environments and hybrid identity integrations. You’ll solve complex identity and access challenges, from security hardening to migration planning, delivering measurable resilience for clients. You will collaborate with cross-functional teams and senior stakeholders to drive impactful outcomes and support organizational risk reduction. Compensation / Benefits * Lead Active Directory and identity infrastructure engagements through assessment, design, migration, implementation, stabilization, and post-implementation phases * Conduct and oversee AD assessments covering architecture, DNS/DHCP, replication, GPOs, trusts, service accounts, authentication, and admin processes * Design and implement AD security hardening (tiering, RBAC, service accounts, GPO controls, identity threat detection) * Architect and support enterprise AD environments, including hybrid identity with Microsoft Entra ID, federation, and synchronization * Lead or support domain/forest migrations, separations, consolidations (discovery, dependency analysis, cutover planning, validation, rollback, post-migration stabilization) Tasks * Bachelor’s degree in Computer Science, Cybersecurity, Information Security, Engineering, Information Technology, or another technical field * 4+ years of experience in technical consulting, enterprise infrastructure, identity security, or AD engineering * 4+ years hands-on experience designing, securing, assessing, migrating, or operating Microsoft Active Directory environments * Experience with AD services: domain/forest architecture, domain controllers and replication, DNS, DHCP, Sites and Services, Group Policy, trusts, service accounts, LDAP, recovery * Experience leading or supporting AD domain/forest migrations, separations, or consolidations * Experience with migration tooling (Quest On Demand Migration or Semperis) * Experience with identity threat detection or recovery tooling (Semperis, Rubrik, Microsoft Defender for Identity) * Ability to travel up to 50% * Limited immigration sponsorship may be available Key requirements * Discretionary annual incentive program * Accommodations for people with disabilities * Travel opportunity (up to 50% when needed)

Requirements

  • Design and implement AD security hardening (tiering, RBAC, service accounts, GPO controls, identity threat detection) * Architect and support enterprise AD environments, including hybrid identity with Microsoft Entra ID, federation, and synchronization * Lead or support domain/forest migrations, separations, consolidations (discovery, dependency analysis, cutover planning, validation, rollback, post-migration stabilization) Tasks * Bachelor’s degree in Computer Science, Cybersecurity, Information Security, Engineering, Information Technology, or another technical field * 4+ years of experience in technical consulting, enterprise infrastructure, identity security, or AD engineering * 4+ years hands-on experience designing, securing, assessing, migrating, or operating Microsoft Active Directory environments * Experience with AD services: domain/forest architecture, domain controllers and replication, DNS, DHCP, Sites and Services, Group Policy, trusts, service accounts, LDAP, recovery * aaa service leading or supporting AD domain/forest migrations, separations, or consolidations * Experience with migration tooling (Quest On Demand Migration or Semperis) * Experience with identity threat detection or recovery tooling (Semperis, Rubrik, Microsoft Defender for Identity) * Ability to travel up to 50% * Limited immigration sponsorship may be available Key requirements * Discretionary annual incentive program * Accommodations for people with disabilities * Travel opportunity (up to 50% when needed)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen Ā· LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman Ā· WWC 2022

2:14 min

Custom domain controllers and vehicle communication networks

Denis Grahovac Ā· WWC 2021

1:45 min

Evolution from manual setups to automated monolith deployments

Axel Barbier Ā· WWC 2023

2:48 min

Daily responsibilities and alignment practices for technical engineering leadership

Edoardo Dusi Ā· LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger Ā· LIVE

Videos

See all

Related articles

See all