Identity Engineer

Blueprint School Network, Inc.
United States
1 day ago
Apply on simeio.applytojob.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Active Directory Ad Management Active Directory Federation Services Domain Controllers Audit Trail User Authentication Microsoft Azure Desktop Computing Disaster Recovery Domain Name System (DNS) Monitoring of Systems Identity and Access Management
+9 more
System Center Operations Management Public Key Infrastructure Windows PowerShell Azure Active Directory Data Logging Cloud Monitoring HR Software Integration Frameworks ManageEngine

Job description

The Active Directory Architect (Domain Consolidation) will support a US-based engagement focused on assessing the client’s on-premises Active Directory (AD) and Azure/Entra ID deployment. The role involves evaluating forest, site, domain, security group, organizational unit (OU), authentication, group policy, and deployment architecture, identifying configuration and operational gaps, and providing recommendations to address critical risks. The architect will also review existing AD management processes, gather data using tools such as PowerShell, ADUC, and help define the resources, skills, and budget required for remediation.

What You’ll Do:

  • Assess the current state of the client’s Active Directory and Azure/Entra ID deployment, including forest design, site design, domain design, security group topology, deployment architecture, organizational unit (“OU”) design, authentication, and group policy design.
  • Run PowerShell queries against the client AD to determine relevant statistics of current AD and Azure objects, including users, accounts, groups, organizational units (OUs), computer objects, and related identity objects
  • Review AD configurations, processes, and documentation to understand the client’s current deployment and operating model.
  • Identify configuration and operational gaps in the client’s AD domains, infrastructure, architecture, and deployment.
  • Prioritize identified gaps based on criticality and risk.
  • Provide recommendations to address critical gaps and risks across AD and Entra ID environments.
  • Discover and assess current processes for AD group management, AD group policy management, and AD account management.
  • Suggest modifications and refinements to existing processes and create new processes if required.
  • Determine the resources and skills necessary to complete remediation activities and achieve defined milestones.
  • Provide an estimated budget to accomplish remediation as outlined during the assessment phases.
  • Leverage client tools such as ADUC (Active Directory Users & Computers), ManageEngine, StealthAUDIT, or other AD scanning utilities as needed to accomplish data-gathering activities., * Disaster Recovery & Backup, review AD forest recovery readiness, backup schedules, and Azure Entra disaster recovery setup.
  • Monitoring & Alerting, Evaluate monitoring tools (SCOM, ManageEngine, Azure Monitor) and alert thresholds for AD/Entra events.
  • Privileged Access Management, Assess privileged account handling, tiered admin models, and PAM/JIT/JEA usage.
  • Certificate & PKI Integration, Review AD CS/PKI setup, certificate lifecycle management, and Entra authentication integration.
  • Hybrid Identity & Federation, Evaluate ADFS, Pass-through Authentication, Seamless SSO, and hybrid identity configurations.
  • Conditional Access & MFA, Review conditional access policies, MFA enforcement, and exception handling.
  • Lifecycle Management, Assess joiner/mover/leaver processes, automation, and HR system integration.
  • Audit & Compliance, Review logging, audit trails, and compliance with ISO, SOC2, GDPR, etc.
  • Patch & Update Management, Validate patch/update cadence for Domain Controllers and Entra connectors.
  • Third-Party Integrations, Identify external apps/services integrated with AD/Entra and assess their security posture.

Requirements

  • Strong experience as an Active Directory Architect, including domain consolidation, AD assessment, and enterprise identity infrastructure review.
  • Hands-on knowledge of Active Directory forest, site, domain, OU, security group, authentication, and group policy design.
  • Experience assessing Azure/Entra ID deployments and hybrid identity environments.
  • Ability to run and interpret PowerShell queries against AD domains to gather statistics on users, accounts, groups, OUs, computer objects, and related AD/Azure objects.
  • Ability to identify configuration and operational gaps and prioritize them based on criticality and risk.
  • Experience reviewing AD configurations, processes, and documentation.
  • Working knowledge of tools such as ADUC, Group Polcies, DNS, AD Trusts, AD Sites and services, AD Replications, and other AD scanning utilities.
  • Ability to provide practical recommendations, remediation planning inputs, resource estimates, skill requirements, and budget estimates.
  • Strong communication skills to document findings, recommendations, risks, and remediation plans for stakeholders.

About the company

Simeio has over 650 talented employees across the globe. We have offices in USA (Atlanta HQ and Texas), India, Canada, Costa Rica, and UK. Founded in 2007, and now backed by private equity company ZMC, Simeio is recognized as a top IAM provider by industry analysts. Alongside Simeio’s identity orchestration tool, Simeio IO’ - Simeio’ is also partners with industry leading IAM software vendors to provide access management, identity governance and administration, privileged access management and risk intelligence services across on-premises, cloud, and hybrid technology environments. Simeio provides services to numerous Fortune 1000 companies across all industries including financial services, technology, healthcare, media, retail, public sector, utilities, and education.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on simeio.applytojob.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter ¡ World Congress 2024

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski ¡ World Congress 2026 Europe

2:47 min

Designing benefit programs with high activation and low administration

Rudi Bauer Rudi Bauer +1 ¡ Cappuccino with HR

1:31 min

Integrating edge environments with enterprise identity and authorization platforms

Christian Koep Christian Koep ¡ World Congress 2025

1:09 min

Managing enterprise execution with the Operate runtime

Marcin Makowski Marcin Makowski ¡ World Congress 2026 Europe

1:35 min

Mandatory EU time tracking challenges for small business operations

Alija Nuredini Alija Nuredini ¡ World Congress 2026 Europe

Videos

See all

Related articles

See all