Identity Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+9 more
Job description
The Active Directory Architect (Domain Consolidation) will support a US-based engagement focused on assessing the clientâs on-premises Active Directory (AD) and Azure/Entra ID deployment. The role involves evaluating forest, site, domain, security group, organizational unit (OU), authentication, group policy, and deployment architecture, identifying configuration and operational gaps, and providing recommendations to address critical risks. The architect will also review existing AD management processes, gather data using tools such as PowerShell, ADUC, and help define the resources, skills, and budget required for remediation.
What Youâll Do:
- Assess the current state of the clientâs Active Directory and Azure/Entra ID deployment, including forest design, site design, domain design, security group topology, deployment architecture, organizational unit (âOUâ) design, authentication, and group policy design.
- Run PowerShell queries against the client AD to determine relevant statistics of current AD and Azure objects, including users, accounts, groups, organizational units (OUs), computer objects, and related identity objects
- Review AD configurations, processes, and documentation to understand the clientâs current deployment and operating model.
- Identify configuration and operational gaps in the clientâs AD domains, infrastructure, architecture, and deployment.
- Prioritize identified gaps based on criticality and risk.
- Provide recommendations to address critical gaps and risks across AD and Entra ID environments.
- Discover and assess current processes for AD group management, AD group policy management, and AD account management.
- Suggest modifications and refinements to existing processes and create new processes if required.
- Determine the resources and skills necessary to complete remediation activities and achieve defined milestones.
- Provide an estimated budget to accomplish remediation as outlined during the assessment phases.
- Leverage client tools such as ADUC (Active Directory Users & Computers), ManageEngine, StealthAUDIT, or other AD scanning utilities as needed to accomplish data-gathering activities., * Disaster Recovery & Backup, review AD forest recovery readiness, backup schedules, and Azure Entra disaster recovery setup.
- Monitoring & Alerting, Evaluate monitoring tools (SCOM, ManageEngine, Azure Monitor) and alert thresholds for AD/Entra events.
- Privileged Access Management, Assess privileged account handling, tiered admin models, and PAM/JIT/JEA usage.
- Certificate & PKI Integration, Review AD CS/PKI setup, certificate lifecycle management, and Entra authentication integration.
- Hybrid Identity & Federation, Evaluate ADFS, Pass-through Authentication, Seamless SSO, and hybrid identity configurations.
- Conditional Access & MFA, Review conditional access policies, MFA enforcement, and exception handling.
- Lifecycle Management, Assess joiner/mover/leaver processes, automation, and HR system integration.
- Audit & Compliance, Review logging, audit trails, and compliance with ISO, SOC2, GDPR, etc.
- Patch & Update Management, Validate patch/update cadence for Domain Controllers and Entra connectors.
- Third-Party Integrations, Identify external apps/services integrated with AD/Entra and assess their security posture.
Requirements
- Strong experience as an Active Directory Architect, including domain consolidation, AD assessment, and enterprise identity infrastructure review.
- Hands-on knowledge of Active Directory forest, site, domain, OU, security group, authentication, and group policy design.
- Experience assessing Azure/Entra ID deployments and hybrid identity environments.
- Ability to run and interpret PowerShell queries against AD domains to gather statistics on users, accounts, groups, OUs, computer objects, and related AD/Azure objects.
- Ability to identify configuration and operational gaps and prioritize them based on criticality and risk.
- Experience reviewing AD configurations, processes, and documentation.
- Working knowledge of tools such as ADUC, Group Polcies, DNS, AD Trusts, AD Sites and services, AD Replications, and other AD scanning utilities.
- Ability to provide practical recommendations, remediation planning inputs, resource estimates, skill requirements, and budget estimates.
- Strong communication skills to document findings, recommendations, risks, and remediation plans for stakeholders.
About the company
Simeio has over 650 talented employees across the globe. We have offices in USA (Atlanta HQ and Texas), India, Canada, Costa Rica, and UK. Founded in 2007, and now backed by private equity company ZMC, Simeio is recognized as a top IAM provider by industry analysts. Alongside Simeioâs identity orchestration tool, Simeio IOâ - Simeioâ is also partners with industry leading IAM software vendors to provide access management, identity governance and administration, privileged access management and risk intelligence services across on-premises, cloud, and hybrid technology environments. Simeio provides services to numerous Fortune 1000 companies across all industries including financial services, technology, healthcare, media, retail, public sector, utilities, and education.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Everything a Developer Needs to Know About MCP with Neo4j
How We Built a Worry-Free System That Runs for 10+ Years â And What Weâd Do Again
Navigating the AI Shift