> Markdown version of [/jobs/ext/2721552-identity-engineer](https://www.wearedevelopers.com/jobs/ext/2721552-identity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity Engineer - **Company:** Blueprint School Network, Inc. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Ad Management, Active Directory Federation Services, Domain Controllers, Audit Trail, User Authentication, Microsoft Azure, Desktop Computing, Disaster Recovery, Domain Name System (DNS), Monitoring of Systems, Identity and Access Management, System Center Operations Management, Public Key Infrastructure, Windows PowerShell, Azure Active Directory, Data Logging, Cloud Monitoring, HR Software, Integration Frameworks, ManageEngine - **Published:** September 4, 2026 - **Apply:** https://simeio.applytojob.com/apply/u5vhJqluEq/Senior-Identity-Engineer-AD?source=GS ## About the Role * Strong experience as an Active Directory Architect, including domain consolidation, AD assessment, and enterprise identity infrastructure review. * Hands-on knowledge of Active Directory forest, site, domain, OU, security group, authentication, and group policy design. * Experience assessing Azure/Entra ID deployments and hybrid identity environments. * Ability to run and interpret PowerShell queries against AD domains to gather statistics on users, accounts, groups, OUs, computer objects, and related AD/Azure objects. * Ability to identify configuration and operational gaps and prioritize them based on criticality and risk. * Experience reviewing AD configurations, processes, and documentation. * Working knowledge of tools such as ADUC, Group Polcies, DNS, AD Trusts, AD Sites and services, AD Replications, and other AD scanning utilities. * Ability to provide practical recommendations, remediation planning inputs, resource estimates, skill requirements, and budget estimates. * Strong communication skills to document findings, recommendations, risks, and remediation plans for stakeholders. ## Description The Active Directory Architect (Domain Consolidation) will support a US-based engagement focused on assessing the client's on-premises Active Directory (AD) and Azure/Entra ID deployment. The role involves evaluating forest, site, domain, security group, organizational unit (OU), authentication, group policy, and deployment architecture, identifying configuration and operational gaps, and providing recommendations to address critical risks. The architect will also review existing AD management processes, gather data using tools such as PowerShell, ADUC, and help define the resources, skills, and budget required for remediation. What You'll Do: * Assess the current state of the client's Active Directory and Azure/Entra ID deployment, including forest design, site design, domain design, security group topology, deployment architecture, organizational unit ("OU") design, authentication, and group policy design. * Run PowerShell queries against the client AD to determine relevant statistics of current AD and Azure objects, including users, accounts, groups, organizational units (OUs), computer objects, and related identity objects * Review AD configurations, processes, and documentation to understand the client's current deployment and operating model. * Identify configuration and operational gaps in the client's AD domains, infrastructure, architecture, and deployment. * Prioritize identified gaps based on criticality and risk. * Provide recommendations to address critical gaps and risks across AD and Entra ID environments. * Discover and assess current processes for AD group management, AD group policy management, and AD account management. * Suggest modifications and refinements to existing processes and create new processes if required. * Determine the resources and skills necessary to complete remediation activities and achieve defined milestones. * Provide an estimated budget to accomplish remediation as outlined during the assessment phases. * Leverage client tools such as ADUC (Active Directory Users & Computers), ManageEngine, StealthAUDIT, or other AD scanning utilities as needed to accomplish data-gathering activities., * Disaster Recovery & Backup, review AD forest recovery readiness, backup schedules, and Azure Entra disaster recovery setup. * Monitoring & Alerting, Evaluate monitoring tools (SCOM, ManageEngine, Azure Monitor) and alert thresholds for AD/Entra events. * Privileged Access Management, Assess privileged account handling, tiered admin models, and PAM/JIT/JEA usage. * Certificate & PKI Integration, Review AD CS/PKI setup, certificate lifecycle management, and Entra authentication integration. * Hybrid Identity & Federation, Evaluate ADFS, Pass-through Authentication, Seamless SSO, and hybrid identity configurations. * Conditional Access & MFA, Review conditional access policies, MFA enforcement, and exception handling. * Lifecycle Management, Assess joiner/mover/leaver processes, automation, and HR system integration. * Audit & Compliance, Review logging, audit trails, and compliance with ISO, SOC2, GDPR, etc. * Patch & Update Management, Validate patch/update cadence for Domain Controllers and Entra connectors. * Third-Party Integrations, Identify external apps/services integrated with AD/Entra and assess their security posture. ## Related Videos - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [What if your HR software adapted to you, not the other way around?](https://www.wearedevelopers.com/videos/100259-what-if-your-hr-software-adapted-to-you-not-the-other-way-around) - [How One Developer Built the Back Office for 10 Million Companies](https://www.wearedevelopers.com/videos/100082-how-one-developer-built-the-back-office-for-10-million-companies) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)