Active Directory Specialist

Cognizant Technology Solutions Corporation
Sleepy Hollow, United States of America
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Sleepy Hollow, United States of America

Tech stack

Microsoft Active Directory
Domain Controllers
User Authentication
Azure
Distributed File Systems
Disaster Recovery
Domain Name System Security Extensions
DNS
Identity and Access Management
Kerberos (Protocol)
Lightweight Directory Access Protocols (LDAP)
Windows Server
Public Key Infrastructure
Azure
Single Sign-On
User Provisioning Software
System Availability
Information Technology
Cloudflare
GXP

Job description

We are seeking an experienced Active Directory / Azure AD (Microsoft Entra ID) Specialist to support and manage enterprise Directory Services operations within a large-scale hybrid identity environment. The ideal candidate will have strong hands-on expertise in On-Prem Active Directory, Microsoft Entra ID (Azure AD), Azure AD Connect, DNS, Certificates, Identity & Access Management, and Directory Services Operations.

The role requires extensive experience in troubleshooting authentication and access-related issues, managing Active Directory infrastructure, maintaining hybrid identity synchronization, supporting security and compliance initiatives, and ensuring the availability and performance of mission-critical directory services.

Experience supporting regulated environments with knowledge of GxP compliance is highly preferred.

In this role, you will

  • Administer and support enterprise Active Directory and Microsoft Entra ID (Azure AD) environments, ensuring high availability, security, and performance.
  • Manage user, group, computer, and service accounts, including provisioning, deprovisioning, and access control activities.
  • Support and troubleshoot Azure AD Connect synchronization, hybrid identity, authentication, and Single Sign-On (SSO) issues.
  • Administer and maintain AD-integrated DNS, public DNS (Cloudflare), domain registrations, renewals, and DNS security.
  • Manage PKI and Certificate Services, including Internal CA and external certificates (Sectigo), renewals, and troubleshooting.
  • Monitor and resolve Active Directory replication, Group Policy (GPO), authentication, LDAP, Kerberos, and permissions-related issues.
  • Provide advanced support for critical P1/P2 incidents, perform root cause analysis, and implement preventive measures.
  • Perform Active Directory health checks, Domain Controller maintenance, patching, OS updates, backup validation, and recovery activities.
  • Manage AD security tools including Quest RMAD, Quest Change Auditor, password auditing, and identity security monitoring solutions.
  • Support disaster recovery and business continuity testing, including Domain Controller recovery, AD object restoration, and failover validation.
  • Collaborate with application teams to onboard new applications and implement directory integrations using LDAP, Kerberos, certificate-based authentication, and standard identity patterns.
  • Drive continuous improvement initiatives by identifying operational gaps, documenting procedures, recommending best practices, and partnering with stakeholders to enhance directory services operations., * Microsoft Entra ID (Azure AD)
  • Azure AD Connect
  • DNS Administration (AD Integrated & Cloudflare)
  • Group Policy Management
  • Hybrid Identity Management
  • Certificate Services / PKI
  • Incident & Problem Management
  • Authentication & Authorization Troubleshooting
  • Active Directory Replication

Requirements

  • Bachelor's degree in Information Technology, Computer Science, or related discipline.
  • 8+ years of experience administering Active Directory environments.
  • 5+ years of experience supporting Microsoft Entra ID (Azure AD) and Azure AD Connect.
  • Strong hands-on experience with:
  • Active Directory (On-Premises)
  • Microsoft Entra ID (Azure AD)
  • Azure AD Connect
  • DNS Administration
  • Cloudflare DNS
  • Group Policy (GPO)
  • Identity & Access Management (IAM)
  • Certificate Services / PKI
  • Experience supporting hybrid identity environments.
  • Strong troubleshooting skills across authentication, synchronization, and access management issues.
  • Experience with incident management, problem management, and root cause analysis.
  • Excellent client-facing communication skills., * Experience with Quest RMAD.
  • Experience with Quest Change Auditor.
  • Experience managing Sectigo certificates.
  • Knowledge of DFS (Distributed File Services).
  • Experience in pharmaceutical, healthcare, or regulated industries.
  • Familiarity with GxP compliance requirements.

Benefits & conditions

  • Microsoft certifications related to Entra ID, Identity Management, Azure, or Windows Server Administration.

Benefits: Cognizant offers the following benefits for this position, subject to applicable eligibility requirements:

  • Medical/Dental/Vision/Life Insurance
  • Paid holidays plus Paid Time Off
  • 401(k) plan and contributions
  • Long-term/Short-term Disability
  • Paid Parental Leave
  • Employee Stock Purchase Plan

Work model:

At Cognizant, we strive to provide flexibility wherever possible, and we are here to support a healthy work-life balance though our various wellbeing programs. Based on this role's business requirements, this is an onsite role requiring 5 days a week at client site in Sleepy Hollow, New York, USA.

The working arrangements for this role are accurate as of the date of posting. This may change based on the project you're engaged in, as well as business and client requirements. Rest assured; we will always be clear about role expectations.

Apply for this position