> Markdown version of [/jobs/ext/737208-l2-engineer-for-on-premises-and-azure-active-directory](https://www.wearedevelopers.com/jobs/ext/737208-l2-engineer-for-on-premises-and-azure-active-directory). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # L2 Engineer for On-Premises and Azure Active Directory - **Company:** Stanley David and Associates - **Location:** Clinton, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Active Directory, Software System Penetration Testing, Microsoft Azure, CompTIA Security+, Disaster Recovery, Integrated Windows Authentication, Domain Name System (DNS), Multi-Factor Authentication, Identity and Access Management, Kerberos (Protocol), Lightweight Directory Access Protocols (LDAP), Networking Basics, OAuth, Windows PowerShell, Openid Connect, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Single Sign-On, Data Logging, Enterprise Software Applications, HybridCloud, Infrastructure as Code (IaC), Bicep, Terraform, User Administration - **Published:** June 29, 2026 - **Apply:** https://www.dice.com/job-detail/79f0c716-a429-4edf-89c6-23065e3b36da ## About the Role Expert-level knowledge of Microsoft Active Directory (2008 R2, 2012 R2, 2016, 2019). In-depth experience with Azure Active Directory and hybrid identity management. Strong understanding of LDAP, Kerberos, DNS, and networking fundamentals. Proficiency in PowerShell and experience with automation tools. Familiarity with security tools like Azure Sentinel, Defender for Identity, or equivalent. Certifications (Preferred): Microsoft Certified: Identity and Access Administrator Associate. Microsoft Certified: Azure Solutions Architect Expert. CompTIA Security+ or CISSP (for security-focused roles). Soft Skills: Analytical thinking with excellent problem-solving abilities. Ability to work independently and in cross-functional teams. Effective communication skills for technical and non-technical stakeholders. Additional Responsibilities (Optional): Participate in disaster recovery and business continuity planning. Assist in planning Zero Trust Architecture strategies. Contribute to Identity Governance and Administration (IGA) initiatives. This role typically requires 5+ years of experience in identity management or related IT fields. The job may also involve being part of an on-call rotation for critical incident support. ## Description The L2 Engineer for On-Premises and Azure Active Directory is responsible for maintaining the stability, performance, and security of enterprise directory services. This includes troubleshooting complex issues, implementing enhancements, and supporting seamless integration between on-prem AD and Azure AD. The role also requires proactive involvement in security hardening, lifecycle management, automation, and supporting a hybrid cloud infrastructure. Key Responsibilities: 1. Active Directory (On-Premises): Design and Maintenance: Architect and manage multi-domain, multi-forest Active Directory environments. Perform schema extensions and manage= replication across sites. Plan and execute AD migrations, upgrades, and domain consolidations. Configuration and Optimization: Configure and optimize Group Policy Objects (GPOs) for user and device management. Manage trusts, sites, and services to ensure optimal directory performance. Security: Implement security measures such as access controls, auditing, and logging. Regularly perform AD security assessments using tools like ADAudit+, PingCastle, or BloodHound. Address vulnerabilities identified through audits and penetration tests. Troubleshooting: Diagnose and resolve advanced AD issues related to authentication, replication, and performance. Support complex Kerberos and NTLM authentication scenarios. 2. Azure Active Directory (AAD): Integration and Management: Deploy and configure Azure AD Connect for hybrid identity scenarios. Ensure seamless synchronization of on-prem AD with Azure AD, managing attributes and custom rules. Implement conditional access policies, Multi-Factor Authentication (MFA), and Privileged Identity Management (PIM). Applications and SSO: Integrate enterprise applications with Azure AD for Single Sign-On (SSO). Manage OAuth, OpenID Connect, and SAML integrations for third-party services. Identity Protection: Configure Azure AD Identity Protection to monitor suspicious activity. Investigate alerts and take corrective actions for compromised accounts. 3. Automation & Scripting: Develop PowerShell scripts for bulk user management, auditing, and system automation. Create and maintain Infrastructure as Code (IaC) templates for Azure AD resources using ARM, Terraform, or Bicep. 4. Monitoring & Reporting: Use monitoring tools like Azure Monitor, Sentinel, or on-prem solutions to track system health and generate compliance reports. Implement alerting mechanisms for unauthorized access attempts, account lockouts, or replication failures. 5. Collaboration & Documentation: Work closely with other IT teams, including network, cloud, and security, to support initiatives. Maintain detailed documentation for all configurations, processes, and troubleshooting guides. ## Related Videos - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)