Senior Active Directory Engineer

  • 临时
  • 伦敦
  • 可协商英镑/年

Senior Active Directory Engineer

Our client, a leading global supplier for IT services, requires Senior Active Directory Engineer to be based at their client’s office in London, UK.

这是个混合型职位——您可在英国远程办公,每周到伦敦办公室工作4天。

This is a 6+ month temporary contract to start asa

日费率:具有市场竞争力的费率

Our client is seeking a strong Active Directory Specialist with hands‑on technical experience and architectural insight, capable of assessing, designing, and remediating complex AD environments

主要职责

  • Review existing AD tiering policies and progress completed to date in collaboration with customer’s stakeholders
  • Finalise inventory and scope of remaining tiering-related activities
  • Validate business and application ownership and confirm alignment with the AD tiering model
  • Assess cross-tier system dependencies and associated risks
  • Review and remediate service accounts and scheduled tasks
  • Finalise technical configurations, deployment activities, risks, and mitigation plans
  • Implement changes to server objects, Active Directory groups, and user configurations
  • Validate functionality and access post-change”

关键要求

核心技能:

Deep hands‑on experience with Microsoft Active Directory

  • Strong understanding of AD architecture, including forests, domains, trusts, sites, and replication
  • Practical experience managing large, complex, enterprise AD environments
  • Ability to operate confidently at both design and implementation levels

Active Directory architecture and design expertise

  • Experience reviewing and defining AD target‑state architectures
  • Clear understanding of how AD design decisions impact security, operations, and scalability
  • Strong knowledge of identity, authentication, and authorization flows

AD Tiering and security model expertise

  • Proven understanding of AD Tiering concepts (Tier 0, Tier 1, Tier 2)
  • Ability to assess environments for tiering misalignment and security risk
  • Experience designing and implementing tier‑aware access models, including:
    • Privileged access segregation
    • Admin role separation
    • Secure administrative workstations (SAWs) or equivalent concepts

Organisational Unit (OU) structure design and analysis

  • Experience designing, rationalising, and refactoring OU structures
  • Strong understanding of OU‑based:
    • Delegation models
    • Group Policy inheritance
    • Administrative boundaries
  • Ability to assess the operational and security impact of OU changes

Roles, delegation, and administrative model understanding

  • Strong knowledge of AD roles, permissions, and delegated administration
  • Ability to analyse existing role assignments, identify excessive privilege, and recommend remediation
  • Experience assessing and mitigating risks associated with:
    • Domain Admin usage
    • Delegated OU permissions
    • Service accounts and scheduled tasks

Gap analysis & assessment capability

  • Ability to conduct structured gap analysis between:
  • Current‑state environment
  • Target‑state architecture and security standards
  • Comfortable reviewing and analysing: Existing configurations, Operational practices &Security controls and exceptions
  • Capable of producing clear findings, risks, and recommendations

理想技能:

  • Translate technical findings into clear recommendations for both technical and non‑technical stakeholders
  • Exposure to identity governance tools or controlled AD administration solutions (e.g. Active Roles, PAM/PIM tools)
  • Understand the business and application impact of AD changes
  • Work collaboratively with security, infrastructure, and application teams
  • Produce implementation‑ready designs, runbooks, and remediation plans
  • Strong Communication skills to articulate and understand customer requirements
  • Understanding of Azure Entra for the On-prem to Cloud AD object synchronisation
  • Handon experience working with Collaborative tools Like Jira, Kanban , Azure Dev for updating the tasks
  • Knowledge of ITSM process and tool BMC remedy for logging and updating changes

Special Working Conditions:

  • Night shift depending on the change scheduled

由于申请数量庞大,我们很遗憾无法逐一回复每位申请人。

若您在提交申请后7天内未收到我们的回复,请理解本次申请未能成功。

请随时关注我们的网站https://projectrecruit.com/jobs/,了解未来发布的职位信息

上传您的简历或其他相关文件。最大文件大小:50 MB。

全球项目
隐私概述

本网站使用 Cookie,以便为您提供最佳的用户体验。Cookie 信息存储在您的浏览器中,其功能包括在您再次访问我们的网站时识别您的身份,以及帮助我们的团队了解您对网站的哪些部分最感兴趣和最有用。