Identity & Access Management Subject Matter Expert
Job Description
Job DescriptionWe are looking for an experienced Identity & Access Management specialist to support and enhance enterprise directory services. This long-term contract position focuses on strengthening Active Directory architecture, improving secure access across on-premises and cloud environments, and advancing reliable identity operations at scale. The role is well suited for someone who combines deep technical expertise in Active Directory with strong automation, documentation, and operational support capabilities.
Responsibilities:
• Architect, administer, and secure Active Directory environments, including forests, domains, trusts, organizational units, group policy, and domain controllers.
• Collaborate with security and infrastructure teams to establish privileged access approaches, delegated administration models, and administrative group structures.
• Investigate and resolve directory service issues related to authentication, replication, service dependencies, domain controller performance, and account status.
• Build and support connections between Active Directory and identity governance, access request, authentication, and certification solutions.
• Create and maintain technical standards, operational procedures, and support documentation for directory services and domain controller management.
• Contribute to change control activities, security incident response, audit support, and ongoing service improvement efforts aligned with enterprise security goals.
• Develop authentication integration patterns for applications and platforms connecting to Active Directory, including Kerberos-based approaches where appropriate.
• Promote modern engineering practices by implementing automation, infrastructure as code, and repeatable deployment methods using tools such as Ansible, Terraform, or Chef.
• Extend directory service capabilities into AWS and broader cloud environments while maintaining security, resiliency, and compliance standards.• Extensive hands-on experience managing Microsoft Active Directory in large and complex enterprise environments.
• Strong knowledge of directory security concepts, delegated administration, privileged access controls, and group management practices.
• Background supporting Active Directory within a broader identity and access management ecosystem.
• Demonstrated ability to diagnose and resolve issues involving authentication, replication, account lifecycle management, and access controls.
• Experience working with AWS-based Active Directory deployment models, including managed or self-hosted implementations.
• Familiarity integrating Active Directory with identity governance, privileged access management, or related security platforms.
• Experience supporting multi-domain, multi-region, or globally distributed directory environments.
• Practical expertise with automation, infrastructure-as-code, and software engineering practices for operational efficiency and consistency.
