We are seeking an experienced L2 Active Directory Specialist to join our IT Infrastructure and Security team. The ideal candidate will have expertise in managing and securing Active Directory (AD) environments, ADFS, ADCS, Proxy solutions, Endpoint Security, and ensuring compliance with AD security best practices.
Key Responsibilities
Active Directory Management :
Maintain and manage AD infrastructure, including domain controllers, group policies, and replication.
Perform advanced troubleshooting for AD-related issues (L2-L3 level).
Conduct AD migrations, upgrades, and integrations with other systems.
ADFS (Active Directory Federation Services) :
Deploy, manage, and troubleshoot ADFS configurations for secure access management.
Ensure the reliability and security of federation services.
ADCS (Active Directory Certificate Services) :
Implement and manage public key infrastructure (PKI) using ADCS.
Troubleshoot and maintain certificates for users, devices, and applications.
Proxy Management :
Manage and support proxy solutions to control and monitor web traffic.
Optimize proxy configurations for performance and security.
Endpoint Security :
Administer and monitor endpoint security tools to protect organizational assets.
Ensure compliance with endpoint protection policies and address vulnerabilities.
Compliance and Security :
Implement and enforce security measures in line with Active Directory compliance standards.
Perform regular audits, hardening, and security assessments of AD and related infrastructure.
Develop and maintain AD-related security documentation, including incident response plans.
Collaboration and Support :
Work closely with other IT and Security teams to integrate AD with other technologies.
Provide L2-L3 technical support and mentor junior team members.
Microsoft 365 Administration :
Manage and administer Microsoft Office 365, including Exchange Online, Teams, and OneDrive.
Configure and optimize Cloud Exchange environments.
Ensure smooth integration and operational efficiency of Microsoft 365 services.
Mobile Device and Application Management (MDM & MAM) :
Deploy and manage Microsoft Intune for device and application management.
Define and implement Microsoft Mobile Application Management (MAM) policies to secure corporate data on BYOD devices.
Troubleshoot and optimize mobile device compliance and security configurations.
Microsoft Defender Policies :
Configure and manage Microsoft Defender for endpoint protection.
Monitor and respond to security alerts and incidents using Microsoft Defender and related tools.
Azure Active Directory (AAD) :
Manage Azure AD, including user identities, roles, and access controls.
Configure and enforce conditional access policies to enhance security.
Ensure compliance with Azure AD security standards and best practices.
Security Enhancements in Intune and MFA :
Design and implement security measures for devices and applications through Intune.
Enhance multi-factor authentication (MFA) configurations for secure access.
Regularly review and update Intune policies to align with emerging security threats.
Risk Score Management and Compliance :
Monitor and manage Microsoft Secure Score to continuously enhance security posture.
Identify and mitigate risks across Microsoft 365 and Azure environments.
Conduct security audits and provide recommendations for compliance improvements.
Specialist in Security Enhancements :
Proactively identify vulnerabilities and implement preventive measures across Microsoft ecosystems.
Design and enforce enterprise-level security frameworks for Microsoft workloads.
Document and maintain security processes, including incident response plans.
Required Skills and Qualifications
Technical Expertise :
Advanced knowledge of Active Directory and AAD (multi-forest and multi-domain environments).
Hands-on experience with ADFS, ADCS, and PKI solutions.
Strong understanding of proxy technologies
Proficiency in endpoint security tools.
Security and Compliance :
Familiarity with frameworks like NIST, ISO 27001, or CIS benchmarks for AD security.
Experience implementing AD hardening measures.
Tools and Scripting (Dev Sec Ops) :
Knowledge of PowerShell scripting for AD management and automation.
Familiarity with monitoring tools for AD health and security.