IAM Expert – Active Directory (AD)
About the role
IAM Expert - Active Directory (AD)
Role Overview
The IAM Expert - Active Directory (AD) is responsible for providing advanced expertise in Microsoft Active Directory services, supporting identity and access management initiatives, and ensuring the secure and efficient operation of AD infrastructure.
The role focuses on supporting the Canada site through the implementation, management, and governance of Active Directory trust relationships and GreenZone Active Directory creation activities.
The position requires strong technical knowledge of enterprise Active Directory environments, cross-domain trusts, security best practices, and collaboration with infrastructure, security, and application teams.
Key Responsibilities
- Lead and support Active Directory (AD) design, implementation, and operational activities.
- Manage and maintain AD trust relationships between domains and forests.
- Support GreenZone Active Directory creation, configuration, and deployment activities.
- Ensure compliance with IAM standards, security policies, and governance requirements.
- Perform AD health checks, troubleshooting, performance tuning, and root cause analysis.
- Review and implement security hardening measures for Active Directory environments.
- Support identity lifecycle management and access control processes.
- Collaborate with infrastructure, cybersecurity, and application teams during migration and integration projects.
- Develop and maintain technical documentation, operational procedures, and architecture diagrams.
- Participate in change management, risk assessment, and audit activities related to Active Directory.
- Provide Level 3 support for complex AD-related incidents and service requests.
- Monitor AD services and proactively address potential issues impacting availability or security.
- Support disaster recovery and business continuity planning for Active Directory services.
- Contribute to continuous improvement initiatives and modernization of IAM and directory services.
Required Skills & Experience
Technical Skills
- 5+ years of strong expertise in Microsoft Active Directory Domain Services (AD DS).
- Experience with Active Directory Forest and Domain Trusts .
- Knowledge of: Active Directory Sites and Services
- DNS
- Group Policy (GPO)
- AD replication mechanisms
Experience creating and managing secure AD environments, including GreenZone or segregated security environments .
Strong understanding of Identity and Access Management (IAM) principles.
Experience with PowerShell scripting and automation of AD administration tasks.
Understanding of authentication and authorization protocols:
- Kerberos
- LDAP/LDAPS
- NTLM
- SAML
- OAuth/OpenID Connect - preferred
Experience with Microsoft Entra ID (Azure AD) integration is an advantage.
Knowledge of security best practices for privileged access management and directory security.
Familiarity with Active Directory migration, consolidation, and transformation projects.
Experience with operational support and continuous improvement of directory services.
Qualifications
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity , or a related field, or equivalent professional experience.
- Relevant Microsoft certifications are preferred, including: Microsoft Certified: Identity and Access Administrator Associate
- Windows Server Administration certifications
- Security or IAM-related certifications
This engagement is managed end-to-end by Querentia. Our recruiters give you honest feedback at every stage, prepare you for the interview, and support a smooth onboarding once you land the offer.
