Active Directory Architecture & Design

InfosysTimisoara, County TimisSenior
Active

Job description

Active Directory Architecture & Design

Active Directory Architecture & DesignActive Directory Architecture & DesignActive Directory Architecture & DesignActive Directory Architecture & DesignActive Directory Architecture & DesignActive Directory Architecture & Design
  • Design and manage enterprise AD forests, domains, trusts, OU structures, site topology, Tiering Model in AD and Disaster Recovery Plan
Design and manage enterprise AD forests, domains, trusts, OU structures, site topology, Tiering Model in AD and Disaster Recovery PlanDesign and manage enterprise AD forests, domains, trusts, OU structures, site topology, Tiering Model in AD and Disaster Recovery PlanDesign and manage enterprise AD forests, domains, trusts, OU structures, site topology, Tiering Model in AD and Disaster Recovery PlanDesign and manage enterprise AD forests, domains, trusts, OU structures, site topology, Tiering Model in AD and Disaster Recovery PlanDesign and manage enterprise AD forests, domains, trusts, OU structures, site topology, Tiering Model in AD and Disaster Recovery PlanDesign and manage enterprise AD forests, domains, trusts, OU structures, site topology, Tiering Model in AD and Disaster Recovery Plan
  • Define and enforce AD naming conventions, delegation models, and role separation aligned with Tiering Model

Define and enforce AD naming conventions, delegation models, and role separation aligned with Tiering Model

Define and enforce AD naming conventions, delegation models, and role separation aligned with Tiering ModelDefine and enforce AD naming conventions, delegation models, and role separation aligned with Tiering ModelDefine and enforce AD naming conventions, delegation models, and role separation aligned with Tiering ModelDefine and enforce AD naming conventions, delegation models, and role separation aligned with Tiering ModelDefine and enforce AD naming conventions, delegation models, and role separation aligned with Tiering ModelDefine and enforce AD naming conventions, delegation models, and role separation aligned with Tiering Model
  • Architect high availability and disaster recovery for domain controllers and critical AD services

Architect high availability and disaster recovery for domain controllers and critical AD services

Architect high availability and disaster recovery for domain controllers and critical AD servicesArchitect high availability and disaster recovery for domain controllers and critical AD servicesArchitect high availability and disaster recovery for domain controllers and critical AD servicesArchitect high availability and disaster recovery for domain controllers and critical AD servicesArchitect high availability and disaster recovery for domain controllers and critical AD servicesArchitect high availability and disaster recovery for domain controllers and critical AD services
  • Design Group Policy (GPO) strategy aligned to security and operational best practices

Design Group Policy (GPO) strategy aligned to security and operational best practices

Design Group Policy (GPO) strategy aligned to security and operational best practicesDesign Group Policy (GPO) strategy aligned to security and operational best practicesDesign Group Policy (GPO) strategy aligned to security and operational best practicesDesign Group Policy (GPO) strategy aligned to security and operational best practicesDesign Group Policy (GPO) strategy aligned to security and operational best practicesDesign Group Policy (GPO) strategy aligned to security and operational best practices
  • Lead domain controller lifecycle management, patching, and capacity planning

Lead domain controller lifecycle management, patching, and capacity planning

Lead domain controller lifecycle management, patching, and capacity planningLead domain controller lifecycle management, patching, and capacity planningLead domain controller lifecycle management, patching, and capacity planningLead domain controller lifecycle management, patching, and capacity planningLead domain controller lifecycle management, patching, and capacity planningLead domain controller lifecycle management, patching, and capacity planning
  • Oversee DNS, SYSVOL, replication health, and AD performance tuning

Oversee DNS, SYSVOL, replication health, and AD performance tuning

Oversee DNS, SYSVOL, replication health, and AD performance tuningOversee DNS, SYSVOL, replication health, and AD performance tuningOversee DNS, SYSVOL, replication health, and AD performance tuningOversee DNS, SYSVOL, replication health, and AD performance tuningOversee DNS, SYSVOL, replication health, and AD performance tuningOversee DNS, SYSVOL, replication health, and AD performance tuning
  • Troubleshoot complex AD issues across multi‑domain and multi‑forest environments

Troubleshoot complex AD issues across multi‑domain and multi‑forest environments

Troubleshoot complex AD issues across multi‑domain and multi‑forest environmentsTroubleshoot complex AD issues across multi‑domain and multi‑forest environmentsTroubleshoot complex AD issues across multi‑domain and multi‑forest environmentsTroubleshoot complex AD issues across multi‑domain and multi‑forest environmentsTroubleshoot complex AD issues across multi‑domain and multi‑forest environmentsTroubleshoot complex AD issues across multi‑domain and multi‑forest environments
  • Establish monitoring, alerting, and operational runbooks

Establish monitoring, alerting, and operational runbooks

Establish monitoring, alerting, and operational runbooksEstablish monitoring, alerting, and operational runbooksEstablish monitoring, alerting, and operational runbooksEstablish monitoring, alerting, and operational runbooksEstablish monitoring, alerting, and operational runbooksEstablish monitoring, alerting, and operational runbooks
  • Identify and remediate: Stale / inactive users and computer objectsOrphaned and over‑privileged accountsLegacy and unmanaged service accounts

Identify and remediate:

Identify and remediate:Identify and remediate:Identify and remediate:Identify and remediate:Identify and remediate:Identify and remediate:
  • Stale / inactive users and computer objects

Stale / inactive users and computer objects

Stale / inactive users and computer objectsStale / inactive users and computer objectsStale / inactive users and computer objectsStale / inactive users and computer objectsStale / inactive users and computer objectsStale / inactive users and computer objects
  • Orphaned and over‑privileged accounts

Orphaned and over‑privileged accounts

Orphaned and over‑privileged accountsOrphaned and over‑privileged accountsOrphaned and over‑privileged accountsOrphaned and over‑privileged accountsOrphaned and over‑privileged accountsOrphaned and over‑privileged accounts
  • Legacy and unmanaged service accounts

Legacy and unmanaged service accounts

Legacy and unmanaged service accountsLegacy and unmanaged service accountsLegacy and unmanaged service accountsLegacy and unmanaged service accountsLegacy and unmanaged service accountsLegacy and unmanaged service accounts
  • Define and enforce account lifecycle and access review processes

Define and enforce account lifecycle and access review processes

Define and enforce account lifecycle and access review processesDefine and enforce account lifecycle and access review processesDefine and enforce account lifecycle and access review processesDefine and enforce account lifecycle and access review processesDefine and enforce account lifecycle and access review processesDefine and enforce account lifecycle and access review processes
  • Support service account migration, standardization, and credential hygiene

Support service account migration, standardization, and credential hygiene

Support service account migration, standardization, and credential hygieneSupport service account migration, standardization, and credential hygieneSupport service account migration, standardization, and credential hygieneSupport service account migration, standardization, and credential hygieneSupport service account migration, standardization, and credential hygieneSupport service account migration, standardization, and credential hygiene
  • Perform AD security posture assessments and remediation planning

Perform AD security posture assessments and remediation planning

Perform AD security posture assessments and remediation planningPerform AD security posture assessments and remediation planningPerform AD security posture assessments and remediation planningPerform AD security posture assessments and remediation planningPerform AD security posture assessments and remediation planningPerform AD security posture assessments and remediation planning
  • Implement tiered administration, least privilege, and role‑based access controls

Implement tiered administration, least privilege, and role‑based access controls

Implement tiered administration, least privilege, and role‑based access controlsImplement tiered administration, least privilege, and role‑based access controlsImplement tiered administration, least privilege, and role‑based access controlsImplement tiered administration, least privilege, and role‑based access controlsImplement tiered administration, least privilege, and role‑based access controlsImplement tiered administration, least privilege, and role‑based access controls
  • Harden AD against common attack vectors (Kerberos abuse, credential theft, lateral movement)

Harden AD against common attack vectors (Kerberos abuse, credential theft, lateral movement)

Harden AD against common attack vectors (Kerberos abuse, credential theft, lateral movement)Harden AD against common attack vectors (Kerberos abuse, credential theft, lateral movement)Harden AD against common attack vectors (Kerberos abuse, credential theft, lateral movement)Harden AD against common attack vectors (Kerberos abuse, credential theft, lateral movement)Harden AD against common attack vectors (Kerberos abuse, credential theft, lateral movement)Harden AD against common attack vectors (Kerberos abuse, credential theft, lateral movement)
  • Support privileged access design and secure admin workstation models

Support privileged access design and secure admin workstation models

Support privileged access design and secure admin workstation modelsSupport privileged access design and secure admin workstation modelsSupport privileged access design and secure admin workstation modelsSupport privileged access design and secure admin workstation modelsSupport privileged access design and secure admin workstation modelsSupport privileged access design and secure admin workstation models
  • Define AD governance framework, policies, and technical standards

Define AD governance framework, policies, and technical standards

Define AD governance framework, policies, and technical standardsDefine AD governance framework, policies, and technical standardsDefine AD governance framework, policies, and technical standardsDefine AD governance framework, policies, and technical standardsDefine AD governance framework, policies, and technical standardsDefine AD governance framework, policies, and technical standards
  • Review and approve changes impacting AD architecture and security

Review and approve changes impacting AD architecture and security

Review and approve changes impacting AD architecture and securityReview and approve changes impacting AD architecture and securityReview and approve changes impacting AD architecture and securityReview and approve changes impacting AD architecture and securityReview and approve changes impacting AD architecture and securityReview and approve changes impacting AD architecture and security
  • Ensure compliance with internal controls, audits, and regulatory requirements

Ensure compliance with internal controls, audits, and regulatory requirements

Ensure compliance with internal controls, audits, and regulatory requirementsEnsure compliance with internal controls, audits, and regulatory requirementsEnsure compliance with internal controls, audits, and regulatory requirementsEnsure compliance with internal controls, audits, and regulatory requirementsEnsure compliance with internal controls, audits, and regulatory requirementsEnsure compliance with internal controls, audits, and regulatory requirements
  • Maintain architecture diagrams, design documents, and SOPs

Maintain architecture diagrams, design documents, and SOPs

Maintain architecture diagrams, design documents, and SOPsMaintain architecture diagrams, design documents, and SOPsMaintain architecture diagrams, design documents, and SOPsMaintain architecture diagrams, design documents, and SOPsMaintain architecture diagrams, design documents, and SOPsMaintain architecture diagrams, design documents, and SOPs
  • Support domain consolidation, forest restructuring, and trust rationalization

Support domain consolidation, forest restructuring, and trust rationalization

Support domain consolidation, forest restructuring, and trust rationalizationSupport domain consolidation, forest restructuring, and trust rationalizationSupport domain consolidation, forest restructuring, and trust rationalizationSupport domain consolidation, forest restructuring, and trust rationalizationSupport domain consolidation, forest restructuring, and trust rationalizationSupport domain consolidation, forest restructuring, and trust rationalization
  • Provide technical design inputs for hybrid identity and directory modernization

Provide technical design inputs for hybrid identity and directory modernization

Provide technical design inputs for hybrid identity and directory modernizationProvide technical design inputs for hybrid identity and directory modernizationProvide technical design inputs for hybrid identity and directory modernizationProvide technical design inputs for hybrid identity and directory modernizationProvide technical design inputs for hybrid identity and directory modernizationProvide technical design inputs for hybrid identity and directory modernization
  • Assess AD readiness for integration with cloud identity platforms

Assess AD readiness for integration with cloud identity platforms

Assess AD readiness for integration with cloud identity platformsAssess AD readiness for integration with cloud identity platformsAssess AD readiness for integration with cloud identity platformsAssess AD readiness for integration with cloud identity platformsAssess AD readiness for integration with cloud identity platformsAssess AD readiness for integration with cloud identity platforms
  • Validate designs and deliverables from system integrators or partner teams

Validate designs and deliverables from system integrators or partner teams

Validate designs and deliverables from system integrators or partner teamsValidate designs and deliverables from system integrators or partner teamsValidate designs and deliverables from system integrators or partner teamsValidate designs and deliverables from system integrators or partner teamsValidate designs and deliverables from system integrators or partner teamsValidate designs and deliverables from system integrators or partner teams
  • Act as L4 escalation point for AD‑related issues and Mentor AD engineers and operations teams

Act as L4 escalation point for AD‑related issues and Mentor AD engineers and operations teams

Act as L4 escalation point for AD‑related issues and Mentor AD engineers and operations teamsAct as L4 escalation point for AD‑related issues and Mentor AD engineers and operations teamsAct as L4 escalation point for AD‑related issues and Mentor AD engineers and operations teamsAct as L4 escalation point for AD‑related issues and Mentor AD engineers and operations teamsAct as L4 escalation point for AD‑related issues and Mentor AD engineers and operations teamsAct as L4 escalation point for AD‑related issues and Mentor AD engineers and operations teams
  • Collaborate with security, infrastructure, and application teams

Collaborate with security, infrastructure, and application teams

Collaborate with security, infrastructure, and application teamsCollaborate with security, infrastructure, and application teamsCollaborate with security, infrastructure, and application teamsCollaborate with security, infrastructure, and application teamsCollaborate with security, infrastructure, and application teamsCollaborate with security, infrastructure, and application teams
  • Present technical findings and recommendations to senior stakeholders

Present technical findings and recommendations to senior stakeholders

Present technical findings and recommendations to senior stakeholdersPresent technical findings and recommendations to senior stakeholdersPresent technical findings and recommendations to senior stakeholdersPresent technical findings and recommendations to senior stakeholdersPresent technical findings and recommendations to senior stakeholdersPresent technical findings and recommendations to senior stakeholders

Required Skills & Experience

Required Skills & ExperienceRequired Skills & ExperienceRequired Skills & ExperienceRequired Skills & ExperienceRequired Skills & ExperienceRequired Skills & Experience
  • 8–12+ years of experience managing large‑scale on‑prem Active Directory

8–12+ years of experience managing large‑scale on‑prem Active Directory

8–12+ years of experience managing large‑scale on‑prem Active Directory8–12+ years of experience managing large‑scale on‑prem Active Directory8–12+ years of experience managing large‑scale on‑prem Active Directory8–12+ years of experience managing large‑scale on‑prem Active Directory8–12+ years of experience managing large‑scale on‑prem Active Directory8–12+ years of experience managing large‑scale on‑prem Active Directory
  • Deep expertise in: AD DS, DNS, Group Policy, Sites & Services, ReplicationMulti‑domain and multi‑forest environments

Deep expertise in:

Deep expertise in:Deep expertise in:Deep expertise in:Deep expertise in:Deep expertise in:Deep expertise in:
  • AD DS, DNS, Group Policy, Sites & Services, Replication

AD DS, DNS, Group Policy, Sites & Services, Replication

AD DS, DNS, Group Policy, Sites & Services, ReplicationAD DS, DNS, Group Policy, Sites & Services, ReplicationAD DS, DNS, Group Policy, Sites & Services, ReplicationAD DS, DNS, Group Policy, Sites & Services, ReplicationAD DS, DNS, Group Policy, Sites & Services, ReplicationAD DS, DNS, Group Policy, Sites & Services, Replication
  • Multi‑domain and multi‑forest environments

Multi‑domain and multi‑forest environments

Multi‑domain and multi‑forest environmentsMulti‑domain and multi‑forest environmentsMulti‑domain and multi‑forest environmentsMulti‑domain and multi‑forest environmentsMulti‑domain and multi‑forest environmentsMulti‑domain and multi‑forest environments
  • Strong PowerShell scripting for automation and reporting

Strong PowerShell scripting for automation and reporting

Strong PowerShell scripting for automation and reportingStrong PowerShell scripting for automation and reportingStrong PowerShell scripting for automation and reportingStrong PowerShell scripting for automation and reportingStrong PowerShell scripting for automation and reportingStrong PowerShell scripting for automation and reporting
  • Solid understanding of AD security architecture and threat models

Solid understanding of AD security architecture and threat models

Solid understanding of AD security architecture and threat modelsSolid understanding of AD security architecture and threat modelsSolid understanding of AD security architecture and threat modelsSolid understanding of AD security architecture and threat modelsSolid understanding of AD security architecture and threat modelsSolid understanding of AD security architecture and threat models
  • Proven experience delivering assessments, remediation plans, and architectural designs

Proven experience delivering assessments, remediation plans, and architectural designs

Proven experience delivering assessments, remediation plans, and architectural designsProven experience delivering assessments, remediation plans, and architectural designsProven experience delivering assessments, remediation plans, and architectural designsProven experience delivering assessments, remediation plans, and architectural designsProven experience delivering assessments, remediation plans, and architectural designsProven experience delivering assessments, remediation plans, and architectural designs

About Infosys Infosys is a global leader in next-generation digital services and consulting. We enable clients in 59 countries to navigate their digital transformation.With over four decades of experience in managing the systems and workings of global enterprises, we expertly steer clients, in 59 countries, as they navigate their digital transformation powered by cloud and AI. We enable them with an AI-first core, empower the business with agile digital at scale and drive continuous improvement with always-on learning through the transfer of digital skills, expertise, and ideas from our innovation ecosystem. We are deeply committed to being a well-governed, environmentally sustainable organization where diverse talent thrives in an inclusive workplace.

About Infosys Infosys is a global leader in next-generation digital services and consulting. We enable clients in 59 countries to navigate their digital transformation.With over four decades of experience in managing the systems and workings of global enterprises, we expertly steer clients, in 59 countries, as they navigate their digital transformation powered by cloud and AI. We enable them with an AI-first core, empower the business with agile digital at scale and drive continuous improvement with always-on learning through the transfer of digital skills, expertise, and ideas from our innovation ecosystem. We are deeply committed to being a well-governed, environmentally sustainable organization where diverse talent thrives in an inclusive workplace.About Infosys Infosys is a global leader in next-generation digital services and consulting. We enable clients in 59 countries to navigate their digital transformation.With over four decades of experience in managing the systems and workings of global enterprises, we expertly steer clients, in 59 countries, as they navigate their digital transformation powered by cloud and AI. We enable them with an AI-first core, empower the business with agile digital at scale and drive continuous improvement with always-on learning through the transfer of digital skills, expertise, and ideas from our innovation ecosystem. We are deeply committed to being a well-governed, environmentally sustainable organization where diverse talent thrives in an inclusive workplace.About Infosys Infosys is a global leader in next-generation digital services and consulting. We enable clients in 59 countries to navigate their digital transformation.With over four decades of experience in managing the systems and workings of global enterprises, we expertly steer clients, in 59 countries, as they navigate their digital transformation powered by cloud and AI. We enable them with an AI-first core, empower the business with agile digital at scale and drive continuous improvement with always-on learning through the transfer of digital skills, expertise, and ideas from our innovation ecosystem. We are deeply committed to being a well-governed, environmentally sustainable organization where diverse talent thrives in an inclusive workplace.About InfosysAbout InfosysInfosys is a global leader in next-generation digital services and consulting. We enable clients in 59 countries to navigate their digital transformation.With over four decades of experience in managing the systems and workings of global enterprises, we expertly steer clients, in 59 countries, as they navigate their digital transformation powered by cloud and AI. We enable them with an AI-first core, empower the business with agile digital at scale and drive continuous improvement with always-on learning through the transfer of digital skills, expertise, and ideas from our innovation ecosystem. We are deeply committed to being a well-governed, environmentally sustainable organization where diverse talent thrives in an inclusive workplace.