Lead Active Directory Engineer

N-iX

Medellín

Híbrido

COP 120.000.000 - 200.000.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Ventajas ofrecidas por este puesto de trabajo

Flexible working format
Competitive salary and compensation
Education reimbursement
Professional development tools

Descripción de la vacante

N-iX is seeking a Lead Active Directory Engineer in Medellín to assess, clean up, and harden multiple inherited AD environments for a European online car market. You will design GPOs, OU structures, and RBAC models while integrating AD with IAM platforms and ensuring PCI DSS alignment.

The role requires hands-on expertise, SSO and identity lifecycle knowledge, and strong PowerShell skills to automate remediation and reporting. Flexible hybrid/remote work options are offered.

Formación

  • 7+ years of hands-on AD engineering and administration.
  • Experience in AD clean-up, consolidation, or post-transition work.
  • AD architecture for single-domain environments at scale.
  • Security hardening using tiered admin models and least privilege.
  • Experience with integrating AD with IAM/IdP platforms (Azure AD / Entra ID, Okta).
  • Familiar with PCI DSS or similar audit frameworks.
  • Strong knowledge of Kerberos, NTLM, SAML/OIDC basics, DNS, and replication.
  • Proficient in PowerShell for bulk changes and reporting.

Responsabilidades

  • Perform comprehensive assessment of current AD environments.
  • Identify and remediate inactive/stale objects and legacy permissions.
  • Redesign OU structure and delegation model; implement GP strategy.
  • Implement security hardening and privileged access controls.
  • Integrate AD with IAM platforms, including SSO and identity lifecycle processes.
  • Review and optimize AD Sites, DNS configuration, and replication topology.
  • Develop cleanup/remediation plans with minimal disruption; automate tasks and reporting with PowerShell.
  • Produce audit-ready documentation and operational standards.

Conocimientos

AD engineering
GPO design
OU design
AD security
PowerShell
Azure AD / Entra ID
SSO / IdP
RBAC
Identity lifecycle
Kerberos / NTLM
DNS / AD sites

Herramientas

ADUC
ADSIEdit
Group Policy Management Console
PowerShell (AD module)

Descripción del empleo

About the client:

Our customer is the European online car market with over 30 million monthly users, with a market presence in 18 countries. As a Lead Active Directory Engineer, you will play a pivotal role in shaping the future of online car markets and enhancing the user experience for millions of car buyers and sellers.

Project Overview

We require a Lead Active Directory Engineer to assess, clean up, and harden multiple inherited single-forest, single-domain Active Directory environments.

These environments require standardization, security hardening, and alignment with current best practices. The focus will be on improving AD structure, security posture, Group Policy hygiene, and operational consistency, while also evaluating long‑term viability and integration with enterprise IAM platforms.

This is a hands‑on senior role requiring deep expertise in Active Directory architecture, security, identity integration, and remediation of legacy configurations, including alignment with industry audit and compliance standards (e.g., PCI DSS).

Requirements
  • EDT Timezone work hours
  • Extensive hands‑on experience (typically 7+ years) with Active Directory engineering and administration
  • Proven experience performing AD clean‑up, consolidation, or post‑transition integration work
  • Strong expertise in:
    • Active Directory (single‑domain environments at scale)
    • Group Policy design, cleanup, and optimization
    • OU design and delegation models
  • Demonstrated experience with:
    • AD security hardening (tiered admin model, least privilege, attack surface reduction)
  • Identifying and remediating:
    • Stale objects (users, computers, groups)
    • Legacy permissions and misconfigurations
    • GPO sprawl and conflicts
  • Experience integrating Active Directory with IAM/IdP platforms, including:
    • Azure AD / Entra ID, Okta, etc
    • SSO, federation, and identity synchronization (e.g., AAD Connect or equivalent)
    • Role‑based access control (RBAC) and identity lifecycle management
  • Experience working within regulated or audited environments, including:
    • PCI DSS (or similar frameworks such as ISO 27001, NIST)
    • Implementing controls related to identity, access management, and auditability
  • Strong knowledge of:
    • Authentication protocols (Kerberos, NTLM, SAML/OIDC basics)
    • DNS (AD‑integrated), replication, and site topology
  • Experience with tools such as:
    • ADUC, ADSIEdit, Group Policy Management Console
    • PowerShell (AD module) for bulk changes and reporting
  • Experience in auditing and improving:
    • Privileged access (Domain Admins, Enterprise Admins)
    • Service accounts and delegation
  • At least upper‑intermediate English level
Responsibilities
  • Perform a comprehensive assessment of current AD environments
  • Identify and remediate:
    • Inactive/stale objects
    • Legacy groups and excessive permissions
    • GPO duplication, conflicts, and inefficiencies
  • Redesign and implement:
    • OU structure and delegation model
    • Group Policy strategy aligned to best practices
  • Implement security hardening measures, including:
    • Privileged access model (e.g., tiering)
    • Reduction of attack surface and legacy protocols
    • Alignment with audit/compliance requirements (e.g., PCI DSS controls)
  • Integrate AD environments with enterprise IAM platforms, including:
    • Identity synchronization and federation
    • Access model alignment (RBAC / least privilege)
    • SSO enablement and identity lifecycle processes
  • Review and optimize:
    • AD Sites and Services (replication topology)
    • DNS configuration and health
    • Develop and execute cleanup and remediation plans with minimal disruption
    • Automate tasks and reporting using PowerShell
    • Produce clear documentation and operational standards, including audit‑ready configurations
Expected Deliverables
  • Completed AD health assessment and remediation roadmap
  • Reduction in stale objects, legacy permissions, and GPO sprawl
  • Implemented hardened AD structure aligned with best practices and audit standards (e.g., PCI DSS)
  • Successful integration of AD environments with IAM platform(s), including SSO and identity lifecycle alignment
  • Improved security posture (privileged access, delegation, policies)
  • Documented AD design, IAM integration approach, and operational procedures
  • Assessment and recommendations for future state strategy, including options to consolidate, migrate, or decommission existing domains, with associated risks, dependencies, and a high‑level migration approach
Nice‑to‑Have Certifications
  • Microsoft Certified: Windows Server Hybrid Administrator Associate
  • Microsoft Certified: Identity and Access Administrator Associate (SC‑300)
  • Microsoft Certified: Azure Solutions Architect Expert
  • MCSA / MCSE (legacy but relevant)
  • Security certifications (e.g., CISSP, Security+, CISM)
  • Okta Certified Professional / Administrator (or similar IAM certifications)
We offer*:
  • Flexible working format - remote, office‑based or flexible
  • A competitive salary and good compensation package
  • Personalized career growth
  • Professional development tools (mentorship program, tech talks and trainings, centers of excellence, and more)
  • Active tech communities with regular knowledge sharing
  • Education reimbursement
  • Memorable anniversary presents
  • Corporate events and team buildings
  • Other location‑specific benefits
  • not applicable for freelancers
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Systems Administrator / IT Support Engineer
Systems Administrator / IT Support Engineer

NeoWork • Colombia

Híbrido
COP 93.305.035 - 111.248.311
Health insurance for contractors
Holiday extra pay
Mental health days
+2
Engineer Infrastructure & Platform Services – Intel/Linux/Active Directory
Engineer Infrastructure & Platform Services – Intel/Linux/Active Directory

G10X • Colombia

Presencial
COP 73.257.000 - 109.887.000
Lead Active Directory Engineer - Remote & Security Focused
Lead Active Directory Engineer - Remote & Security Focused

N-iX • Medellín

Híbrido
COP 120.000.000 - 200.000.000
Flexible working format
Competitive salary and compensation
Education reimbursement
+1
Lead IT Engineer
Lead IT Engineer

Autonomic Mind • Medellín

Presencial
Private health insurance
Education and training bonus
Parking
Lead Azure DevOps Engineer
Lead Azure DevOps Engineer

EPAM Systems • Colombia

Presencial
COP 120.000.000 - 240.000.000
Healthcare benefits
Paid time off and sick leave
Upskilling and certification courses
+2
Azure Cloud Administrator
Azure Cloud Administrator

SoftwareOne Deutschland GmbH • Montes de María

Presencial
COP 279.738.000 - 372.984.000
Health insurance
Life insurance
Paid sick leave
+5
Azure Data Architect
Azure Data Architect

EXL • Bogotá

Híbrido
COP 200.880.000 - 312.480.000
Learning platforms access
Certification programs
Hybrid or remote work depending on loc
Azure Cloud Administrator
Azure Cloud Administrator

SoftwareONE Deutschland GmbH • Sur

Híbrido
COP 90.000.000 - 150.000.000
Health insurance
Life insurance
100% paid sick leave
+3
Senior Security Consultant
Senior Security Consultant

Scale Up Recruiting Partners • Perímetro Urbano Barranquilla

Presencial
COP 294.849.954 - 425.894.378
Senior/Lead DevSecOps Engineer (Azure, Terraform, Sentinel)
Senior/Lead DevSecOps Engineer (Azure, Terraform, Sentinel)

N-iX • Colombia

Híbrido
COP 300.812.000 - 434.507.000
Flexible working format
Competitive salary
Education reimbursement
+2