Active Directory Specialist

Queen Square Recruitment

Reading

Hybrid

GBP 80,000 - 100,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Queen Square Recruitment seeks an experienced identity security specialist to lead Active Directory remediation and governance across large enterprise environments. You will administer AD at Domain Admin and Enterprise Admin levels and drive security improvements for AD CS, authentication, and delegation models.

You will coordinate remediation with infrastructure, security, server, database, and application teams, producing governance reports and executive updates.

Qualifications

  • Proven experience administering and securing Active Directory in large enterprises.
  • Expertise in AD security remediation, hardening, and privilege reduction.
  • Strong understanding of AD CS and certificate-based authentication.
  • Knowledge of Kerberos, SPNs, and delegation models.
  • Experience reviewing AD permissions, ACLs, and privileged groups.
  • Familiarity with IAM and PAM technologies and security principles.
  • Experience with Azure AD and hybrid identities.
  • Experience with PAM platforms and least-privilege security models.
  • Experience producing remediation plans and governance reports.
  • Experience with live production environments and change management.

Responsibilities

  • Lead AD security remediation activities across complex environments.
  • Perform AD administration and governance at Domain Admin and Enterprise Admin levels.
  • Identify and remediate identity-related vulnerabilities and misconfigurations.
  • Review and secure AD CS, authentication, and delegation models.
  • Govern privileged access controls, service accounts, and admin groups.
  • Coordinate remediation with infrastructure, security, server, database, and apps teams.
  • Plan and govern production changes with risk and change management.
  • Produce remediation evidence, governance reports, and executive updates.
  • Support identity security initiatives and cyber resilience programs.
  • Conduct root-cause investigations and provide remediation recommendations.
  • Provide escalation support during out-of-hours periods.

Skills

Active Directory
AD security remediation
Privileged Access Management
Azure AD / Entra ID
Kerberos authentication
AD CS
IAM
PAM platforms (CyberArk, BeyondTrust,D

Education

Microsoft Identity & Access Administrator Associate
Microsoft Security Operations Analyst Associate
CISSP
CISM

Tools

PingCastle
BloodHound
Purple Knight

Job description

Work Model: Hybrid – 2 days per week in office

Contract Duration: 12 Months

Key Responsibilities
  • Lead and drive Active Directory security remediation activities across complex enterprise environments.
  • Perform Active Directory administration and governance at Domain Admin and Enterprise Admin levels.
  • Identify, assess, prioritise, and remediate identity-related vulnerabilities, security misconfigurations, and privilege escalation risks.
  • Review, harden, and secure Active Directory Certificate Services (AD CS), authentication mechanisms, and delegation models.
  • Manage and govern privileged access controls, service accounts, administrative groups, permissions, and access pathways.
  • Coordinate remediation activities across infrastructure, security, server, database, application, and support teams.
  • Plan, execute, and govern production changes while ensuring effective change, risk, and operational management processes are followed.
  • Produce detailed technical documentation, remediation evidence, governance reports, and executive-level status updates.
  • Support enterprise initiatives focused on identity security improvement, cyber resilience, compliance, and security governance.
  • Conduct root-cause investigations and provide recommendations for resolving complex identity, authentication, and access management issues.
  • Provide escalation and remediation support during agreed out-of-hours periods where required.
Required Skills
  • Proven hands-on experience administering and securing Active Directory within large-scale enterprise environments.
  • Strong expertise in Active Directory security remediation, security hardening, and privilege reduction programmes.
  • Deep understanding of Active Directory Certificate Services (AD CS) and certificate-based authentication security.
  • Strong knowledge of Kerberos authentication, delegation models, SPNs, and service account security.
  • Experience reviewing and remediating AD permissions, ACLs, privileged groups, and administrative access paths.
  • Strong knowledge of Microsoft Identity & Access Management (IAM) technologies and security principles.
  • Experience with Privileged Access Management (PAM) and least-privilege security models.
  • Experience delivering security remediation activities within live production environments, including change and risk management.
  • Experience producing remediation plans, technical reports, governance documentation, and executive updates.
  • Experience with Microsoft Entra ID (Azure AD) and hybrid identity environments.
  • Knowledge of CyberArk, BeyondTrust, Delinea, or other PAM platforms.
  • Exposure to Microsoft Defender for Identity and identity threat detection technologies.
  • Experience implementing Tiered Administration, ESAE (Red Forest), or similar privileged access security models.
  • Understanding of Microsoft Security Baselines, CIS Controls, and Active Directory security best practices.
  • Experience using tools such as PingCastle, BloodHound, Purple Knight, or similar Active Directory security assessment solutions.
  • Experience supporting large-scale security transformation or remediation programmes.
  • Knowledge of SQL Server security, authentication, and privileged access governance.
  • Relevant certifications including: - Microsoft Certified: Identity and Access Administrator Associate, Microsoft Certified: Security Operations Analyst Associate, CISSP, CISM, Or equivalent security certifications.
  • Experience working within regulated environments with strong governance, audit, compliance, and risk management requirements.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Active Directory Specialist
Active Directory Specialist

La Fosse • Greater London

On-site
GBP 70,000 - 95,000
Active Directory Security Lead - Identity & PAM Expert
Active Directory Security Lead - Identity & PAM Expert

Queen Square Recruitment • Reading

Hybrid
GBP 80,000 - 100,000
Infrastructure Engineer -
Infrastructure Engineer -

Experis - ManpowerGroup • Manchester

On-site
GBP 59,000 - 98,000
AD Engineer
AD Engineer

La-Fosse-1 • Greater London

Hybrid
GBP 94,000 - 127,000
DV Cleared Active Directory
DV Cleared Active Directory

Synergize Consulting Ltd • Corsham

On-site
GBP 90,000 - 130,000
Active Directory Specialist
Active Directory Specialist

mthree • London

On-site
GBP 50,000 - 90,000
AD Engineer
AD Engineer

La Fosse Associates • Greater London

Hybrid
GBP 94,000 - 127,000
Active Directory Specialist
Active Directory Specialist

Amtex Systems Inc • Greater London

On-site
GBP 60,000 - 80,000
Senior Systems Engineer, User Support
Senior Systems Engineer, User Support

ARCH EUROPE INSURANCE SERVICES LTD • Manchester

On-site
GBP 60,000 - 80,000
Senior Systems Engineer, User Support
Senior Systems Engineer, User Support

ARCH EUROPE INSURANCE SERVICES LTD • England

On-site
GBP 65,000 - 85,000