Active Directory(ADFS) Customer Engineer BG4, Bangalore, Karnataka, India Permanent
Job Description
Job Title: Active Directory(ADFS) Customer Engineer
Location: Bangalore/Hyderabad
Duration: Full Time
Experience level: 8-20 years
Role Overview : We are looking for a highly experienced Principal Solution Architect with 15+ years of expertise in Microsoft Active Directory, Active Directory Federation Services (ADFS), Public Key Infrastructure (PKI), and Microsoft Identity technologies to join the CSAGlobal Delivery (CSA GD) team. The successful candidate will serve as a technical authority and architecture leader for complex enterprise identity, authentication, federation, directory services, and PKI engagements. The role requires deep hands‑on technical expertise combined with the ability to define enterprise architectures, lead complex implementations and transformations, troubleshoot critical environments, and provide technical direction to engineering teams and customers. The architect will work closely with Microsoft customers, CSA teams, engineering teams, program managers, and other technology stakeholders to design secure, scalable, resilient, and modern identity solutions.
Key Responsibilities:
1. Solution Architecture & Design
- Lead architecture and design of complex Microsoft Identity and AccessManagement solutions.
- Develop enterprise architectures covering:
- Active Directory Domain Services (AD DS)
- Active Directory Federation Services (ADFS)
- PKI / Active Directory Certificate Services (AD CS)
- Active Directory Domain Controllers
- DNS and Group Policy
- Windows authentication and authorization
- Kerberos and NTLM
- LDAP
- Federation and SSO
- Hybrid identity
- Define High-Level Design (HLD), Low-Level Design (LLD), architecture diagrams, technical standards, and implementation strategies.
- Design highly available and resilient identity infrastructures across on-premises, hybrid, and cloud environments.
- Conduct architecture assessments and identify technical, security, scalability, and operational risks.
- Provide modernization strategies for legacy AD/ADFS/PKI environments.
2. Active Directory – Principal-Level Expertise
- Provide deep architectural expertise in Active Directory Domain Services (AD DS).
- Design and optimize:
- Forest and domain architecture
- Domain/forest trusts
- Sites and Services
- Replication topology
- Global Catalog
- FSMO role
- DNS integration
- Group Policy architecture
- OU and delegation models
- Authentication architecture
- Troubleshoot complex AD issues involving:
- Replication failures
- Kerberos authentication
- DNS
- SYSVOL/DFSR
- Domain controller health
- Trust relationships
- Authentication failures
- GPO processing
- Lead AD forest/domain migrations, consolidations, restructures, and modernization initiatives.
- Develop AD recovery and business continuity strategies, including forest recovery.
3. ADFS Core
- Provide subject‑matter expertise in Active Directory Federation Services (ADFS) architecture and implementation.
- Design and troubleshoot complex:
- ADFS farms
- Federation services
- Web Application Proxy (WAP)
- Claims‑based authentication
- Claims rules
- Relying Party Trusts
- Claims Provider Trusts
- SAML
- WS‑Federation
- OAuth/OIDC integrations where applicable
- Design highly available and secure ADFS architectures.
- Troubleshoot complex authentication and federation issues.
- Analyze ADFS event logs, authentication flows, token issuance, certificates, and claims.
- Lead ADFS migrations, upgrades, farm redesigns, and modernization programs.
- Develop strategies for transitioning legacy ADFS workloads to modern cloud‑based identity platforms where appropriate.
4. PKI / Active Directory Certificate Services
- Provide principal‑level architecture expertise in Microsoft PKI and Active Directory Certificate Services (AD CS).
- Design enterprise PKI architectures including:
- Root CA
- Subordinate/Issuing CA
- Offline Root CA
- Enterprise CA
- Standalone CA
- Certificate templates
- CRL
- OCSP
- AIA/CDP
- Design certificate lifecycle management strategies.
- Troubleshoot complex certificate issuance, validation, revocation, and trust chain issues.
- Architect PKI solutions for:
- Windows authentication
- Smart cards
- Device authentication
- TLS/SSL
- Wi‑Fi authentication
- VPN
- Application authentication
- Code signing
- Lead PKI migrations, CA upgrades, certificate authority consolidation, and certificate infrastructure modernization.
- Define PKI security controls, key protection, CA hierarchy, backup/recovery, and disaster recovery strategies.
5. Identity Security
- Design secure identity architectures following Zero Trust and least‑privilege principles.
- Assess risks associated with:
- Privileged accounts
- Domain Admin access
- Service accounts
- Kerberos
- NTLM
- LDAP
- Certificate authorities
- ADFS
- Domain Controllers
- Recommend security hardening for AD, ADFS, and PKI environments.
- Develop strategies for reducing legacy authentication protocols and improving identity security.
- Support identity security assessments and remediation programs.
6. Modernization & Transformation
- Lead transformation initiatives from legacy identity infrastructure toward modern Microsoft identity architectures.
- Evaluate migration paths from:
- Legacy AD Modern AD architecture
- ADFS Microsoft Entra ID
- Legacy PKI Modern certificate management
- Traditional authentication modern authentication
- Develop phased migration roadmaps while maintaining business continuity.
- Assess dependencies between legacy applications and identity infrastructure.
- Provide technical recommendations for hybrid identity and cloud adoption.
7. Customer & Technical Leadership
- Act as a Principal Technical Advisor for complex customer engagements.
- Engage directly with customer architects, technical leaders, and senior stakeholders.
- Lead architecture workshops and technical deep dives.
- Translate complex technical requirements into scalable enterprise solutions.
- Present architecture recommendations and technical strategies to senior leadership.
- Serve as an escalation point for Severity 1 / critical identity incidents.
- Mentor senior engineers, architects, and technical leads.
8. CSA GD / Global Delivery Responsibilities
- Collaborate with Microsoft CSA teams and Global Delivery stakeholders on complex customer engagements.
- Participate in customer workshops, architecture reviews, technical assessments, and delivery governance.
- Provide technical leadership across geographically distributed delivery teams.
- Define reusable architecture patterns, reference architectures, and technical accelerators.
- Contribute to knowledge management and technical communities within CSA GD.
- Identify opportunities for automation and standardization across identity engagements.
Required Technical SkillsMandatory Active Directory
- 15+ years of Microsoft infrastructure / identity experience.
- Expert-level Active Directory Domain Services knowledge.
- AD architecture and design.
- Forest/domain design.
- AD replication.
- DNS.
- Group Policy.
- Kerberos.
- LDAP.
- Trusts.
- Domain Controller architecture and troubleshooting.
- AD migration and consolidation.
Architecture & Leadership Competencies
- The candidate should demonstrate the ability to:
- Own architecture for large‑scale enterprise identity environments.
- Make architecture decisions involving security, availability, scalability, and operational complexity.
- Lead technical teams through complex transformation programs.
- Conduct architecture reviews and challenge existing technical designs.
- Provide clear technical recommendations to senior stakeholders.
- Lead customer‑facing technical discussions independently.
- Mentor architects and senior engineers.
- Drive technical standards and reusable solutions.
- Manage ambiguity and provide structured technical direction.
- Operate effectively in a global delivery / customer‑facing environment.
Education & CertificationsRequired:
- Bachelor's degree in Computer Science, Information Technology, Engineering, or related discipline.
Preferred Certifications:
- Microsoft Certified: Identity and Access Administrator
- Microsoft Certified: Windows Server Hybrid Administrator
- Microsoft Certified: Azure Solutions Architect Expert
- Microsoft Certified: Cybersecurity Architect Expert
- Microsoft Certified: Azure Security Engineer Associate
- Microsoft Certified: Azure Administrator Associate
- Equivalent extensive enterprise architecture experience may be considered in lieu of specific certifications.
Experience ProfileThe ideal candidate should have:
- 15+ years of overall IT experience.
- Extensive experience designing and supporting enterprise Microsoft identity infrastructure.
- Significant experience working with large Active Directory environments.
- Proven expertise in ADFS and PKI architecture.
- Experience leading complex AD/ADFS/PKI migrations and modernization programs.
- Strong customer‑facing and consulting experience.
- Experience working with globally distributed teams.
- Strong technical documentation and presentation skills.
- Experience acting as a technical authority / principal architect rather than solely as an implementation engineer.
A BOUT SONATA SOFTWARE Sonata Software is an AI-first modernization engineering company that helps enterprises transform legacy systems into intelligent, scalable business platforms. Powered by its Platformation framework and Harmoni.AI platform, Sonata delivers AI‑led modernization across cloud, data, AI, Dynamics, test automation, and managed services. Headquartered in Bengaluru, India, Sonata has more than $1.2 billion in revenue and 6,400+ AI engineers supporting global delivery across regions including the US, UK, India, Malaysia, Mexico, Australia, DACH, and the Nordics. With deep partnerships across Microsoft, AWS, Salesforce, and Snowflake, Sonata helps Fortune 500 enterprises accelerate innovation, improve efficiency, and drive sustainable growth.