Active Directory(ADFS) Customer Engineer

Darwinbox Digital Solutions Pvt. Ltd.

Bengaluru

On-site

INR 2,000,000 - 3,200,000

Full time

30 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Darwinbox Digital Solutions Pvt. Ltd. seeks a senior Active Directory/ADFS Architect to lead enterprise identity initiatives. You will design and implement secure, scalable identity platforms across on-premises, hybrid, and cloud environments, trabajando with cross‑functional teams and customers.

The role requires deep hands-on expertise in AD, ADFS, PKI, and related technologies, with capability to mentor teams and drive modernization programs.

Qualifications

  • 15+ years of IT/identity experience.
  • Expert-level Active Directory knowledge and design.
  • Experience with ADDS, ADFS, PKI architectures and migrations.

Responsibilities

  • Lead architecture and design of complex Microsoft Identity solutions.
  • Architect high-availability identity infrastructures across on‑prem, hybrid, and cloud.
  • Drive modernization of legacy AD/ADFS/PKI environments.

Skills

Active Directory
ADFS
PKI
Identity
Kerberos
LDAP
DNS
Group Policy
NTLM
SSO

Education

Bachelor's degree in CS/IT/Eng

Tools

AD CS
WAP

Job description

Active Directory(ADFS) Customer Engineer BG4, Bangalore, Karnataka, India Permanent

Job Description

Job Title: Active Directory(ADFS) Customer Engineer

Location: Bangalore/Hyderabad

Duration: Full Time

Experience level: 8-20 years

Role Overview : We are looking for a highly experienced Principal Solution Architect with 15+ years of expertise in Microsoft Active Directory, Active Directory Federation Services (ADFS), Public Key Infrastructure (PKI), and Microsoft Identity technologies to join the CSAGlobal Delivery (CSA GD) team. The successful candidate will serve as a technical authority and architecture leader for complex enterprise identity, authentication, federation, directory services, and PKI engagements. The role requires deep hands‑on technical expertise combined with the ability to define enterprise architectures, lead complex implementations and transformations, troubleshoot critical environments, and provide technical direction to engineering teams and customers. The architect will work closely with Microsoft customers, CSA teams, engineering teams, program managers, and other technology stakeholders to design secure, scalable, resilient, and modern identity solutions.

Key Responsibilities:
1. Solution Architecture & Design
  • Lead architecture and design of complex Microsoft Identity and AccessManagement solutions.
  • Develop enterprise architectures covering:
    • Active Directory Domain Services (AD DS)
    • Active Directory Federation Services (ADFS)
    • PKI / Active Directory Certificate Services (AD CS)
    • Active Directory Domain Controllers
    • DNS and Group Policy
    • Windows authentication and authorization
    • Kerberos and NTLM
    • LDAP
    • Federation and SSO
    • Hybrid identity
  • Define High-Level Design (HLD), Low-Level Design (LLD), architecture diagrams, technical standards, and implementation strategies.
  • Design highly available and resilient identity infrastructures across on-premises, hybrid, and cloud environments.
  • Conduct architecture assessments and identify technical, security, scalability, and operational risks.
  • Provide modernization strategies for legacy AD/ADFS/PKI environments.
2. Active Directory – Principal-Level Expertise
  • Provide deep architectural expertise in Active Directory Domain Services (AD DS).
  • Design and optimize:
    • Forest and domain architecture
    • Domain/forest trusts
    • Sites and Services
    • Replication topology
    • Global Catalog
    • FSMO role
    • DNS integration
    • Group Policy architecture
    • OU and delegation models
    • Authentication architecture
  • Troubleshoot complex AD issues involving:
    • Replication failures
    • Kerberos authentication
    • DNS
    • SYSVOL/DFSR
    • Domain controller health
    • Trust relationships
    • Authentication failures
    • GPO processing
  • Lead AD forest/domain migrations, consolidations, restructures, and modernization initiatives.
  • Develop AD recovery and business continuity strategies, including forest recovery.
3. ADFS Core
  • Provide subject‑matter expertise in Active Directory Federation Services (ADFS) architecture and implementation.
  • Design and troubleshoot complex:
    • ADFS farms
    • Federation services
    • Web Application Proxy (WAP)
    • Claims‑based authentication
    • Claims rules
    • Relying Party Trusts
    • Claims Provider Trusts
    • SAML
    • WS‑Federation
    • OAuth/OIDC integrations where applicable
  • Design highly available and secure ADFS architectures.
  • Troubleshoot complex authentication and federation issues.
  • Analyze ADFS event logs, authentication flows, token issuance, certificates, and claims.
  • Lead ADFS migrations, upgrades, farm redesigns, and modernization programs.
  • Develop strategies for transitioning legacy ADFS workloads to modern cloud‑based identity platforms where appropriate.
4. PKI / Active Directory Certificate Services
  • Provide principal‑level architecture expertise in Microsoft PKI and Active Directory Certificate Services (AD CS).
  • Design enterprise PKI architectures including:
    • Root CA
    • Subordinate/Issuing CA
    • Offline Root CA
    • Enterprise CA
    • Standalone CA
    • Certificate templates
    • CRL
    • OCSP
    • AIA/CDP
  • Design certificate lifecycle management strategies.
  • Troubleshoot complex certificate issuance, validation, revocation, and trust chain issues.
  • Architect PKI solutions for:
    • Windows authentication
    • Smart cards
    • Device authentication
    • TLS/SSL
    • Wi‑Fi authentication
    • VPN
    • Application authentication
    • Code signing
  • Lead PKI migrations, CA upgrades, certificate authority consolidation, and certificate infrastructure modernization.
  • Define PKI security controls, key protection, CA hierarchy, backup/recovery, and disaster recovery strategies.
5. Identity Security
  • Design secure identity architectures following Zero Trust and least‑privilege principles.
  • Assess risks associated with:
    • Privileged accounts
    • Domain Admin access
    • Service accounts
    • Kerberos
    • NTLM
    • LDAP
    • Certificate authorities
    • ADFS
    • Domain Controllers
  • Recommend security hardening for AD, ADFS, and PKI environments.
  • Develop strategies for reducing legacy authentication protocols and improving identity security.
  • Support identity security assessments and remediation programs.
6. Modernization & Transformation
  • Lead transformation initiatives from legacy identity infrastructure toward modern Microsoft identity architectures.
  • Evaluate migration paths from:
    • Legacy AD Modern AD architecture
    • ADFS Microsoft Entra ID
    • Legacy PKI Modern certificate management
    • Traditional authentication modern authentication
  • Develop phased migration roadmaps while maintaining business continuity.
  • Assess dependencies between legacy applications and identity infrastructure.
  • Provide technical recommendations for hybrid identity and cloud adoption.
7. Customer & Technical Leadership
  • Act as a Principal Technical Advisor for complex customer engagements.
  • Engage directly with customer architects, technical leaders, and senior stakeholders.
  • Lead architecture workshops and technical deep dives.
  • Translate complex technical requirements into scalable enterprise solutions.
  • Present architecture recommendations and technical strategies to senior leadership.
  • Serve as an escalation point for Severity 1 / critical identity incidents.
  • Mentor senior engineers, architects, and technical leads.
8. CSA GD / Global Delivery Responsibilities
  • Collaborate with Microsoft CSA teams and Global Delivery stakeholders on complex customer engagements.
  • Participate in customer workshops, architecture reviews, technical assessments, and delivery governance.
  • Provide technical leadership across geographically distributed delivery teams.
  • Define reusable architecture patterns, reference architectures, and technical accelerators.
  • Contribute to knowledge management and technical communities within CSA GD.
  • Identify opportunities for automation and standardization across identity engagements.
Required Technical SkillsMandatory Active Directory
  • 15+ years of Microsoft infrastructure / identity experience.
  • Expert-level Active Directory Domain Services knowledge.
  • AD architecture and design.
  • Forest/domain design.
  • AD replication.
  • DNS.
  • Group Policy.
  • Kerberos.
  • LDAP.
  • Trusts.
  • Domain Controller architecture and troubleshooting.
  • AD migration and consolidation.
Architecture & Leadership Competencies
  • The candidate should demonstrate the ability to:
  • Own architecture for large‑scale enterprise identity environments.
  • Make architecture decisions involving security, availability, scalability, and operational complexity.
  • Lead technical teams through complex transformation programs.
  • Conduct architecture reviews and challenge existing technical designs.
  • Provide clear technical recommendations to senior stakeholders.
  • Lead customer‑facing technical discussions independently.
  • Mentor architects and senior engineers.
  • Drive technical standards and reusable solutions.
  • Manage ambiguity and provide structured technical direction.
  • Operate effectively in a global delivery / customer‑facing environment.
Education & CertificationsRequired:
  • Bachelor's degree in Computer Science, Information Technology, Engineering, or related discipline.
Preferred Certifications:
  • Microsoft Certified: Identity and Access Administrator
  • Microsoft Certified: Windows Server Hybrid Administrator
  • Microsoft Certified: Azure Solutions Architect Expert
  • Microsoft Certified: Cybersecurity Architect Expert
  • Microsoft Certified: Azure Security Engineer Associate
  • Microsoft Certified: Azure Administrator Associate
  • Equivalent extensive enterprise architecture experience may be considered in lieu of specific certifications.
Experience ProfileThe ideal candidate should have:
  • 15+ years of overall IT experience.
  • Extensive experience designing and supporting enterprise Microsoft identity infrastructure.
  • Significant experience working with large Active Directory environments.
  • Proven expertise in ADFS and PKI architecture.
  • Experience leading complex AD/ADFS/PKI migrations and modernization programs.
  • Strong customer‑facing and consulting experience.
  • Experience working with globally distributed teams.
  • Strong technical documentation and presentation skills.
  • Experience acting as a technical authority / principal architect rather than solely as an implementation engineer.

A BOUT SONATA SOFTWARE Sonata Software is an AI-first modernization engineering company that helps enterprises transform legacy systems into intelligent, scalable business platforms. Powered by its Platformation framework and Harmoni.AI platform, Sonata delivers AI‑led modernization across cloud, data, AI, Dynamics, test automation, and managed services. Headquartered in Bengaluru, India, Sonata has more than $1.2 billion in revenue and 6,400+ AI engineers supporting global delivery across regions including the US, UK, India, Malaysia, Mexico, Australia, DACH, and the Nordics. With deep partnerships across Microsoft, AWS, Salesforce, and Snowflake, Sonata helps Fortune 500 enterprises accelerate innovation, improve efficiency, and drive sustainable growth.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Azure cloud architect with DNS/DHCP
Azure cloud architect with DNS/DHCP

Darwinbox Digital Solutions Pvt. Ltd. • Bengaluru

On-site
INR 2,500,000 - 4,200,000
Architect -Microsoft 365 & Active Directory Tenant Migration
Architect -Microsoft 365 & Active Directory Tenant Migration

Darwinbox Digital Solutions Pvt. Ltd. • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Senior Devops Engineer
Senior Devops Engineer

Darwinbox Digital Solutions Pvt. Ltd. • Pune District

Hybrid
INR 1,500,000 - 2,100,000
Digital Senior Engineer
Digital Senior Engineer

Darwinbox Digital Solutions Pvt. Ltd. • Pune District

Hybrid
INR 2,000,000 - 2,800,000
SharePoint Online & On-Premise
SharePoint Online & On-Premise

Darwinbox Digital Solutions Pvt. Ltd. • Bengaluru

On-site
INR 3,800,000 - 7,000,000
Linux/Unix support & DevOps enginee
Linux/Unix support & DevOps enginee

Darwinbox Digital Solutions Pvt. Ltd. • Hyderabad

On-site
INR 1,800,000 - 3,600,000
SharePoint Administration with Power Platform
SharePoint Administration with Power Platform

Sonata Software • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Entra ID Customer Engineer
Entra ID Customer Engineer

Darwinbox Digital Solutions Pvt. Ltd. • Hyderabad

On-site
INR 3,500,000 - 6,000,000
Azure AI Architect (Technical Advisor Specialist ) Role - Blr / Hyd
Azure AI Architect (Technical Advisor Specialist ) Role - Blr / Hyd

Sonata Software • Hyderabad, Bengaluru

On-site
INR 2,500,000 - 5,000,000
Sharepoint Architect
Sharepoint Architect

Darwinbox Digital Solutions Pvt. Ltd. • Bengaluru

On-site
INR 3,500,000 - 5,500,000