Active Directory Specialist

SHI Solutions India Pvt. Ltd.

Pune District

On-site

INR 1,400,000 - 1,800,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SHI Solutions India Pvt. Ltd. seeks an experienced L3 AD & Windows Server Engineer to own end-to-end AD/Windows Server administration, upgrades, migrations, and security hardening within enterprise environments.

Responsibilities include leading Domain Controller projects, implementing security controls, and mentoring L1/L2 engineers while supporting hybrid identity and Hyper-V infrastructure.

Qualifications

  • Strong hands-on experience with Windows Server 2016/2019/2022/2025 and Active Directory.
  • Experience with AD upgrades/migrations and domain controller operations.
  • Design and implement security hardening measures for privileged access.
  • Hands-on Hyper-V host/cluster administration and VM lifecycle management.
  • Proficient in DNS, DHCP, Group Policy, SYSVOL, and Kerberos/LDAP/NTLM.
  • Experience with Entra Connect/Azure AD hybrid identity concepts.

Responsibilities

  • Own end-to-end administration and troubleshooting of enterprise AD environments.
  • Lead AD and Windows Server upgrade/migration initiatives.
  • Design and implement security hardening measures and access controls.
  • Serve as the L3 escalation point for complex AD/Windows Server incidents.
  • Support hybrid identity and cloud integration with Entra Connect.
  • Administer Hyper-V virtualization and cluster infrastructure.
  • Maintain documentation, runbooks, and mentor L1/L2 engineers.

Skills

Windows Server
Active Directory
Hyper-V
PowerShell
DNS/DHCP
Group Policy
Entra Connect
Azure basics
Security hardening
FSMO roles
VM provisioning

Job description

The L3 Active Directory (AD) & Windows Server Engineer is a senior technical resource responsible for the end-to-end administration, upgrade, migration, and security hardening of enterprise Active Directory, Windows Server and Hyper-V environments. This role combines hands-on experience on complex Hyper-V, Windows server environments, operational ownership with the ability to lead complex AD initiatives – including Domain Controller upgrades, migrations, and security hardening programs – and acts as the escalation point for issues beyond L1/L2 capability. The profile is designed to be broadly applicable across AD/Hyper-V/Windows Server engagements, not tied to any single project.

  • Own end-to-end administration and troubleshooting of enterprise AD environments – DNS, Group Policy, SYSVOL replication, and authentication services (Kerberos/LDAP/NTLM).
  • Lead AD and Windows Server upgrade/migration initiatives – Domain Controller builds, FSMO role transfers, functional level upgrades, and legacy decommissioning.
  • Design and implement security hardening measures – privileged access tiering, service account security, protocol hardening, and alignment with industry best practices.
  • Serve as the L3 escalation point for complex AD/Windows Server incidents – driving root-cause analysis and permanent resolution beyond L1/L2 capability.
  • Support hybrid identity and cloud integration – Microsoft Entra Connect sync, troubleshooting, and coordination with cloud/identity teams.
  • Administer Hyper-V virtualization and cluster infrastructure – host/cluster build and configuration, VM provisioning and lifecycle management, storage and networking, and troubleshooting across the virtualized environment.
  • Maintain documentation, drive change management, and mentor L1/L2 engineers – runbooks, as-built records, and knowledge transfer to strengthen operational maturity.
Technical Skill Set Required
  • Windows Server & AD DS: Strong hands-on experience with Windows Server 2016/2019/2022/2025 and Active Directory Domain Services.
  • Windows Server upgrade/migration: 2016 → 2019/2022/2025 – in-place and migration-based upgrade approaches, compatibility assessment, and rollback planning.
  • Domain Controllers: Build, promotion/demotion, and multi-site replication topology.
  • FSMO & Functional Levels: FSMO role management, Domain/Forest Functional Level upgrades and dependencies.
  • DNS & DHCP: AD-integrated DNS and DHCP administration.
  • Group Policy: Design, troubleshooting, and enterprise-scale management.
  • SYSVOL/DFSR: Replication configuration and health validation.
  • Authentication protocols: Kerberos, LDAP, and NTLM – configuration and troubleshooting.
  • Hybrid identity: Microsoft Entra Connect (Azure AD Connect) sync, configuration, and troubleshooting.
  • Azure fundamentals (basic): Working knowledge of Entra ID/Azure AD concepts and hybrid identity scenarios – AD/on-prem remains the primary focus, not deep Azure administration.
  • Security hardening: Windows LAPS, gMSA, Tier 0/1/2 privileged access model, legacy protocol remediation.
  • Hyper-V & Clustering: Host and Failover Cluster build/configuration, VM provisioning and lifecycle management, storage/networking, and general troubleshooting.
  • PowerShell: Scripting for automation, auditing, and bulk administration.
  • Monitoring & diagnostics: Familiarity with AD health-check and replication diagnostic tools.
  • ITSM/ticketing: Working knowledge of ITSM/ticketing platforms for incident and change management.
Preferred Qualifications
  • 9+ years of hands-on AD/Hyper-V/Windows Server infrastructure experience.
  • Relevant certification (e.g., Microsoft Certified: Windows Server Hybrid Administrator Associate, MCSE, or Azure Fundamentals AZ-900).
  • Prior experience with large-scale AD migrations, Migrating to Hyper-V or Domain Controller/Windows Server upgrade projects.

Strong written and verbal communication skills for client-facing documentation and reporting

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Active Directory Specialist
Active Directory Specialist

SHI • Pune District

On-site
INR 1,800,000 - 2,800,000
Active Directory Specialist
Active Directory Specialist

SHI • Mumbai City

On-site
INR 1,800,000 - 2,400,000
Active Directory Administrator
Active Directory Administrator

Indorama Ventures Global Shared Services • Kolkata District

Hybrid
INR 1,200,000 - 2,400,000
Manager - IT Operations & Infrastructure
Manager - IT Operations & Infrastructure

Tata Communications • Pune District

On-site
INR 1,200,000 - 1,800,000
Active directory
Active directory

Infosys • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Active Directory & Exchange L3 Engineer
Active Directory & Exchange L3 Engineer

Tech Mahindra • Hyderabad, Pune District, Bengaluru

Hybrid
INR 1,500,000 - 2,100,000
Active Directory Subject Matter Expert
Active Directory Subject Matter Expert

Tata Consultancy Services • Bengaluru

On-site
INR 600,000 - 900,000
Senior Windows and Active Directory Administrator
Senior Windows and Active Directory Administrator

Broadway Global Services • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Windows Server Engineer - Active Directory ,Domain Controllers , DHCP
Windows Server Engineer - Active Directory ,Domain Controllers , DHCP

CtrlS • Pune District

On-site
INR 900,000 - 1,500,000
Senior / Lead Active Directory Administrator (B3/C1)
Senior / Lead Active Directory Administrator (B3/C1)

r3 Consultant • Mumbai

Hybrid
INR 1,200,000 - 1,800,000