Responsibilities
EN Active Directory Expert / Identity Architect Identity & Directory Services Tech Lead – Workplace & Security Positioning within the Organization Reporting line: IT Production – Run / Workplace / Infrastructure Scope: Identity & Directory Services – Global Workplace environments Job location: Offshore – India (fully integrated within the global Workplace organization)
- L1 / L2 Support (Onshore & Offshore)
- L3 Workplace / Infrastructure / Security teams
- IT Projects / Build / Transformation teams
- Change, Release & CAB
- Security, IAM & Compliance teams
- AYVENS / Société Générale environments
Role Context The Active Directory Expert / Identity Architect role is part of a major Workplace and Identity transformation, operating in a hybrid Microsoft environment combining On-Prem Active Directory and Microsoft Entra ID, deployed across more than 43 countries. The role combines advanced technical expertise, Run accountability, security reinforcement and architectural contribution, in an international, complex and security-critical environment, subject to strong regulatory and compliance constraints. This is a senior N3 / global reference role, embedded within a global Workplace organization composed of onshore (France) and offshore (India) resources. The expert acts as the ultimate technical reference for Identity and Active Directory, ensuring standards, consistency and best practices across all environments.
Key Responsibilities
- Active Directory Architecture Reference (core responsibility)
- Act as the global technical reference for Active Directory architecture
- Own and promote AD standards at enterprise scale
- Design, maintain and evolve:
- Forest and domain architectures
- Trust relationships
- Replication models
- Challenge project design choices and ensure Run, security and resilience compliance
- Validate Active Directory and Identity designs from a production and security standpoint
- This is a decision-making and reference role, not limited to administration.
- Hybrid Identity & Microsoft Entra ID (reinforced expectations)
- Advanced expertise in Hybrid Identity architectures
- Full mastery of integration between:
- Active Directory On-Prem
- Microsoft Entra ID (Azure AD)
- Strong experience with:
- Azure AD Connect / Cloud Sync
- Hybrid authentication flows
- Complex identity synchronization scenarios
- Ability to analyze and explain Identity impacts on:
- Workplace services
- Security
- Business applications
- The role requires a functional and security-oriented understanding of authentication flows, not just directory synchronization.
- Active Directory Security & Hardening (key pillar)
- Act as a key authority on Active Directory security posture
- Deep understanding of Active Directory attack techniques and attack paths
- Implement, maintain and enforce best practices including:
- Tiering model (Tier 0 / 1 / 2)
- Privileged account separation
- Domain Controller hardening
- Actively challenge projects and changes that do not meet security requirements
- Contribute to:
- Security audits
- Risk assessments
- Remediation action plans
- The role includes real technical and security authority over the Identity perimeter.
- Core AD Services (DNS, GPO, Dependencies)
- Strong expertise in Active Directory-integrated DNS, considered a critical service
- Ability to design, operate and troubleshoot:
- Complex DNS architectures
- Name resolution issues impacting authentication and services
- Advanced mastery of:
- Group Policy design, optimization and troubleshooting
- GPO impacts on security and Workplace services
- Understanding of DHCP dependencies, where applicable
- PKI & Identity-Related Security Services
- Strong hands-on knowledge of Enterprise PKI
- Clear understanding of:
- Certificate lifecycle management
- Certificate roles in authentication and encryption
- Ability to troubleshoot complex certificate-related identity issues
- Awareness of data protection and classification services (AIP)
- Run, N3 Support & Advanced Troubleshooting
- Act as N3 Identity / Active Directory expert, final escalation point
- Handle incidents that are:
- Complex
- Critical
- Non-documented
- Advanced troubleshooting on:
- AD replication issues
- Authentication failures
- Trust and federation problems
- Ability to analyze:
- System logs
- Security events
- Abnormal infrastructure behavior
- Ability to operate under high operational pressure and crisis situations
- Change Management, Standards & Governance
- Own Identity-related changes presented in CAB
- Perform impact analyses and define rollback strategies
- Define, formalize and enforce Active Directory and Identity standards
- Produce, validate and maintain:
- Technical procedures
- Architecture documentation (DAT)
- Runbooks
- Actively contribute to the maturity and autonomy of L2 teams
- Automation & Continuous Improvement
- Expert use of PowerShell for:
- Administrative automation
- Run activities
- Reporting and AD health checks
- Identify structural weaknesses and recurring incidents
- Propose and lead continuous improvement initiatives for Identity services
Required Skills
Technical Skills
- Expert-level Active Directory knowledge
- Strong experience with:
- Microsoft Entra ID
- Complex hybrid Identity architectures
- Strong expertise in:
- Active Directory security and hardening
- DNS / GPO
- PKI
- Recognized advanced troubleshooting capabilities
- Strong PowerShell proficiency
Functional Skills
- Ability to operate in a global, multi-entity environment
- Strong understanding of Run / Build / Project organizations
- Solid familiarity with ITIL processes
- Proven experience working with onshore and offshore teams
Posture & Soft Skills
- Senior N3 / global reference expert posture, credible and recognized
- Natural technical authority and ability to challenge decisions
- High autonomy and strong sense of ownership
- Structured, rigorous and security-driven mindset
- Excellent communication skills in international contexts
Target Profile
- Bachelor’s to Master’s degree in IT (or equivalent experience)
- 5 to 8+ years of experience in Active Directory / Identity
- Strong experience in hybrid Microsoft environments
- International exposure is a strong plus
- Professional English mandatory (written and spoken)
What This Role Is Not
- An L2 support role
- A simple Active Directory administrator position
- A purely operational role
Profile required
EN Active Directory Expert / Identity Architect Identity & Directory Services Tech Lead – Workplace & Security Positioning within the Organization Reporting line: IT Production – Run / Workplace / Infrastructure Scope: Identity & Directory Services – Global Workplace environments Job location: Offshore – India (fully integrated within the global Workplace organization)
- L1 / L2 Support (Onshore & Offshore)
- L3 Workplace / Infrastructure / Security teams
- IT Projects / Build / Transformation teams
- Change, Release & CAB
- Security, IAM & Compliance teams
- AYVENS / Société Générale environments
Role Context The Active Directory Expert / Identity Architect role is part of a major Workplace and Identity transformation, operating in a hybrid Microsoft environment combining On-Prem Active Directory and Microsoft Entra ID, deployed across more than 43 countries. The role combines advanced technical expertise, Run accountability, security reinforcement and architectural contribution, in an international, complex and security-critical environment, subject to strong regulatory and compliance constraints. This is a senior N3 / global reference role, embedded within a global Workplace organization composed of onshore (France) and offshore (India) resources. The expert acts as the ultimate technical reference for Identity and Active Directory, ensuring standards, consistency and best practices across all environments.
Missions principales
1. Référent Architecture Active Directory (rôle central) • Être le référent technique global sur l’architecture Active Directory • Porter la vision et les standards AD à l’échelle des environnements • Maîtriser et faire évoluer les architectures : o Forêts et domaines o Relations de confiance (trusts) o Modèles de réplication • Challenger les choix techniques projets et garantir leur compatibilité Run & Sécurité • Valider les designs AD et Identité du point de vue production, sécurité et résilience Le rôle ne se limite pas à l’administration : il s’agit d’un poste de référence et de décision technique.
Compétences requises
- Expertise Active Directory de niveau expert
- Solide expérience en :
- Microsoft Entra ID
- Architectures hybrides complexes
- Forte compétence en :
- Sécurité Active Directory
- DNS / GPO
- PKI
- Capacité reconnue de troubleshooting avancé
- Très bonne maîtrise de PowerShell
Posture & soft skills
- Posture d’expert N3 / référent, crédible et reconnu
- Autorité technique naturelle et capacité à challenger
- Forte autonomie et sens des responsabilités
- Approche structurée, rigoureuse et orientée sécurité
- Excellent relationnel en contexte international
Profil recherché
- Bac+3 à Bac+5 en informatique ou équivalent
- 5 à 8 ans minimum d’expérience en Active Directory / Identité
- Expérience confirmée en environnement Microsoft hybride
- Expérience internationale appréciée
- Anglais professionnel obligatoire (écrit et oral)
Ce que ce poste n’est pas
- Un poste de support L2
- Un simple administrateur Active Directory
- Un rôle purement opérationnel
- C’est un poste d’expert / architecte Active Directory, référent global, garant de la stabilité, de la sécurité et de l’évolution des services d’Identité à l’échelle internationale.
Why join us
"We are committed to creating a diverse environment and are proud to be an equal opportunity employer. All qualified applicants receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status".
Business insight
At Société Générale, we are convinced that people are drivers of change, and that the world of tomorrow will be shaped by all their initiatives, from the smallest to the most ambitious. Whether you’re joining us for a period of months, years or your entire career, together we can have a positive impact on the future. Creating, daring, innovating, and taking action are part of our DNA. If you too want to be directly involved, grow in a stimulating and caring environment, feel useful on a daily basis and develop or strengthen your expertise, you will feel right at home with us! Still hesitating? You should know that our employees can dedicate several days per year to solidarity actions during their working hours, including sponsoring people struggling with their orientation or professional integration, participating in the financial education of young apprentices, and sharing their skills with charities. There are many ways to get involved. We are committed to support accelerating our Group’s ESG strategy by implementing ESG principles in all our activities and policies. They are translated in our business activity (ESG assessment, reporting, project management or IT activities), our work environment and in our responsible practices for environment protection.