Job Description Title: Technical Consultant – EDS Department: Technology Infrastructure Services – Team: Collaboration Technology – Identity and Cloud Collaboration – Location: India – Bangalore – Reports To: Associate Director – Level: Technical Consultant
The Enterprise Directory Services (EDS) team engineers and manages solutions and infrastructure supporting Fidelity’s global enterprise directory services and identity & access management, including Microsoft Active Directory and Microsoft Entra ID.
Key Responsibilities
- BAU delivery: triage and resolve incidents, service requests, and standard changes across AD/Entra ID, PKI, AD FS, and Quest Active Roles in line with SLAs.
- Hardening & hygiene: implement Tier‑0/DC hardening, GPO governance, Kerberos/LDAP protections, Conditional Access/PIM controls, SPN/gMSA/service‑account hygiene.
- Engineering execution: build and ship changes from SME/architect designs (e.g., DC upgrades, federation tweaks, AAD Connect/Cloud Sync tasks, App Proxy integrations).
- Automation: use PowerShell and Microsoft Graph to audit, enforce, and remediate configuration; contribute to policy/config‑as‑code practices.
- Security remediation: run BloodHound/AzureHound and PingCastle collections, analyze findings, and implement agreed remediations with SMEs.
- Monitoring & ops quality: contribute to health/capacity checks, dashboards, and runbooks; document work clearly and keep records up to date.
- Change & compliance: raise change records, follow CAB processes, and align with platform standards and security product roadmaps.
- Collaboration: partner with SMEs, Operations, Network, and Security teams; participate in major‑incident support and post‑incident actions when required.
- Knowledge sharing: provide peer support and share practical know‑how (acting as a subject‑matter contributor for assigned tasks while SMEs retain ownership).
Experience & Qualifications
- Microsoft identity stack: deep experience with Active Directory and Entra ID (Azure AD), plus AD FS and Azure AD Connect; excellent knowledge of AD 2016/2019 design, troubleshooting, and administration.
- Tiering & privileged access: practical understanding of AD security concepts (Tier‑0/Tier‑1, PAWs) and lateral‑movement risks; PAW/jump pattern design and rollout.
- Active Directory hardening: CIS‑aligned DC baselines, host firewalls, and no‑Internet DC patterns.
- Entra ID controls at scale: Conditional Access (MFA/device/risk), and PIM for roles and PIM for Groups.
- GPO & identity hygiene: Tier‑0/Tier‑1 GPO design/governance, SPN hygiene, gMSA adoption, and service‑account policies (length/rotation).
- Automation‑first: PowerShell and Microsoft Graph for audits, enforcement, and remediation; KQL, Terraform, Python – policy/config‑as‑code mindset in a DevOps environment.
- Exposure tooling: hands‑on with BloodHound/AzureHound and PingCastle (collection, analysis, and driving remediation).
- Quest ecosystem: Active Roles (ARS) and Change Auditor (or equivalent) for RBAC and change/drift tracking.
- Endpoint & access management: experience with Microsoft Intune or strong understanding of MDM/MAM/Conditional Access.
- Standards & protocols: strong understanding of OAuth2/OIDC and SAML; experience with PKI/AD CS and relevant Windows security standards.
- Security principles: least privilege, separation of duties, auditability; confident engagement with InfoSec.
- Networking foundations: HTTP, SMTP, DNS, TCP/IP, proxies, and load balancers.
- Communication: clear written/verbal communication and presentation skills for technical and senior audiences.
- Process: ITIL certification (desirable) and familiarity with structured change management.
Seniority level
Mid‑Senior level
Employment type
Full‑time
Job function
Information Technology – IT Services and IT Consulting