Systems Admin Sr

Stefanini North America and APAC

Philippines

On-site

PHP 1,200,000 - 1,800,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Stefanini North America and APAC is seeking an experienced Active Directory lead to design, implement, and manage complex AD environments across on-premises and cloud. You will enforce GPOs, lead migrations, and collaborate with InfoSec for RBAC and security baselines.

The role focuses on hybrid identity solutions including Azure AD Connect and ADFS, with strong emphasis on documentation and mentoring of junior engineers.

Qualifications

  • 7+ years hands-on experience with Microsoft Active Directory in a large-scale enterprise.
  • Expertise in ADDS, DNS, DHCP, DFS, and GPO management.
  • Strong knowledge of Kerberos, LDAP, NTLM and authentication mechanisms.
  • Experience with hybrid cloud environments and identity federation.
  • Microsoft certifications strongly preferred (ID Admin Associate, MCSE).

Responsibilities

  • Serve as technical expert and escalation point for AD incidents and requests.
  • Design, implement, and manage complex AD environments including forests, trusts, and replication.
  • Maintain and enforce GPOs with auditing and lifecycle management.
  • Ensure security/compliance of AD environments through reviews, hardening, and monitoring.
  • Lead AD upgrades, migrations, and DR planning.
  • Mentor junior team members and provide knowledge sharing.
  • Collaborate with InfoSec/IAM to implement RBAC and security baselines.
  • Support Azure AD Connect and ADFS hybrid identity solutions.
  • Document architecture and operational procedures.

Skills

RBAC
Privileged identity management
Azure AD integration
PowerShell scripting
Azure CLI
DNS management
AD health monitoring tools
Azure AD Connect

Education

Microsoft Certified: Identity and Access Administrator Associate
MCSE

Tools

Azure AD Connect
Quest Change Auditor
AD health monitoring tools

Job description

Job Description
Job Responsibilities
  • Serve as the technical expert and escalation point for all Active Directory-related incidents and requests.
  • Design, implement, and manage complex AD environments including forests, domains, trusts, and replication.
  • Maintain and enforce Group Policy Objects (GPOs), including creation, auditing, and lifecycle management.
  • Ensure the security and compliance of AD environments through regular reviews, hardening, and monitoring.
  • Maintaining Group Policy Objects (GPOs), including creation, testing, deployment, and documentation.
  • Design, manage, and troubleshoot AD Sites and Services
  • Plan and implement site topology, subnet mapping, replication schedules and bridgehead server configuration.
  • Ensure DNS and AD environments are secure. highly available and compliant.
  • Support hybrid identity solutions such as Azure AD Connect and ADFS.
  • Troubleshoot and resolve replication issues, authentication failures, and DNS-related problems.
  • Collaborate with InfoSec and IAM teams to implement RBAC, privileged access management, and security baselines.
  • Lead AD upgrades, migrations, consolidations, and DR planning.
  • Maintain documentation of AD infrastructure, policies, and procedures.
  • Mentor junior team members and provide knowledge sharing and training.
  • Act as Second Level Liaison between client and service provider.
  • Define, write, and maintain PPM (Process and Procedure Manual) for the project
  • Assigned special projects
  • Analyze systems, review and implement improvements or upgrades to enhance user experience and to prevent capacity issues
  • Participate in rotating On-Call schedule and assist in after-hours Monthly Maintenance
  • Primary Lead in training and mentoring less-experienced members of the team.
  • Primary Lead in assigned special projects.
Identity And Access Management Mastery
  • Extensive experience in designing and implementing complex identity and access management solutions, including RBAC, access governance, and privileged identity management (PIM).
  • Proficiency in integrating Azure AD with various Microsoft and non-Microsoft services, including Azure, Office 365, and third-party applications.
Directory Services
  • In-depth knowledge of directory synchronization methods, including Azure AD Connect and Azure AD Domain Services.
  • Experience in architecting and managing complex directory structures for multi-domain and multi-forest environments.
Scripting And Automation Skills
  • Proficiency in scripting and automation with PowerShell, Azure CLI, or other relevant tools for Azure AD management and reporting.
Communication And Documentation
  • Excellent communication skills, including the ability to communicate complex technical concepts to non-technical stakeholders.

Strong documentation skills for creating comprehensive architectural and operational documentation.

Job Requirements
  • 7+ years of hands-on experience with Microsoft Active Directory in a large-scale enterprise environment.
  • Expertise in:
    • ADDS, DNS, DHCP, DFS, and GPO management
    • Kerberos, LDAP, NTLM, and authentication mechanisms
    • AD replication and health monitoring tools
  • Strong knowledge of Windows Server (2016/2019/2022).
  • Strong experience in troubleshooting AD replication and authentication across multi-site environment.
  • Experience with PowerShell scripting and automation for AD tasks.
  • Familiarity with security best practices for Active Directory.
  • Experience integrating AD with enterprise tools (e.g., MIM, Azure AD, ADFS, Okta, Duo).
  • Solid understanding of change management, ITIL processes, and incident escalation procedures.
  • Microsoft certifications (e.g., Microsoft Certified: Identity and Access Administrator Associate, MCSE, etc.)
  • Experience with hybrid cloud environments and identity federation.
  • Familiarity with auditing tools such as Quest Change Auditor or similar.
  • Knowledge of Active Directory disaster recovery and backup strategies.
  • Experience with DNS management tools and IPAM.
  • Experience supporting DNS in hybrid and cloud environments
  • Experience in AD disaster recovery, DNS failover, and high availability setups.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Systems Admin, Sr
Systems Admin, Sr

Stefanini, Inc • Pasay

On-site
PHP 1,400,000 - 2,600,000
Junior Active Directory Administrator
Junior Active Directory Administrator

The AM3 Global Singapore/USA • Muntinlupa

On-site
Sr. Active Directory Engineer
Sr. Active Directory Engineer

Hrtx • Cebu City

On-site
PHP 1,200,000 - 1,600,000
Jr. Active Directory
Jr. Active Directory

UPTC • Muntinlupa

On-site
PHP 240,000 - 420,000
Sr Project Lead-Cloud & Infra Engg
Sr Project Lead-Cloud & Infra Engg

Birlasoft • Hinoba-an

On-site
PHP 792,000 - 1,452,000
Windows Lead
Windows Lead

Tata Consultancy Services • Philippines

On-site
PHP 900,000 - 1,500,000
Microsoft 365 Security & Identity Administrator
Microsoft 365 Security & Identity Administrator

Tata Consultancy Services • Philippines

On-site
PHP 800,000 - 1,200,000
Active Directory Administrator (Mid Level)
Active Directory Administrator (Mid Level)

GECO Asia Pte Ltd • Muntinlupa

Hybrid
PHP 350,000 - 550,000
Senior Active Directory & IAM Lead
Senior Active Directory & IAM Lead

Stefanini, Inc • Pasay

Hybrid
PHP 1,400,000 - 2,600,000
Senior Infrastructure Engineer
Senior Infrastructure Engineer

Ascendion • Philippines

On-site
PHP 1,004,000 - 1,562,000