Senior/Lead Active Directory Engineer

N-iX

Warszawa

Hybrid

PLN 279,000 - 390,600

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible working format
Competitive salary and compensation package
Personalized career growth
Education reimbursement
Corporate events and team buildings

Job summary

A leading technology firm is seeking a skilled Senior/Lead Active Directory Engineer to join their team in Warsaw, Poland. This senior role involves assessing and enhancing Active Directory environments while ensuring security hardening and compliance with industry standards. The ideal candidate will have extensive experience with Active Directory, Group Policies, and IAM integrations, along with strong skills in automation and documentation. The role offers flexible working options and a competitive compensation package.

Qualifications

  • Minimum of 7+ years of hands-on experience with Active Directory engineering.
  • Proven track record of AD clean-up, consolidation, and integration.
  • Experience working within regulated environments like PCI DSS.

Responsibilities

  • Conduct assessments of current AD environments with security enhancements.
  • Remediate inactive objects and align policies with best practices.
  • Integrate AD with enterprise IAM platforms and optimize configurations.

Skills

Active Directory engineering
Group Policy design
Active Directory security hardening
Identity integration
Troubleshooting legacy configurations
PowerShell scripting
Audit and compliance standards
Authentication protocols
Reverse engineering legacy permissions
DNS management

Education

Upper-intermediate English level

Tools

ADUC
ADSIEdit
Group Policy Management Console
PowerShell (AD module)

Job description

N-iX is looking for a skilled Senior/Lead Active Directory Engineer to join our team! Our customer is the European online car market with over 30 million monthly users, with a market presence in 18 countries. As a Lead Active Directory Engineer, you will play a pivotal role in shaping the future of online car markets and enhancing the user experience for millions of car buyers and sellers. We require a Lead Engineer to assess, clean up, and harden multiple inherited single‑forest, single‑domain Active Directory environments. These environments require standardization, security hardening, and alignment with current best practices. The focus will be on improving AD structure, security posture, Group Policy hygiene, and operational consistency, while also evaluating long‑term viability and integration with enterprise IAM platforms. This is a hands‑on senior role requiring deep expertise in Active Directory architecture, security, identity integration, and remediation of legacy configurations, including alignment with industry audit and compliance standards (e.g., PCI DSS).

Requirements
  • EDT Timezone work hours
  • Extensive hands‑on experience (typically 7+ years) with Active Directory engineering and administration.
  • Proven experience performing AD clean‑up, consolidation, or post‑transition integration work.
  • Strong expertise in: Active Directory (single‑domain environments at scale), Group Policy design, cleanup, and optimization, OU design and delegation models.
  • Demonstrated experience with: AD security hardening (tiered admin model, least privilege, attack surface reduction), identifying and remediating stale objects (users, computers, groups), legacy permissions and misconfigurations, GPO sprawl and conflicts.
  • Experience integrating Active Directory with IAM/IdP platforms, including: Azure AD / Entra ID - must have, Okta - nice to have, etc, SSO, federation, and identity synchronization (e.g., AAD Connect or equivalent), role‑based access control (RBAC) and identity lifecycle management.
  • Experience working within regulated or audited environments, including: PCI DSS (or similar frameworks such as ISO 27001, NIST).
  • Implementing controls related to identity, access management, and auditability.
  • Strong knowledge of: Authentication protocols (Kerberos, NTLM, SAML/OIDC basics), DNS (AD‑integrated), replication, and site topology.
  • Experience with tools such as: ADUC, ADSIEdit, Group Policy Management Console, PowerShell (AD module - must have) for bulk changes and reporting.
  • Experience in auditing and improving privileged access (Domain Admins, Enterprise Admins), service accounts and delegation.
  • At least upper‑intermediate English level.
Responsibilities
  • Perform a comprehensive assessment of current AD environments.
  • Identify and remediate inactive/stale objects, legacy groups and excessive permissions, GPO duplication, conflicts, and inefficiencies.
  • Redesign and implement an OU structure and delegation model, and Group Policy strategy aligned to best practices.
  • Implement security hardening measures, including a privileged access model (e.g., tiering), reduction of attack surface and legacy protocols.
  • Align with audit/compliance requirements (e.g., PCI DSS controls).
  • Integrate AD environments with enterprise IAM platforms, including identity synchronization and federation, access model alignment (RBAC / least privilege), SSO enablement and identity lifecycle processes.
  • Review and optimize AD Sites and Services (replication topology), DNS configuration and health.
  • Develop and execute cleanup and remediation plans with minimal disruption.
  • Automate tasks and reporting using PowerShell.
  • Produce clear documentation and operational standards, including audit‑ready configurations.
Nice‑to‑Have Certifications
  • Microsoft Certified: Windows Server Hybrid Administrator Associate
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • Microsoft Certified: Azure Solutions Architect Expert
  • MCSA / MCSE (legacy but relevant)
  • Security certifications (e.g., CISSP, Security+, CISM)
  • Okta Certified Professional / Administrator (or similar IAM certifications)
We offer
  • Flexible working format – remote, office‑based or flexible
  • A competitive salary and good compensation package
  • Personalized career growth
  • Professional development tools (mentorship program, tech talks and trainings, centers of excellence, and more)
  • Active tech communities with regular knowledge sharing
  • Education reimbursement
  • Memorable anniversary presents
  • Corporate events and team buildings
  • Other location‑specific benefits
  • Not applicable for freelancers
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Active Directory (AD) L3 Administrator
Active Directory (AD) L3 Administrator

Ubique Systems • Województwo pomorskie

On-site
PLN 90,000 - 130,000
Active Directory Administrator (L3 Support)
Active Directory Administrator (L3 Support)

MPower Plus • Województwo pomorskie

Hybrid
PLN 70,000 - 90,000
Lead DevOps Engineer (AWS Migration & Security)
Lead DevOps Engineer (AWS Migration & Security)

N-iX • Poland

Hybrid
PLN 210,000 - 320,000
Flexible format
Career growth
Mentorship & training
+4
Junior Consultant - Active Directory & Entra ID Expert
Junior Consultant - Active Directory & Entra ID Expert

Ernst & Young Advisory Services Sdn Bhd • Województwo mazowieckie

Hybrid
PLN 60,000 - 80,000
Private healthcare
Career Counseling
Hybrid work model
Junior Consultant - Active Directory & Entra ID Expert
Junior Consultant - Active Directory & Entra ID Expert

EY • Wrocław

Hybrid
Professional support for certifications
Private healthcare
Mental health consultations
Senior AI Platform Engineer
Senior AI Platform Engineer

N-iX • Kraków

Hybrid
PLN 260,000 - 380,000
Flexible working format
Competitive salary
Career growth
+1
Senior AI Platform Engineer
Senior AI Platform Engineer

N-iX • Warszawa

Hybrid
PLN 180,000 - 300,000
Flexible remote/work format
Competitive salary
Career growth
+3
Active Directory Admin
Active Directory Admin

MPower Plus • Województwo pomorskie

Hybrid
PLN 90,000 - 130,000
Senior/Lead Software Engineer
Senior/Lead Software Engineer

Addepto • Wrocław

On-site
Flexible work arrangements
Career paths and knowledge-sharing initiatives
20 fully paid days off
+3
Senior IAM/PAM Engineer — Hybrid MFA & AD Expert
Senior IAM/PAM Engineer — Hybrid MFA & AD Expert

DCG Poland • Poland

On-site
PLN 120,000 - 180,000