Senior Active Directory Engineer

Alnafitha International for Information Technology

Riyadh

On-site

SAR 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual leave in accordance with KSA labor law
Overtime compensation for work outside normal hours

Job summary

Alnafitha International for Information Technology is looking for a Senior Active Directory Engineer to manage operations and support a major identity change initiative for a banking client in Saudi Arabia. You will ensure stability and compliance of the Active Directory environment while managing proactive remediation and security hardening activities.

The ideal candidate should possess strong expertise in Active Directory and PowerShell, and be experienced in troubleshooting security incidents. This role requires collaboration with global offices and the ability to operate in a dynamic production environment.

Qualifications

  • 5+ years of hands-on experience administering enterprise Active Directory environments.
  • Experience in banking or regulated sectors.
  • Ability to operate within change management in a 24/7 production environment.

Responsibilities

  • Monitor Active Directory health and perform daily health checks.
  • Participate in joint planning with global teams for major changes.
  • Diagnose and resolve AD-related incidents and perform root cause analysis.

Skills

Active Directory Domain Services
PowerShell scripting
DNS management
Kerberos authentication
Group Policy

Education

Bachelor’s degree in Computer Science or related field

Tools

ADMT
Quest Migration Manager
SIEM platforms (Splunk, Microsoft Sentinel, QRadar)

Job description

Riyadh, Saudi Arabia | Posted on 06/16/2026

Alnafitha is seekinga Senior Active Directory Engineer to deliver managed operations and to supporta major identity change initiative for a banking client in the Kingdom of SaudiArabia. Working as the on-site technical liaison between the client and theglobal office, the engineer ensures the stability, security, and compliance ofthe client’s Active Directory environment while executing planned modernizationwork (such as forest consolidation, domain migration, schema upgrades, andsecurity hardening) in parallel with business-as-usual operations.

Key Responsibilities
OperationalStability & Health Management (Daily / Weekly)
  • Monitor Active Directory health,including replication, FSMO roles, SYSVOL, event logs, and domain controllerperformance.
  • Perform daily health checks(DCDIAG, REPADMIN, NETDIAG) and carry out proactive remediation.
  • Manage DNS hygiene, includingscavenging, stale records, and DNSSEC where used.
  • Manage time synchronisation,ensuring the PDC emulator points to a reliable NTP source.
  • Ensure backup success (systemstate and full forest) and periodically test restores.
  • Apply OS, security, and ADcumulative updates during approved maintenance windows.
Support the“Change” Initiative (Project Mode, in parallel with BAU)
  • Participate in joint planning withthe global office and local bank teams to define the change (e.g., forestconsolidation, domain migration, schema upgrade, security overhaul, sitetopology redesign).
  • Deploy new domain controllers orupgrade existing ones.
  • Modify site links, subnets, andreplication schedules.
  • Restructure OUs and move objects(users, computers, groups) using tools such as ADMT, PowerShell, and Quest.
  • Implement new GPOs or refactorexisting ones.
  • Configure or reconfigure foreand domain trusts.
  • Migrate service accounts to gMSAwherever possible.
  • Perform pre-change validation in alab or staging environment.
  • Execute change during approvedmaintenance windows (nights / weekends, respecting banking hours).
  • Validate post-change health androll back if success criteria are not met.
Security &Compliance Hardening (Ongoing)
  • Maintain an AD security baselinealigned with CIS / NIST and banking regulations (FFIEC, PCI, SWIFT CSP).
  • Manage and monitor privilegedgroups (Enterprise Admins, Domain Admins, Schema Admins) for unauthorizedchanges.
  • Review and clean up stale users,computers, and service accounts monthly.
  • Enforce Kerberos AES encryption,restrict NTLM, and enable LDAP signing and channel binding.
  • Manage and rotate service accountcredentials (LAPS for local admins, gMSA for services).
  • Assist with privileged accessmanagement (PAWs, JIT, break-glass accounts).
  • Ensure audit policies forward logsto the SIEM (Splunk, Sentinel, QRadar) and investigate anomalies.
Collaborationwith the Global Office
  • Act as the technical liaisonbetween the global AD team and local bank operations.
  • Participate in weekly design /status calls with the global office during the major change initiative.
  • Translate global AD standards intolocal implementation plans.
  • Report on local environmenthealth, risks, and change progress using agreed dashboards.
  • Escalate issues requiring globaldecisions (e.g., schema changes, cross-forest trust policies).
Troubleshooting& Incident Resolution
  • Diagnose and resolve AD-relatedincidents, including authentication failures, replication breaks, GPOapplication issues, account lockouts, and Kerberos errors.
  • Perform root cause analysis andimplement permanent fixes.
  • Support application teams with ADintegration issues (SPN misconfigurations, delegation, permissions).
  • Participate in security incidentresponse where AD compromise is suspected (e.g., golden ticket, DCSyncattacks).
Documentation& Knowledge Transfer (Local team and global office)
  • Maintain living documentation: ADtopology, domain controller inventory, FSMO locations, site links, GPOinventory, privileged group memberships, and service account lists.
  • Document all changes performedduring the major change initiative, including before / after states.
  • Produce troubleshooting runbooksfor common AD issues tailored to the bank’s environment.
  • Provide training sessions forlocal junior admins and global office teams as needed.
DisasterRecovery & Business Continuity
  • Maintain and test AD forestrecovery procedures.
  • Ensure backup integrity andoff-site / air-gapped copies for ransomware resilience.
  • Participate in annual DR drillswith global and local teams.
Reporting& Metrics
  • Provide status reports to thelocal IT manager and global office as required, covering health metrics, changeprogress, security findings, incidents, and planned activities.
  • Track and report KPIs: domaincontroller uptime, replication latency, authentication success rate, backupsuccess rate, stale object reduction, and audit log coverage.
Requirements
Qualifications & Experience
  • Bachelor’s degree in ComputerScience, Information Technology, or a related field (or equivalent experience).
  • 5+ years of hands-on experienceadministering enterprise Active Directory environments, ideally in banking,financial services, or other regulated sectors.
  • Experience operating within changemanagement and approved maintenance windows in a 24/7 production environment.
Technical Skills
  • Deep expertise in Active DirectoryDomain Services, DNS, DHCP, Group Policy, and Kerberos / NTLM authentication.
  • Strong PowerShell scripting andautomation skills.
  • Hands-on experience with migrationtooling such as ADMT and Quest Migration Manager.
  • Knowledge of AD security hardening(LAPS, gMSA, tiered administration, PAW, JIT) and frameworks (CIS, NIST).
  • Familiarity with SIEM platforms(Splunk, Microsoft Sentinel, QRadar) and audit log forwarding.
  • Experience with backup / recoveryand AD forest recovery procedures.
  • Working knowledge of hybrididentity (Entra ID / Azure AD Connect) is a plus.
Certifications (Preferred)
  • Microsoft certifications (e.g.,MCSE, Identity and Access Administrator) preferred.
  • Security certifications such asSecurity+, GIAC, or CISSP are an advantage.
Core Competencies
  • Strong analytical and root-causetroubleshooting skills.
  • Clear written and verbalcommunication in English; Arabic is a plus.
  • Ability to work with global andlocal stakeholders across time zones.
  • Discretion and reliabilityappropriate to a regulated banking environment.
Working Conditions

Standard working week is Sunday toThursday during normal working hours.

Annual leave is provided inaccordance with KSA labor law.

Work required outside normalworking hours or days is treated as overtime; overtime cost is settled with themonthly invoice.

Change activities may requirenight and weekend maintenance windows, scheduled to respect banking operatinghours.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AD Engineer - Banking Identity & Security
Senior AD Engineer - Banking Identity & Security

Alnafitha International for Information Technology • Riyadh

On-site
SAR 120,000 - 150,000
Annual leave in accordance with KSA labor law
Overtime compensation for work outside normal hours
Senior Active Directory & Exchange Administrator
Senior Active Directory & Exchange Administrator

Saudi Business Machines • Al Khobar

Hybrid
Senior System Administrator (Windows) - Saudi National- Riyadh, KSA
Senior System Administrator (Windows) - Saudi National- Riyadh, KSA

DS DeepSource • Riyadh

On-site
SAR 150,000 - 190,000
Office & Operations Coordinator
Office & Operations Coordinator

FileCloud • Riyadh

On-site
SAR 60,000 - 90,000
Annual bonus
20 days PTO
Wellbeing stipend
+2
HR & Finance Administrator
HR & Finance Administrator

Celeros Flow Technology • Dammam

On-site
SAR 60,000 - 110,000
Senior Network & Email Security Engineer – Cyber Defense Specialist (5+ Years)
Senior Network & Email Security Engineer – Cyber Defense Specialist (5+ Years)

CBT • Riyadh

On-site
SAR 350,000 - 520,000
Exposure to advanced cybersecurity technologies
Strong career growth opportunities
Datacenter Manager
Datacenter Manager

The Saudi National Bank - SNB • Jeddah

On-site
SAR 300,000 - 420,000
System Administration Engineer
System Administration Engineer

Arbete Careers • Al Khobar

On-site
SAR 89,000 - 134,000
HR & Finance Administrator
HR & Finance Administrator

Celeros Flow Technology LLC • Eastern Province

On-site
SAR 67,000 - 134,000
Senior Active Directory & Exchange Admin
Senior Active Directory & Exchange Admin

Saudi Business Machines • Al Khobar

Hybrid
SAR 150,000 - 200,000