Senior Active Directory L3 Engineer (Enterprise Identity & AD Engineering)

Visible Stars, Inc.

Riyadh

On-site

SAR 240,000 - 360,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Visible Stars, Inc. in Riyadh is seeking a Senior Active Directory L3 Engineer to lead architecture, design, and operation of AD forests, domains, and hybrid integrations. The role focuses on AD services, GPO engineering, identity & access management, federation & SSO, and security hardening within a high-availability enterprise environment.

Strong scripting and ownership are essential. Excellent communication with security, IT Ops, and business stakeholders, and experience with Entra

Qualifications

  • 8–12+ years of Active Directory engineering and support experience.
  • Deep knowledge of AD DS, DNS, replication and FSMO roles.
  • Experience with forest migrations or carve-outs and IAM integrations.

Responsibilities

  • Design, build, and manage AD forests, domains, and OU structures.
  • Design and implement GPOs and security baselines; manage rollback and backups.
  • Integrate on-prem AD with hybrid identity (Entra ID) and implement Conditional Access.

Skills

AD engineering
PowerShell scripting
Hybrid Identity
RBAC
GPO design

Tools

AD DS
DNS
DHCP
Entra ID
Azure AD Connect
ADFS

Job description

Senior Active Directory L3 Engineer (Enterprise Identity & AD Engineering)

Riyadh

  • Job Type: full-time
  • Category: SYS
  • Post Date: 19/05/2026
Job Description

Key Responsibilities1. AD Architecture & Engineering� Design, build, and manage Active Directory forests, domains, and OU structures� Define and maintain AD Sites, Subnets, and replication topology� Manage domain controllers lifecycle (build, patching, decommissioning)� Lead AD forest carve-out, consolidation, and migration initiatives� Design high availability and disaster recovery strategies2. Core AD Services� Manage and troubleshoot:o AD DS (Domain Services)o DNS (AD-integrated)o DHCP (where applicable)� Handle replication issues, latency optimization, and site link tuning� Maintain FSMO roles and ensure proper role placement3. Group Policy (GPO) Engineering� Design, implement, and optimize Group Policy strategy� Troubleshoot complex GPO inheritance, filtering, and conflicts� Implement security baselines using GPOs� Manage GPO lifecycle (versioning, backup, rollback)4. Identity & Access Management� Manage user and service account lifecycle (JML processes)� Implement RBAC and least privilege models� Integrate AD with enterprise IAM solutions� Support LDAP, Kerberos, NTLM authentication mechanisms5. Federation & SSO� Design and manage Active Directory Federation Services infrastructure� Configure claims-based authentication and trust relationships� Enable SSO across enterprise and third-party applications� Troubleshoot federation, token, and claims issues6. Hybrid Identity & Cloud Integration� Integrate on-prem AD with Microsoft Entra ID� Manage Entra Connect (Azure AD Connect) synchronization� Implement Conditional Access, MFA, and identity protection� Support hybrid identity architecture and cloud authentication models7. Security & Hardening� Implement AD security best practices:o Tiered administration modelo Privileged Access Management (PAM)o AD hardening and attack surface reduction� Monitor and respond to identity-based threats� Support compliance with banking and regulatory standards� Perform periodic AD health checks and security assessments8. Automation & Scripting� Develop automation using PowerShell for AD operations� Automate provisioning, reporting, and monitoring tasks� Maintain scripts for audit, compliance, and operational efficiency9. Monitoring, Audits & Compliance� Monitor AD, ADFS, and Entra ID health and performance� Support internal/external audits and compliance reporting� Maintain detailed documentation (architecture, SOPs, runbooks)10. L3 Support & Incident Management� Act as escalation point for complex AD issues� Perform root cause analysis (RCA) for critical incidents� Ensure SLA adherence in a high-availability banking environment______________Required Skills & Experience� 8�12+ years of experience in Active Directory engineering and support� Strong expertise in AD architecture (multi-domain/forest environments)� Hands-on experience with forest migrations and carve-outs (must-have)� Deep knowledge of:o AD DS, DNS, replication, FSMO roleso GPO design and troubleshootingo Authentication protocols (Kerberos, NTLM, SAML, OAuth, OIDC)� Strong experience with:o Active Directory Federation Serviceso Microsoft Entra ID (Hybrid Identity)� Advanced PowerShell scripting skills� Experience in Windows Server environments (2016/2019/2022)______________Preferred Qualifications� Experience in banking or highly regulated industries� Exposure to Zero Trust and identity security frameworks� Experience with:o Privileged Identity Management (PIM)o Identity Governance tools� Relevant certifications:o Microsoft Certified: Identity and Access Administratoro Microsoft Azure / Entra certifications______________Key Competencies� Strong engineering mindset (not just operations)� Ability to work independently and drive ownership� Strong troubleshooting and RCA skills� Effective communication with technical and business stakeholders

Job qualifications:

Key Competencies� Strong engineering mindset (not just operations)� Ability to work independently and drive ownership� Strong troubleshooting and RCA skills� Effective communication with technical and business stakeholders
Job Description

Key Responsibilities1. AD Architecture & Engineering� Design, build, and manage Active Directory forests, domains, and OU structures� Define and maintain AD Sites, Subnets, and replication topology� Manage domain controllers lifecycle (build, patching, decommissioning)� Lead AD forest carve-out, consolidation, and migration initiatives� Design high availability and disaster recovery strategies2. Core AD Services� Manage and troubleshoot:o AD DS (Domain Services)o DNS (AD-integrated)o DHCP (where applicable)� Handle replication issues, latency optimization, and site link tuning� Maintain FSMO roles and ensure proper role placement3. Group Policy (GPO) Engineering� Design, implement, and optimize Group Policy strategy� Troubleshoot complex GPO inheritance, filtering, and conflicts� Implement security baselines using GPOs� Manage GPO lifecycle (versioning, backup, rollback)4. Identity & Access Management� Manage user and service account lifecycle (JML processes)� Implement RBAC and least privilege models� Integrate AD with enterprise IAM solutions� Support LDAP, Kerberos, NTLM authentication mechanisms5. Federation & SSO� Design and manage Active Directory Federation Services infrastructure� Configure claims-based authentication and trust relationships� Enable SSO across enterprise and third-party applications� Troubleshoot federation, token, and claims issues6. Hybrid Identity & Cloud Integration� Integrate on-prem AD with Microsoft Entra ID� Manage Entra Connect (Azure AD Connect) synchronization� Implement Conditional Access, MFA, and identity protection� Support hybrid identity architecture and cloud authentication models7. Security & Hardening� Implement AD security best practices:o Tiered administration modelo Privileged Access Management (PIM)o AD hardening and attack surface reduction� Monitor and respond to identity-based threats� Support compliance with banking and regulatory standards� Perform periodic AD health checks and security assessments8. Automation & Scripting� Develop automation using PowerShell for AD operations� Automate provisioning, reporting, and monitoring tasks� Maintain scripts for audit, compliance, and operational efficiency9. Monitoring, Audits & Compliance� Monitor AD, ADFS, and Entra ID health and performance� Support internal/external audits and compliance reporting� Maintain detailed documentation (architecture, SOPs, runbooks)10. L3 Support & Incident Management� Act as escalation point for complex AD issues� Perform root cause analysis (RCA) for critical incidents� Ensure SLA adherence in a high-availability banking environment______________Required Skills & Experience� 8�12+ years of experience in Active Directory engineering and support� Strong expertise in AD architecture (multi-domain/forest environments)� Hands-on experience with forest migrations and carve-outs (must-have)� Deep knowledge of:o AD DS, DNS, replication, FSMO roleso GPO design and troubleshootingo Authentication protocols (Kerberos, NTLM, SAML, OAuth, OIDC)� Strong experience with:o Active Directory Federation Serviceso Microsoft Entra ID (Hybrid Identity)� Advanced PowerShell scripting skills� Experience in Windows Server environments (2016/2019/2022)______________Preferred Qualifications� Experience in banking or highly regulated industries� Exposure to Zero Trust and identity security frameworks� Experience with:o Privileged Identity Management (PIM)o Identity Governance tools� Relevant certifications:o Microsoft Certified: Identity and Access Administratoro Microsoft Azure / Entra certifications______________Key Competencies� Strong engineering mindset (not just operations)� Ability to work independently and drive ownership� Strong troubleshooting and RCA skills� Effective communication with technical and business stakeholders

Job qualifications:

Key Competencies� Strong engineering mindset (not just operations)� Ability to work independently and drive ownership� Strong troubleshooting and RCA skills� Effective communication with technical and business stakeholders
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Active Directory L3 Engineer (Enterprise Identity & AD Engineering)
Senior Active Directory L3 Engineer (Enterprise Identity & AD Engineering)

Visible Stars Company • Riyadh

On-site
SAR 280,000 - 420,000
Senior Active Directory Engineer
Senior Active Directory Engineer

Alnafitha International for Information Technology • Riyadh

On-site
SAR 120,000 - 150,000
Annual leave in accordance with KSA labor law
Overtime compensation for work outside normal hours
Senior Enterprise AD & Identity Architect
Senior Enterprise AD & Identity Architect

Visible Stars Company • Riyadh

On-site
SAR 280,000 - 420,000
Senior AD Architect & IAM Engineer (L3)
Senior AD Architect & IAM Engineer (L3)

Visible Stars, Inc. • Riyadh

On-site
SAR 240,000 - 360,000
Senior System Engineer
Senior System Engineer

Nextwo Co. • Riyadh

On-site
SAR 300,000 - 520,000
Active Directory & MS Exchange Administrator (L2) | Trio Telecom | Riyadh, Saudi Arabia
Active Directory & MS Exchange Administrator (L2) | Trio Telecom | Riyadh, Saudi Arabia

Trio Services • Riyadh

On-site
SAR 180,000 - 320,000
Senior Enterprise Consultant – Microsoft Active Directory & Exchange Infrastructure (Onsite)
Senior Enterprise Consultant – Microsoft Active Directory & Exchange Infrastructure (Onsite)

SoftwareOne • Riyadh

On-site
SAR 300,000 - 420,000
Global culture
Mentor support
President’s Club
+2
Senior System Administrator (Windows) - Saudi National- Riyadh, KSA
Senior System Administrator (Windows) - Saudi National- Riyadh, KSA

DS DeepSource • Riyadh

On-site
SAR 150,000 - 190,000
Windows System Administrator (L1 & L2) | Cyber Subnet | Jeddah, Saudi Arabia
Windows System Administrator (L1 & L2) | Cyber Subnet | Jeddah, Saudi Arabia

Tech Junction Ltd • Jeddah

On-site
SAR 96,000 - 168,000
Senior System Administrator (Windows) - Saudi National- Riyadh, KSA at DeepSource Technologies
Senior System Administrator (Windows) - Saudi National- Riyadh, KSA at DeepSource Technologies

DeepSource Technologies • Riyadh

On-site
SAR 300,000 - 420,000