Senior Active Directory L3 Engineer (Enterprise Identity & AD Engineering)

Visible Stars Company

Riyadh

On-site

SAR 280,000 - 420,000

Full time

10 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Visible Stars Company in Riyadh seeks a Senior Active Directory L3 Engineer to lead enterprise AD design, forests, domains, OU structures, and AD sites. You will oversee domain controllers lifecycle, migrations, and high-availability strategies.

Responsibilities include Core AD Services, GPO engineering, Identity & Access Management, Federation & SSO, Hybrid Identity with Entra ID, Conditional Access, MFA, and security hardening. Must have 8–12+ years and banking/regulatory familiarity.

Qualifications

  • 8–12+ years of experience in Active Directory engineering and support.
  • Strong expertise in AD architecture (multi-domain/forest environments).
  • Hands-on experience with forest migrations and carve-outs (must-have).
  • Deep knowledge of AD DS, DNS, replication, FSMO roles; GPO design and troubleshooting.

Responsibilities

  • AD Architecture & Engineering: design, build, and manage AD forests, domains, and OU structures; define AD Sites, Subnets, and replication topology; manage domain controllers lifecycle; lead forest carve-out, consolidation, and migration initiatives; design high availability and disaster recovery strategies.
  • Core AD Services: manage and troubleshoot AD DS, DNS (AD-integrated), DHCP (where applicable); handle replication issues, latency optimization, site link tuning; maintain FSMO roles and proper role placement.
  • GPO Engineering: design, implement, optimize Group Policy strategy; troubleshoot inheritance, filtering, conflicts; implement security baselines using GPOs; manage GPO lifecycle (versioning, backup, rollback).
  • Identity & Access Management: manage user/service account lifecycle; implement RBAC and least privilege models; integrate AD with enterprise IAM solutions; support LDAP, Kerberos, NTLM authentication mechanisms.
  • Federation & SSO: design and manage Active Directory Federation Services; configure claims-based authentication; enable SSO across enterprise and third-party apps; troubleshoot federation, token, and claims issues.
  • Hybrid Identity & Cloud Integration: integrate on-prem AD with Microsoft Entra ID; manage Entra Connect synchronization; implement Conditional Access, MFA, identity protection; support hybrid identity architecture and cloud authentication models.
  • Security & Hardening: implement AD security best practices; PAM; AD hardening; monitor and respond to identity-based threats; support banking/regulatory compliance; periodic AD health checks and security assessments.
  • Automation & Scripting: develop automation using PowerShell for AD operations; automate provisioning, reporting, monitoring; maintain scripts for audit/compliance.
  • Monitoring, Audits & Compliance: monitor AD, ADFS, Entra ID health and performance; support audits and compliance reporting; maintain architecture docs/runbooks.
  • L3 Support & Incident Management: act as escalation point for complex AD issues; RCA for critical incidents; ensure SLA adherence in high-availability banking environment.

Skills

AD Architecture
GPO design
RBAC
PowerShell
Identity & Access
Federation Services
Hybrid Identity
Entra ID
AD DS
Troubleshooting

Tools

Entra Connect

Job description

Senior Active Directory L3 Engineer (Enterprise Identity & AD Engineering)

Riyadh

  • Job Type: full-time
  • Category: SYS
  • Post Date: 19/05/2026
Job Description

Key Responsibilities1. AD Architecture & Engineering� Design, build, and manage Active Directory forests, domains, and OU structures� Define and maintain AD Sites, Subnets, and replication topology� Manage domain controllers lifecycle (build, patching, decommissioning)� Lead AD forest carve-out, consolidation, and migration initiatives� Design high availability and disaster recovery strategies2. Core AD Services� Manage and troubleshoot:o AD DS (Domain Services)o DNS (AD-integrated)o DHCP (where applicable)� Handle replication issues, latency optimization, and site link tuning� Maintain FSMO roles and ensure proper role placement3. Group Policy (GPO) Engineering� Design, implement, and optimize Group Policy strategy� Troubleshoot complex GPO inheritance, filtering, and conflicts� Implement security baselines using GPOs� Manage GPO lifecycle (versioning, backup, rollback)4. Identity & Access Management� Manage user and service account lifecycle (JML processes)� Implement RBAC and least privilege models� Integrate AD with enterprise IAM solutions� Support LDAP, Kerberos, NTLM authentication mechanisms5. Federation & SSO� Design and manage Active Directory Federation Services infrastructure� Configure claims-based authentication and trust relationships� Enable SSO across enterprise and third-party applications� Troubleshoot federation, token, and claims issues6. Hybrid Identity & Cloud Integration� Integrate on-prem AD with Microsoft Entra ID� Manage Entra Connect (Azure AD Connect) synchronization� Implement Conditional Access, MFA, and identity protection� Support hybrid identity architecture and cloud authentication models7. Security & Hardening� Implement AD security best practices:o Tiered administration modelo Privileged Access Management (PAM)o AD hardening and attack surface reduction� Monitor and respond to identity-based threats� Support compliance with banking and regulatory standards� Perform periodic AD health checks and security assessments8. Automation & Scripting� Develop automation using PowerShell for AD operations� Automate provisioning, reporting, and monitoring tasks� Maintain scripts for audit, compliance, and operational efficiency9. Monitoring, Audits & Compliance� Monitor AD, ADFS, and Entra ID health and performance� Support internal/external audits and compliance reporting� Maintain detailed documentation (architecture, SOPs, runbooks)10. L3 Support & Incident Management� Act as escalation point for complex AD issues� Perform root cause analysis (RCA) for critical incidents� Ensure SLA adherence in a high-availability banking environment______________Required Skills & Experience� 8�12+ years of experience in Active Directory engineering and support� Strong expertise in AD architecture (multi-domain/forest environments)� Hands-on experience with forest migrations and carve-outs (must-have)� Deep knowledge of:o AD DS, DNS, replication, FSMO roleso GPO design and troubleshootingo Authentication protocols (Kerberos, NTLM, SAML, OAuth, OIDC)� Strong experience with:o Active Directory Federation Serviceso Microsoft Entra ID (Hybrid Identity)� Advanced PowerShell scripting skills� Experience in Windows Server environments (2016/2019/2022)______________Preferred Qualifications� Experience in banking or highly regulated industries� Exposure to Zero Trust and identity security frameworks� Experience with:o Privileged Identity Management (PIM)o Identity Governance tools� Relevant certifications:o Microsoft Certified: Identity and Access Administratoro Microsoft Azure / Entra certifications______________Key Competencies� Strong engineering mindset (not just operations)� Ability to work independently and drive ownership� Strong troubleshooting and RCA skills� Effective communication with technical and business stakeholders

Job qualifications:

Key Competencies� Strong engineering mindset (not just operations)� Ability to work independently and drive ownership� Strong troubleshooting and RCA skills� Effective communication with technical and business stakeholders
Job Description

Key Responsibilities1. AD Architecture & Engineering� Design, build, and manage Active Directory forests, domains, and OU structures� Define and maintain AD Sites, Subnets, and replication topology� Manage domain controllers lifecycle (build, patching, decommissioning)� Lead AD forest carve-out, consolidation, and migration initiatives� Design high availability and disaster recovery strategies2. Core AD Services� Manage and troubleshoot:o AD DS (Domain Services)o DNS (AD-integrated)o DHCP (where applicable)� Handle replication issues, latency optimization, and site link tuning� Maintain FSMO roles and ensure proper role placement3. Group Policy (GPO) Engineering� Design, implement, and optimize Group Policy strategy� Troubleshoot complex GPO inheritance, filtering, and conflicts� Implement security baselines using GPOs� Manage GPO lifecycle (versioning, backup, rollback)4. Identity & Access Management� Manage user and service account lifecycle (JML processes)� Implement RBAC and least privilege models� Integrate AD with enterprise IAM solutions� Support LDAP, Kerberos, NTLM authentication mechanisms5. Federation & SSO� Design and manage Active Directory Federation Services infrastructure� Configure claims-based authentication and trust relationships� Enable SSO across enterprise and third-party applications� Troubleshoot federation, token, and claims issues6. Hybrid Identity & Cloud Integration� Integrate on-prem AD with Microsoft Entra ID� Manage Entra Connect (Azure AD Connect) synchronization� Implement Conditional Access, MFA, and identity protection� Support hybrid identity architecture and cloud authentication models7. Security & Hardening� Implement AD security best practices:o Tiered administration modelo Privileged Access Management (PIM)o AD hardening and attack surface reduction� Monitor and respond to identity-based threats� Support compliance with banking and regulatory standards� Perform periodic AD health checks and security assessments8. Automation & Scripting� Develop automation using PowerShell for AD operations� Automate provisioning, reporting, and monitoring tasks� Maintain scripts for audit, compliance, and operational efficiency9. Monitoring, Audits & Compliance� Monitor AD, ADFS, and Entra ID health and performance� Support internal/external audits and compliance reporting� Maintain detailed documentation (architecture, SOPs, runbooks)10. L3 Support & Incident Management� Act as escalation point for complex AD issues� Perform root cause analysis (RCA) for critical incidents� Ensure SLA adherence in a high-availability banking environment______________Required Skills & Experience� 8�12+ years of experience in Active Directory engineering and support� Strong expertise in AD architecture (multi-domain/forest environments)� Hands-on experience with forest migrations and carve-outs (must-have)� Deep knowledge of:o AD DS, DNS, replication, FSMO roleso GPO design and troubleshootingo Authentication protocols (Kerberos, NTLM, SAML, OAuth, OIDC)� Strong experience with:o Active Directory Federation Serviceso Microsoft Entra ID (Hybrid Identity)� Advanced PowerShell scripting skills� Experience in Windows Server environments (2016/2019/2022)______________Preferred Qualifications� Experience in banking or highly regulated industries� Exposure to Zero Trust and identity security frameworks� Experience with:o Privileged Identity Management (PIM)o Identity Governance tools� Relevant certifications:o Microsoft Certified: Identity and Access Administratoro Microsoft Azure / Entra certifications______________Key Competencies� Strong engineering mindset (not just operations)� Ability to work independently and drive ownership� Strong troubleshooting and RCA skills� Effective communication with technical and business stakeholders

Job qualifications:

Key Competencies� Strong engineering mindset (not just operations)� Ability to work independently and drive ownership� Strong troubleshooting and RCA skills� Effective communication with technical and business stakeholders
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Active Directory L3 Engineer (Enterprise Identity & AD Engineering)
Senior Active Directory L3 Engineer (Enterprise Identity & AD Engineering)

Visible Stars, Inc. • Riyadh

On-site
SAR 240,000 - 360,000
Senior Active Directory Engineer
Senior Active Directory Engineer

Alnafitha International for Information Technology • Riyadh

On-site
SAR 120,000 - 150,000
Annual leave in accordance with KSA labor law
Overtime compensation for work outside normal hours
Senior Enterprise AD & Identity Architect
Senior Enterprise AD & Identity Architect

Visible Stars Company • Riyadh

On-site
SAR 280,000 - 420,000
Senior AD Architect & IAM Engineer (L3)
Senior AD Architect & IAM Engineer (L3)

Visible Stars, Inc. • Riyadh

On-site
SAR 240,000 - 360,000
Senior System Engineer
Senior System Engineer

Nextwo Co. • Riyadh

On-site
SAR 300,000 - 520,000
Active Directory & MS Exchange Administrator (L2) | Trio Telecom | Riyadh, Saudi Arabia
Active Directory & MS Exchange Administrator (L2) | Trio Telecom | Riyadh, Saudi Arabia

Trio Services • Riyadh

On-site
SAR 180,000 - 320,000
Senior Enterprise Consultant – Microsoft Active Directory & Exchange Infrastructure (Onsite)
Senior Enterprise Consultant – Microsoft Active Directory & Exchange Infrastructure (Onsite)

SoftwareOne • Riyadh

On-site
SAR 300,000 - 420,000
Global culture
Mentor support
President’s Club
+2
Senior System Administrator (Windows) - Saudi National- Riyadh, KSA
Senior System Administrator (Windows) - Saudi National- Riyadh, KSA

DS DeepSource • Riyadh

On-site
SAR 150,000 - 190,000
Senior System Administrator (Windows) - Saudi National- Riyadh, KSA at DeepSource Technologies
Senior System Administrator (Windows) - Saudi National- Riyadh, KSA at DeepSource Technologies

DeepSource Technologies • Riyadh

On-site
SAR 300,000 - 420,000
Windows System Administrator (L1 & L2) | Cyber Subnet | Jeddah, Saudi Arabia
Windows System Administrator (L1 & L2) | Cyber Subnet | Jeddah, Saudi Arabia

Tech Junction Ltd • Jeddah

On-site
SAR 96,000 - 168,000