Microsoft Security Active Directory Senior Consultant

Deloitte France

Columbus (OH)

On-site

USD 105,000 - 208,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

DeloitteCyber seeks a Senior Engineering Management Specialist to lead Active Directory and identity infrastructure projects across assessment, design, migration, and post-implementation phases. You will steer DNS, DHCP, GP, and security hardening while coordinating enterprise AD environments with Entra ID.

The role requires 4+ years in AD engineering, strong communication, and the ability to travel up to 50%. A degree in a technical field and migration tooling experience are preferred.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, Engineering, Information Technology, or equivalent work experience.
  • 4+ years of experience in technical consulting, enterprise infrastructure, identity security, or Active Directory engineering.
  • 4+ years of hands-on experience designing, securing, assessing, migrating, or operating Microsoft Active Directory environments.
  • Experience with enterprise Active Directory services, including domain and forest architecture, domain controllers and replication, DNS, DHCP, Sites and Services, Group Policy, trusts, service accounts, LDAP, and domain or forest recovery.
  • Experience leading or supporting Active Directory domain or forest migrations, separations, or consolidations.
  • Experience with migration tooling such as Quest On Demand Migration (ODM) or Semperis migration capabilities.
  • Experience with identity threat detection, identity resilience, cyber recovery, or recovery validation tooling such as Semperis, Rubrik, or Microsoft Defender for Identity.
  • Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Responsibilities

  • Lead Active Directory and identity infrastructure engagements across assessment, design, migration, implementation, stabilization, and post-implementation phases.
  • Perform and oversee Active Directory assessments covering domain and forest architecture, domain controllers, DNS, DHCP, Sites and Services, Group Policy, trusts, and more.
  • Design and implement Active Directory security and hardening improvements, including administrative tiering and RBAC.
  • Architect and support enterprise Active Directory environments, including hybrid identity integrations with Microsoft Entra ID and federation.
  • Lead or support domain and forest migrations, separations, and consolidations, including discovery, validation, rollback, and post-migration stabilization.

Skills

Independent work
Team collaboration
Communication skills
Attention to detail
Relationship building
Project leadership
Multitasking
Interpersonal skills
Deadline driven

Education

Bachelor's degree

Tools

Quest On Demand Migration
Semperis
Microsoft Entra ID

Job description

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll doAs a Senior Engineering Management Specialist on the Deloitte Cyber team, you will be responsible for:* Leading Active Directory and identity infrastructure engagements across assessment, design, migration, implementation, stabilization, and post-implementation phases.* Performing and overseeing Active Directory assessments covering domain and forest architecture, domain controllers, Sites and Services, Domain Name System (DNS), Dynamic Host Configuration Protocol (DHCP), replication, trusts, Group Policy, privileged groups, service accounts, authentication protocols, and administrative processes.* Designing and implementing Active Directory security and hardening improvements, including administrative tiering, role-based access controls, service account management, Group Policy controls, and identity threat detection and recovery capabilities.* Architecting and supporting enterprise Active Directory environments, including hybrid identity integrations with Microsoft Entra ID, federation, synchronization services, and application dependencies.* Leading or supporting domain and forest migrations, separations, and consolidations, including discovery, dependency analysis, cutover planning, validation, rollback, and post-migration stabilization.A successful candidate would possess these skills:* Ability to work independently and collaborate as part of a team* Effective written and verbal communication skills* Meticulous attention to detail and quality of work product* Ability to build and sustain professional relationships* Ability to lead projects or workstreams* Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment* Strong interpersonal skills and professional demeanor* Ability to meet deadlines* Ability to provide clear guidance to othersThe teamDeloitte Cyber’s Digital Trust & Privacy practice helps organizations build and sustain confidence in their digital products, platforms, services, data practices, and customer experiences. Our work brings together digital trust, online protection, privacy, AI governance, identity, data protection, cybersecurity, and regulatory compliance capabilities.QualificationsRequired:* Bachelor’s degree in Computer Science, Cybersecurity, Information Security, Engineering, Information Technology, another technical field, or equivalent work experience.* 4+ years of experience in technical consulting, enterprise infrastructure, identity security, or Active Directory engineering.* 4+ years of hands-on experience designing, securing, assessing, migrating, or operating Microsoft Active Directory environments.* Experience with enterprise Active Directory services, including domain and forest architecture, domain controllers and replication, DNS, DHCP, Sites and Services, Group Policy, trusts, service accounts, Lightweight Directory Access Protocol (LDAP), and domain or forest recovery.* Experience leading or supporting Active Directory domain or forest migrations, separations, or consolidations.* Experience with migration tooling such as Quest On Demand Migration (ODM) or Semperis migration capabilities.* Experience with identity threat detection, identity resilience, cyber recovery, or recovery validation tooling such as Semperis, Rubrik, or Microsoft Defender for Identity.* Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve.* Limited immigration sponsorship may be available.Preferred:* Advanced degree in Cybersecurity, Information Technology, Engineering, or another technical field.* Experience with Active Directory security assessments, attack-path analysis, domain hardening, and privileged access management.* Experience with enterprise identity security architectures, including Enhanced Security Administrative Environment (ESAE), tiered administration, administrative forests, or privileged access workstations.* Experience supporting mergers, acquisitions, divestitures, carve-outs, spin-offs, or enterprise reorganizations involving Active Directory environments.* Experience with Microsoft Entra ID, federation, synchronization, multifactor authentication (MFA), single sign-on (SSO), or hybrid identity architectures.* Certifications such as Certified Information Systems Security Professional (CISSP), Certificate of Cloud Security Knowledge (CCSK), Microsoft SC-300, or Cisco Certified Network Associate (CCNA).The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a Senior Engineering Management Specialist on the Deloitte Cyber team, you will be responsible for:

  • Leading Active Directory and identity infrastructure engagements across assessment, design, migration, implementation, stabilization, and post-implementation phases.
  • Performing and overseeing Active Directory assessments covering domain and forest architecture, domain controllers, Sites and Services, Domain Name System (DNS), Dynamic Host Configuration Protocol (DHCP), replication, trusts, Group Policy, privileged groups, service accounts, authentication protocols, and administrative processes.
  • Designing and implementing Active Directory security and hardening improvements, including administrative tiering, role-based access controls, service account management, Group Policy controls, and identity threat detection and recovery capabilities.
  • Architecting and supporting enterprise Active Directory environments, including hybrid identity integrations with Microsoft Entra ID, federation, synchronization services, and application dependencies.
  • Leading or supporting domain and forest migrations, separations, and consolidations, including discovery, dependency analysis, cutover planning, validation, rollback, and post-migration stabilization.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

The team

Deloitte Cyber’s Digital Trust & Privacy practice helps organizations build and sustain confidence in their digital products, platforms, services, data practices, and customer experiences. Our work brings together digital trust, online protection, privacy, AI governance, identity, data protection, cybersecurity, and regulatory compliance capabilities.

Qualifications

Required:

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Security, Engineering, Information Technology, another technical field, or equivalent work experience.
  • 4+ years of experience in technical consulting, enterprise infrastructure, identity security, or Active Directory engineering.
  • 4+ years of hands-on experience designing, securing, assessing, migrating, or operating Microsoft Active Directory environments.
  • Experience with enterprise Active Directory services, including domain and forest architecture, domain controllers and replication, DNS, DHCP, Sites and Services, Group Policy, trusts, service accounts, Lightweight Directory Access Protocol (LDAP), and domain or forest recovery.
  • Experience leading or supporting Active Directory domain or forest migrations, separations, or consolidations.
  • Experience with migration tooling such as Quest On Demand Migration (ODM) or Semperis migration capabilities.
  • Experience with identity threat detection, identity resilience, cyber recovery, or recovery validation tooling such as Semperis, Rubrik, or Microsoft Defender for Identity.
  • Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Advanced degree in Cybersecurity, Information Technology, Engineering, or another technical field.
  • Experience with Active Directory security assessments, attack-path analysis, domain hardening, and privileged access management.
  • Experience with enterprise identity security architectures, including Enhanced Security Administrative Environment (ESAE), tiered administration, administrative forests, or privileged access workstations.
  • Experience supporting mergers, acquisitions, divestitures, carve-outs, spin-offs, or enterprise reorganizations involving Active Directory environments.
  • Experience with Microsoft Entra ID, federation, synchronization, multifactor authentication (MFA), single sign-on (SSO), or hybrid identity architectures.
  • Certifications such as Certified Information Systems Security Professional (CISSP), Certificate of Cloud Security Knowledge (CCSK), Microsoft SC-300, or Cisco Certified Network Associate (CCNA).

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Operate SOC L2 Analyst - Senior Consultant
Cyber Operate SOC L2 Analyst - Senior Consultant

Deloitte France • New York (NY)

Hybrid
USD 105,000 - 208,000
Cyber Operate SOC L2 Analyst - Senior Consultant
Cyber Operate SOC L2 Analyst - Senior Consultant

Deloitte France • United States

On-site
USD 105,000 - 208,000
Network Engineer - Senior
Network Engineer - Senior

Deloitte France • Colorado Springs (CO)

On-site
USD 116,000 - 194,000
Cyber Security & Risk Strategy Senior Consultant
Cyber Security & Risk Strategy Senior Consultant

Deloitte France • Wichita (KS)

On-site
USD 105,000 - 208,000
Cyber Security & Risk Strategy Senior Consultant
Cyber Security & Risk Strategy Senior Consultant

Deloitte France • Detroit (MI)

On-site
USD 105,000 - 208,000
Cyber Security & Risk Strategy Senior Consultant
Cyber Security & Risk Strategy Senior Consultant

Deloitte France • Houston (TX)

On-site
USD 105,000 - 208,000
Cyber Security & Risk Strategy Senior Consultant
Cyber Security & Risk Strategy Senior Consultant

Deloitte France • Atlanta (GA)

On-site
USD 105,000 - 208,000
Discretionary annual incentive program
Intermediate Level Maintenance SME, Strategy, Growth, and Transformation, Senior Consultant
Intermediate Level Maintenance SME, Strategy, Growth, and Transformation, Senior Consultant

Deloitte France • United States

On-site
USD 103,000 - 171,000
Discretionary annual incentive program
Microsoft 365 Security Manager
Microsoft 365 Security Manager

Deloitte France • Memphis (TN)

Hybrid
USD 135,000 - 265,000
Microsoft 365 Security Manager
Microsoft 365 Security Manager

Deloitte France • Chicago (IL)

On-site
USD 135,000 - 265,000