Job Title: Senior Identity & Access Management Professional
Project Duration: 12 Months
Job location: WAYZATA, MN
Job Summary
We are seeking a Senior Identity & Access Management professional with extensive hands‑on experience in Microsoft Active Directory to design, engineer, secure, and modernize a large-scale enterprise identity environment.
This role will focus on Active Directory infrastructure, security, automation, cloud integration, and modernization. The ideal candidate will have strong experience managing complex enterprise AD environments and applying modern engineering practices such as Infrastructure as Code, CI/CD, and automation.
Key Responsibilities
- Design, engineer, operate, secure, and maintain Microsoft Active Directory environments.
- Manage Active Directory forests, domains, trusts, Organizational Units, Group Policy, and Domain Controllers.
- Monitor, troubleshoot, and resolve issues related to authentication, replication, DNS, Domain Controller availability, account lifecycle, and access.
- Partner with IAM and PAM teams to support privileged access controls, delegated administration, and administrative group structures.
- Support integrations between Active Directory and identity governance, access request, authentication, and access certification platforms.
- Develop integration patterns between Active Directory and AWS environments using LDAP and Kerberos authentication.
- Establish application authentication patterns that leverage Kerberos where appropriate.
- Modernize existing Active Directory infrastructure through automation and engineering best practices.
- Develop and maintain automation using tools such as Ansible, Terraform, Chef, or similar technologies.
- Implement Infrastructure as Code and CI/CD practices for identity infrastructure and operations.
- Create and maintain technical standards, runbooks, and operational documentation.
- Participate in change management, incident response, audits, and continuous improvement initiatives.
- Support global, multi-domain, and multi-region Active Directory environments.
Required Qualifications
- Extensive hands‑on experience administering Microsoft Active Directory in large, complex enterprise environments.
- Strong knowledge of Active Directory architecture, including forests, domains, trusts, Group Policy, Organizational Units, and Domain Controllers.
- Strong understanding of Active Directory security, delegation models, and privileged group management.
- Experience troubleshooting authentication, replication, DNS, account lifecycle, and access‑related issues.
- Experience working with Active Directory as part of an enterprise IAM ecosystem.
- Experience integrating Active Directory with Identity Governance and Administration and/or Privileged Access Management platforms.
- Experience with AWS Active Directory implementations, including AWS Managed Microsoft AD, self‑hosted Active Directory, or similar solutions.
- Experience developing or supporting authentication integrations using LDAP and Kerberos.
- Experience supporting global, multi- domain, or multi-region Active Directory environments.
- Hands‑on experience with Infrastructure as Code, CI/CD, and automation.
- Experience with automation tools such as Ansible, Terraform, Chef, or similar technologies.
- Proven experience modernizing and transforming existing Active Directory environments using automation and modern engineering practices.
Preferred Profile
The ideal candidate is a senior Active Directory or IAM professional with a strong combination of enterprise identity expertise and modern software engineering skills. Candidates should demonstrate a proven ability to transform traditional Active Directory environments through automation, Infrastructure as Code, CI/CD, and cloud integration.