Job description
Job :
Your mission
As a Level 3 (L3) Active Directory Architect / Administrator, you are the technical point of contact and the guarantor of the architecture, governance, and security of the Active Directory ecosystem.
You define technical standards, manage the strategic evolution of the AD environment, and handle the most critical incidents. You work closely with the IAM, Cybersecurity, Infrastructure, Network, and Workplace teams to ensure the performance, resilience, and security of the identity infrastructure.
Your main responsibilities
Architecture & Design
• Define and govern the architecture of Active Directory forests and domains.
• Design Organizational Unit (OU) structures, delegation models, and administrative boundaries.
• Define the topology of Active Directory Sites and Subnets.
• Develop deployment strategies for domain controllers (high availability, redundancy, RODC).
• Define strategies for upgrading, modernizing, and managing the lifecycle of AD environments.
• Lead the evolution of the Active Directory schema.
• Validate naming conventions for AD objects and service accounts.
Governance & Standards
• Define and maintain Active Directory operational and security standards.
• Validate configurations before production deployment.
• Lead Tier 0 administration models and privilege separation.
• Govern the architecture of GPOs and security baselines.
• Validate delegation models, ACLs, and privileged groups.
• Ensure compliance with cybersecurity and audit requirements.
Security & Risk Management
• Define and maintain the Tier 0 security posture.
• Administer and govern the Microsoft PKI infrastructure (AD CS).
• Define and implement Active Directory hardening measures:
o LDAP Signing
o SMB Signing
o Kerberos Hardening
o NTLM Restrictions
• Support security audits and remediation plans.
• Ensure the security of authentication mechanisms and trust relationships.
IAM Architecture & Hybrid Identity
• Define the Microsoft Entra ID Connect architecture.
• Ensure consistency between Active Directory and Microsoft Entra ID.
• Validate IAM provisioning flows.
• Lead identity integration and migration strategies.
• Validate changes impacting IAM synchronizations and connectors.
Critical Incident Management
Handle major and complex incidents:
• Multi-site or multi-forest replication failures.
• SYSVOL / DFS-R malfunctions.
• DNS incidents affecting authentication.
• Kerberos and delegation issues.
• Domain controller failures or unavailability.
• Critical Entra ID Connect malfunctions.
• PKI incidents and time synchronization problems.
You will conduct root cause analyses, develop corrective action plans, and implement long-term preventive measures.
Strategic Projects & Transformation
• Lead migration, carve-in, and carve-out projects.
• Design new identity architectures.
• Drive Active Directory modernization programs.
• Reduce technical debt and rationalize existing environments.
• Deploy Microsoft best practices around Zero Trust, hybrid identity, and Tier 0 security.
• Provide technical guidance to L2 operations teams.
Required profile :
Profile sought
Education
• Master's degree (Bac+5) in IT, Networks, Systems, or Cybersecurity.
• Significant experience (minimum 8 years recommended) in Active Directory administration and architecture in complex and international environments.
Technical skills
• Advanced expertise in Microsoft Active Directory Domain Services (AD DS).
• In-depth mastery of:
o FSMO
o AD Replication
o SYSVOL / DFS-R
o Active Directory Schema
o Kerberos
o LDAP / LDAPS
• Excellent knowledge of DNS, PKI, time synchronization, and network dependencies.
• Expertise in Tier 0 architectures, Tiering, and Privileged Access Workstations (PAW).
• Very good knowledge of Active Directory cybersecurity:
o Privilege Escalation
o Attack Paths
o ADCS Security
o Hardening
• Expertise in Microsoft Entra ID, Entra Connect, and hybrid architectures.
• Proficiency in PowerShell and automation.
Personal qualities
• Strategic vision and risk management-oriented approach.
• Excellent communication skills with technical teams and management.
• Technical leadership and ability to influence architectural decisions.
• Strong analytical skills and ability to solve complex problems.
• Ability to intervene effectively during critical incidents.
• Enjoy sharing knowledge and mentoring.
وصف العمل
العمل :
مهمتك
بصفتك مصمِّم/مسؤول Active Directory من المستوى 3 (L3)، أنت جهة الاتصال الفنية وضامن الهندسة والحوكمة والأمن في منظومة Active Directory.
تحدد المعايير الفنية، تدير التطوير الاستراتيجي لبيئة AD، وتتولى التعامل مع الحوادث الأكثر حرجاً. تعمل عن كثب مع فرق IAM، الأمن السيبراني، البنية التحتية، الشبكات، ومكان العمل لضمان الأداء والمرونة والأمن لبنية الهوية التحتية.
مسؤولياتك الرئيسيةالهندسة والتصميم
• تعريف وحوكمة هندسة غابات ونطاقات Active Directory.
• تصميم هياكل وحدات تنظيمية (OU)، نماذج التفويض، والحدود الإدارية.
• تعريف طوبولوجيا مواقع و subnets لـ Active Directory.
• تطوير استراتيجيات النشر لعارضات النطاق (التوافر العالي، التكرار، RODC).
• defining استراتيجيات لترقية وتحديث وإدارة دورة حياة بيئات AD.
• قيادة تطوير مخطط Active Directory.
• التحقق من تسمية كائنات AD وحسابات الخدمات.
الحوكمة والمعايير
• تعريف والحفاظ على معايير تشغيلية وأمنية لـ Active Directory.
• التحقق من التكوينات قبل النشر في الإنتاج.
• قيادة نماذج إدارة Tier 0 وفصل الامتيازات.
• حوكمة معمارية لـ GPOs وخطوط الأساس الأمنية.
• التحقق من نماذج التفويض، ACLs والمجموعات المميزة.
• ضمان الامتثال لمتطلبات الأمن السيبراني والتدقيق.
الأمن وإدارة المخاطر
• تعريف والحفاظ على وضع أمني Tier 0.
• إدارة وحوكمة بنية PKI من Microsoft (AD CS).
• تعريف وتنفيذ تدابير تعزيز أمن Active Directory:
o توقيع LDAP
o توقيع SMB
o تعزيز Kerberos
o قيود NTLM
• دعم عمليات التدقيق الأمني وخطط التصحيح.
• ضمان أمان آليات المصادقة وعلاقات الثقة.
هندسة IAM وهوية هجينة
• تعريف هندسة Microsoft Entra ID Connect.
• ضمان الاتساق بين Active Directory وMicrosoft Entra ID.
• التحقق من تدفقات توفير IAM.
• قيادة استراتيجيات تكامل الهوية والهجرة.
• التحقق من التغييرات التي تؤثر على تزامن IAM والمكونات المتصلة.
إدارة الحوادث الحرجة
التعامل مع الحوادث الكبرى والمعقدة:
• فشل التكرار عبر مواقع متعددة أو غابات متعددة.
• أعطال SYSVOL / DFS-R.
• حوادث DNS تؤثر على المصادقة.
• مشاكل Kerberos والتفويض.
• فشل أو عدم توافر وحدة تحكم النطاق.
• أعطال Entra ID Connect الحرجة.
• حوادث PKI ومشاكل مزامنة الوقت.
سوف تجري تحليلات السبب الجذري، وتطور خطط العمل التصحيحية، وتطبق إجراءات وقائية طويلة الأجل.
المشروعات الاستراتيجية والتحول
• قيادة مشاريع الهجرة، والت carve-in، و carve-out.
• تصميم هياكل هوية جديدة.
• دفع برامج تحديث Active Directory.
• تقليل التكاليف التقنية وت racionalize البيئات القائمة.
• تطبيق أفضل ممارسات Microsoft حول Zero Trust، وهوية هجينة، وأمن Tier 0.
• تقديم الإرشاد الفني لفِرَق العمليات L2.
الملف المطلوب :
الملف الشخصي المطلوب
التعليم
• درجة الماجستير ( Bac+5) في تكنولوجيا المعلومات، الشبكات، الأنظمة، أو الأمن السيبراني.
• خبرة كبيرة (ينصح بحد أدنى 8 سنوات) في إدارة Active Directory وهندسته في بيئات معقدة ودولية.
المهارات التقنية
• خبرة متقدمة في خدمات المجال Microsoft Active Directory Domain Services (AD DS).
• إتقان عميق لـ:
o FSMO
o تكرار AD
o SYSVOL / DFS-R
o مخطط Active Directory
o Kerberos
o LDAP / LDAPS
• معرفة ممتازة بـ DNS، PKI، توقيت الشبكة، واعتماديات الشبكة.
• خبرة في هندسة Tier 0، التصنيف، ومحطات الوصول المميزة (PAW).
• معرفة جيدة جدًا بأمان Active Directory:
o تصعيد الامتيازات
o مسارات الهجوم
o أمان ADCS
o التعزيز
• خبرة في Microsoft Entra ID، Entra Connect، والهندسة الهجينة.
• الإجادة في PowerShell والأتمتة.
الصفات الشخصية
• رؤية استراتيجية ونهج مركّز على إدارة المخاطر.
• مهارات تواصل ممتازة مع الفرق الفنية والإدارة.
• قيادة فنية والقدرة على التأثير في قرارات المعمارية.
• مهارات تحليلية قوية والقدرة على حل المشكلات المعقدة.
• القدرة على التدخل بفعالية أثناء الحوادث الحرجة.
• الاستمتاع بمشاركة المعرفة والتوجيه.