الوصف الوظيفي
المهمة :
حول المنصب
كجزء من تعزيز فريق إدارة الهوية والوصول، نبحث عن مسؤول Active Directory من المستوى 2 (L2) لضمان تشغيل وإدارة وصيانة خدمات Active Directory.
ستؤدي دوراً رئيسياً في إدارة بيئة AD اليومية، مع تطبيق المعمارية والمعايير الأمنية والحوكمة المحددة من قبل فرق المستوى 3 (L3).
مسؤولياتك الرئيسية
إدارة Active Directory
• إدارة دورة حياة كائنات Active Directory (المستخدمون، المجموعات، الحواسيب).
• إدارة اشتراكات المجموعات، بما في ذلك المجموعات الحساسة والمميزة.
• التأكد من الالتزام بمسميات دقيقة وتناسق الدليل وتنظيف العمليات.
• تنفيذ الطلبات القياسية عبر أدوات ITSM.
• تطبيق الأذونات والسياسات وعمليات سير العمل المعتمدة.
الإدارة التشغيلية لـ GPOs
• إنشاء وتعديل وحذف وربط سياسات المجموعة (GPOs).
• مراقبة وت verification تطبيقها الصحيح على أجهزة العمل.
• ضمان الاتساق التشغيلي لـ GPOs.
• إجراء التشخيص وحل/incidents الشائعة المتعلقة بـ GPOs.
• تنفيذ عمليات النشر المعتمدة من فرق L3.
تشغيل بيئات Tier 0
• إدارة وحدات التحكم بالنطاق وDNS وPKI وEntra ID Connect بما يتوافق مع قواعد الأمان.
• إجراء تحديثات النظام، اختبارات الصحة، إعادة تشغيل الخدمات، وتحليل السجلات.
• مراقبة أداء وتوافر وحدات التحكم بالنطاق.
• تنفيذ عمليات النسخ الاحتياطي والاستعادة.
• المشاركة في عمليات إدارة DNS المفوضة.
إدارة الحوادث والدعم المستوى 2
• حل الحوادث المتعلقة ب:
o المصادقة وقفل الحسابات؛
o انتشار عضوية المجموعة؛
o مشكلات DNS؛
o تكرار AD الشائع؛
o حوادث GPO؛
o مزامنة Entra ID Connect؛
o مشاكل انضمام النطاق;
RODC البنى التحتية
• إجراء تحليل لسبب الجذر وتصعيد الحوادث المعقدة إلى فرق L3.
الامتثال والأمن والحوكمة
• ضمان الامتثال لقواعد حوكمة IAM وإجراءات التغيير.
• الالتزام بمبادئ الأمان وفصل الامتيازات والوصول من Tier 0.
• توثيق التدخلات والحوادث والتغييرات التي تم إجراؤها.
• الإسهام في التحسين المستمر لإجراءات التشغيل.
المتطلبة :
الملف الشخصي المطلوب
المهارات التقنية:
• خبرة راسخة في إدارة Microsoft Active Directory.
• الإتقان بالأدوات التالية:
o Active Directory Users and Computers (ADUC)
o Active Directory Administration Center (ADAC)
o Group Policy Management Console (GPMC)
o DNS Manager
o PowerShell
• معرفة جيدة ببروتوكولات المصادقة: Kerberos، LDAP، NTLM.
• خبرة في تشخيص مشكلات المصادقة والتكرار وDNS.
• معرفة تشغيلية بخدمات وحدة التحكم بالنطاق.
• مهارة في تشغيل وحل مشاكل GPOs.
• خبرة مع Microsoft Entra ID Connect.
الصفات الشخصية:
• الدقة والمهارات التنظيمية.
• الالتزام الصارم بالإجراءات ومتطلبات الأمان.
• مهارات تحليلية ممتازة وحل الحوادث.
• اتصال جيد وروح العمل الجماعي.
• القدرة على العمل تحت الضغط وإدارة الأولويات.
• وعي قوي بقضايا الأمن السيبراني وهوية الإدارة.
Job description
Job :
About the position
As part of strengthening our Identity & Access Management team, we are looking for a Level 2 (L2) Active Directory Administrator to ensure the operation, administration, and maintenance of Active Directory services.
You will play a key role in the daily management of the AD environment, while applying the architecture, security, and governance standards defined by the Level 3 (L3) teams.
Your main responsibilities
Active Directory Administration
• Manage the lifecycle of Active Directory objects (users, groups, computers).
• Administer group memberships, including sensitive and privileged groups.
• Ensure compliance with naming conventions, directory consistency, and cleanup operations.
• Execute standard requests via ITSM tools.
• Apply validated permissions, policies, and workflows.
Operational Management of GPOs
• Create, modify, delete, and link Group Policies (GPOs).
• Monitor and validate their correct application on workstations.
• Ensure the operational consistency of GPOs.
• Perform diagnostics and resolution of common incidents related to GPOs.
• Implement deployments approved by L3 teams.
Operation of Tier 0 environments
• Administer domain controllers, DNS, PKI, and Entra ID Connect in compliance with security rules.
• Perform system updates, health checks, service restarts, and log analysis.
• Monitor the performance and availability of Domain Controllers.
• Execute backup and restore operations.
• Participate in delegated DNS administration operations.
Incident Management and Level 2 Support
• Resolve incidents related to:
o authentication and account lockouts;
o group membership propagation;
o DNS issues;
o common AD replications;
o GPO incidents;
o Entra ID Connect synchronizations;
o domain join problems;
RODC Infrastructures
• Perform root cause analysis and escalate complex incidents to L3 teams.
Compliance, Security, and Governance
• Ensure compliance with IAM governance rules and change procedures.
• Ensure adherence to security principles, separation of privileges, and Tier 0 access.
• Document interventions, incidents, and changes made.
• Contribute to the continuous improvement of operational procedures.
Required profile :
Profile sought
Technical skills:
• Solid expertise in Microsoft Active Directory administration.
• Proficiency with tools:
o Active Directory Users and Computers (ADUC)
o Active Directory Administration Center (ADAC)
o Group Policy Management Console (GPMC)
o DNS Manager
o PowerShell
• Good knowledge of authentication protocols: Kerberos, LDAP, NTLM.
• Experience in diagnosing authentication, replication, and DNS issues.
• Operational knowledge of Domain Controller services.
• Proficiency in operating and troubleshooting GPOs.
• Experience with Microsoft Entra ID Connect.
Personal qualities:
• Rigor and organizational skills.
• Strict adherence to procedures and security requirements.
• Excellent analytical and incident resolution skills.
• Good communication and teamwork spirit.
• Ability to work under pressure and manage priorities.
• Strong awareness of cybersecurity and identity management issues.