Job description
Job :
About the position
As part of strengthening our Identity & Access Management team, we are looking for an Active Directory Administrator Level 2 (L2) responsible for ensuring the operation, administration, and maintenance of Active Directory services.
You will play a key role in the daily management of the AD environment, while applying the architecture, security, and governance standards defined by Level 3 (L3) teams.
Your main tasks
Active Directory Administration
• Manage the lifecycle of Active Directory objects (users, groups, computers).
• Administer group memberships, including sensitive and privileged groups.
• Ensure compliance with naming conventions, directory consistency, and cleanup operations.
• Execute standard requests via ITSM tools.
• Apply validated permissions, policies, and workflows.
Operational management of GPOs
• Create, modify, delete, and link Group Policies (GPOs).
• Monitor and validate their correct application on workstations.
• Ensure operational consistency of GPOs.
• Perform diagnosis and resolution of common incidents related to GPOs.
• Implement deployments approved by L3 teams.
Operation of Tier 0 environments
• Administer domain controllers, DNS, PKI, and Entra ID Connect in compliance with security rules.
• Perform system updates, health checks, service restarts, and log analysis.
• Monitor the performance and availability of Domain Controllers.
• Execute backup and restore operations.
• Participate in delegated DNS administration operations.
Incident management and Level 2 support
• Resolve incidents related to:
o authentication and account lockouts;
o propagation of group memberships;
o DNS issues;
o common AD replications;
o GPO incidents;
o Entra ID Connect synchronizations;
o domain join problems;
RODC Infrastructures
• Perform root cause analysis and escalate complex incidents to L3 teams.
Compliance, security, and governance
• Ensure compliance with IAM governance rules and change procedures.
• Ensure adherence to security principles, separation of privileges, and Tier 0 access.
• Document interventions, incidents, and changes made.
• Contribute to the continuous improvement of operating procedures.
Required profile :
Profile sought
Technical skills:
• Solid expertise in Microsoft Active Directory administration.
• Proficiency in tools:
o Active Directory Users and Computers (ADUC)
o Active Directory Administration Center (ADAC)
o Group Policy Management Console (GPMC)
o DNS Manager
o PowerShell
• Good knowledge of authentication protocols: Kerberos, LDAP, NTLM.
• Experience in diagnosing authentication, replication, and DNS issues.
• Operational knowledge of Domain Controller services.
• Proficiency in operating and troubleshooting GPOs.
• Experience with Microsoft Entra ID Connect.
Personal qualities:
• Rigor and organizational skills.
• Strict adherence to procedures and security requirements.
• Excellent analytical and incident resolution skills.
• Good communication and teamwork.
• Ability to work under pressure and manage priorities.
• Strong sensitivity to cybersecurity and identity management issues.
وصف الوظيفة
الوظيفة:
حول المنصب
بالإضافة إلى تعزيز فريق الهوية وإدارة الوصول لدينا، نحن نبحث عن مدير Active Directory المستوى 2 (L2) مسؤول عن ضمان تشغيل وصيانة خدمات Active Directory.
سوف تلعب دوراً رئيسياً في الإدارة اليومية لبيئة AD، مع تطبيق المعمارية والمعايير الأمنية والحوكمة التي حددها فرق المستوى 3 (L3).
المهام الرئيسية الخاصة بك
إدارة Active Directory
• إدارة دورة حياة كائنات Active Directory (المستخدمين، المجموعات، أجهزة الكمبيوتر).
• إدارة عضويات المجموعات، بما في ذلك المجموعات الحساسة والممنوحة امتيازات.
• ضمان الامتثال لاتفاقيات التسمية وتناسق الدليل وعمليات التنظيف.
• تنفيذ الطلبات القياسية عبر أدوات ITSM.
• تطبيق الأذونات والسياسات وعمليات سير العمل المعتمدة.
الإدارة التشغيلية لـ GPOs
• إنشاء وتعديل وحذف وربط سياسات المجموعة (GPOs).
• مراقبة وتحقق من تطبيقها الصحيح على أجهزة العمل.
• ضمان اتساق تشغيل GPOs.
• إجراء تشخيص وحل للمشاكل الشائعة المرتبطة بـ GPOs.
• تنفيذ عمليات النشر المعتمدة من فرق L3.
تشغيل بيئات Tier 0
• إدارة وحدات تحكم المجال وDNS وPKI وEntra ID Connect بما يتوافق مع قواعد الأمان.
• إجراء تحديثات النظام وفحص الصحة وإعادة تشغيل الخدمات وتحليل السجلات.
• مراقبة أداء وتوفر وحدات التحكم بالنطاق.
• تنفيذ عمليات النسخ الاحتياطي والاستعادة.
• المشاركة في عمليات إدارة DNS المفوضة.
إدارة الحوادث والدعم المستوى 2
• حل الحوادث المرتبطة بـ:
o المصادقة وقفل الحسابات؛
o انتشار عضويات المجموعات؛
o مشاكل DNS؛
o تكرار AD الشائع؛
o حوادث GPO؛
o مزامنة Entra ID Connect؛
o مشاكل الانضمام للنطاق;
RODC البنى التحتية
• إجراء تحليل لأسباب الجذرية وتصعيد الحوادث المعقدة إلى فرق L3.
الامتثال، الأمن والحوكمة
• ضمان الامتثال لقواعد حوكمة IAM وإجراءات التغيير.
• ضمان الالتزام بمبادئ الأمان، وفصل الامتيازات، والوصول من Tier 0.
• توثيق التدخلات والحوادث والتغييرات التي تمت.
• الإسهام في التحسين المستمر لإجراءات التشغيل.
الملف المطلوب :
الملف الشخصي المطلوب
المهارات التقنية:
• خبرة متينة في إدارة Microsoft Active Directory.
• الكفاءة في الأدوات:
o Active Directory Users and Computers (ADUC)
o Active Directory Administration Center (ADAC)
o Group Policy Management Console (GPMC)
o DNS Manager
o PowerShell
• معرفة جيدة ببروتوكولات المصادقة: Kerberos وLDAP وNTLM.
• خبرة في تشخيص مشاكل المصادقة والتكرار وDNS.
• معرفة تشغيلية بخدمات وحدات تحكم النطاق.
• كفاءة في تشغيل واستكشاف GPOs.
• خبرة مع Microsoft Entra ID Connect.
الصفات الشخصية:
• الدقة والمهارات التنظيمية.
• الالتزام الصارم بالإجراءات والمتطلبات الأمنية.
• مهارات تحليلية وحل حوادث ممتازة.
• قدرة على التواصل والعمل ضمن فريق.
• القدرة على العمل تحت الضغط وإدارة الأولويات.
• حس قوي تجاه قضايا الأمن السيبراني وإدارة الهوية.