Active Directory Architect / Administrator Level 3 (L3) M/F - Sala Al Jadida

HR professions - Secteur Recruitment / Interim

  • Senior (5 to 10 years)
  • 1 job(s) in Rabat and region - Morocco
  • Bachelor (BA, BSc) Minimum - University

Search for new things / novelty Extraversion Need for objectivity Need for autonomy Involvement at work

  • Permanent contract
  • Teleworking : Hybrid
Posted 15 days ago on ReKrute.com - Apply before 20/09/2026

Company :

The Econocom group, founded 50 years ago, was a pioneer in supporting companies in their digital transformation.

Econocom provides, finances, and manages services for workspaces, audiovisual, and infrastructure. This includes purchasing equipment, configuration and customization, maintenance and repair, refurbishment, and end-user support.

Present in 16 countries with over 8,680 employees, Econocom achieved a revenue of 2.9 billion euros in 2025.

The group is listed on Euronext Brussels and is part of the Tech Leaders and Family Business indices. The Rabat (Morocco) center, an operational hub for Econocom's Services' European Remote Services Center, is tasked with providing effective customer support to existing accounts and contributing to acquiring new clients.


Job :

Your mission

As a Level 3 (L3) Active Directory Architect / Administrator, you are the technical point of contact and the guarantor of the architecture, governance, and security of the Active Directory ecosystem.
You define technical standards, manage the strategic evolution of the AD environment, and handle the most critical incidents. You work closely with the IAM, Cybersecurity, Infrastructure, Network, and Workplace teams to ensure the performance, resilience, and security of the identity infrastructure.

Your main responsibilities

Architecture & Design

• Define and govern the architecture of Active Directory forests and domains.
• Design Organizational Unit (OU) structures, delegation models, and administrative boundaries.
• Define the topology of Active Directory Sites and Subnets.
• Develop deployment strategies for domain controllers (high availability, redundancy, RODC).
• Define strategies for upgrading, modernizing, and managing the lifecycle of AD environments.
• Lead the evolution of the Active Directory schema.
• Validate naming conventions for AD objects and service accounts.

Governance & Standards

• Define and maintain Active Directory operational and security standards.
• Validate configurations before production deployment.
• Lead Tier 0 administration models and privilege separation.
• Govern the architecture of GPOs and security baselines.
• Validate delegation models, ACLs, and privileged groups.
• Ensure compliance with cybersecurity and audit requirements.

Security & Risk Management

• Define and maintain the Tier 0 security posture.
• Administer and govern the Microsoft PKI infrastructure (AD CS).
• Define and implement Active Directory hardening measures:
o LDAP Signing
o SMB Signing
o Kerberos Hardening
o NTLM Restrictions
• Support security audits and remediation plans.
• Ensure the security of authentication mechanisms and trust relationships.

IAM Architecture & Hybrid Identity

• Define the Microsoft Entra ID Connect architecture.
• Ensure consistency between Active Directory and Microsoft Entra ID.
• Validate IAM provisioning flows.
• Lead identity integration and migration strategies.
• Validate changes impacting IAM synchronizations and connectors.

Critical Incident Management

Handle major and complex incidents:

• Multi-site or multi-forest replication failures.
• SYSVOL / DFS-R malfunctions.
• DNS incidents affecting authentication.
• Kerberos and delegation issues.
• Domain controller failures or unavailability.
• Critical Entra ID Connect malfunctions.
• PKI incidents and time synchronization problems.

You will conduct root cause analyses, develop corrective action plans, and implement long-term preventive measures.

Strategic Projects & Transformation

• Lead migration, carve-in, and carve-out projects.
• Design new identity architectures.
• Drive Active Directory modernization programs.
• Reduce technical debt and rationalize existing environments.
• Deploy Microsoft best practices around Zero Trust, hybrid identity, and Tier 0 security.
• Provide technical guidance to L2 operations teams.
 


Required profile :

Profile sought

Education

• Master's degree (Bac+5) in IT, Networks, Systems, or Cybersecurity.
• Significant experience (minimum 8 years recommended) in Active Directory administration and architecture in complex and international environments.

Technical skills

• Advanced expertise in Microsoft Active Directory Domain Services (AD DS).
• In-depth mastery of:
o FSMO
o AD Replication
o SYSVOL / DFS-R
o Active Directory Schema
o Kerberos
o LDAP / LDAPS
• Excellent knowledge of DNS, PKI, time synchronization, and network dependencies.
• Expertise in Tier 0 architectures, Tiering, and Privileged Access Workstations (PAW).
• Very good knowledge of Active Directory cybersecurity:
o Privilege Escalation
o Attack Paths
o ADCS Security
o Hardening
• Expertise in Microsoft Entra ID, Entra Connect, and hybrid architectures.
• Proficiency in PowerShell and automation.

Personal qualities

• Strategic vision and risk management-oriented approach.
• Excellent communication skills with technical teams and management.
• Technical leadership and ability to influence architectural decisions.
• Strong analytical skills and ability to solve complex problems.
• Ability to intervene effectively during critical incidents.
• Enjoy sharing knowledge and mentoring.

 

Desired personality traits :

Search for new things / novelty Extraversion Need for objectivity Need for autonomy Involvement at work

4K
Matching global
N/A
N/A
FineTunePro
SKILLS
N/A
Kapacity Revealer
PERSONALITY
N/A
Feel Good
CULTURE

Here you can find a recommendation rate for this vacancy, as well as information on how to promote your application. Log in / Register to view this personalised information.

ReKrute offers you this new personality test to help you get to know yourself better and make the most of your applications. Take it now, it only takes 5 minutes maximum.