Search for new things / novelty Extraversion Need for objectivity Need for autonomy Involvement at work
The group is a leading international player in supporting companies in their digital transformation.
Your mission
As an Active Directory Architect / Administrator Level 3 (L3), you are the technical point of contact and the guarantor of the architecture, governance, and security of the Active Directory ecosystem.
You define technical standards, manage the strategic evolution of the AD environment, and handle the most critical incidents. You work closely with the IAM, Cybersecurity, Infrastructure, Network, and Workplace teams to ensure the performance, resilience, and security of the identity infrastructure.
Your main responsibilities
Architecture & Design
• Define and govern the architecture of Active Directory forests and domains.
• Design Organizational Unit (OU) structures, delegation models, and administrative boundaries.
• Define the Active Directory Sites and Subnets topology.
• Develop deployment strategies for domain controllers (high availability, redundancy, RODC).
• Define strategies for upgrading, modernizing, and lifecycle management of AD environments.
• Manage the evolution of the Active Directory schema.
• Validate naming conventions for AD objects and service accounts.
Governance and Standards
• Define and maintain Active Directory operational and security standards.
• Validate configurations before they go into production.
• Manage Tier 0 administration models and privilege separation.
• Govern the architecture of GPOs and security baselines.
• Validate delegation models, ACLs, and privileged groups.
• Ensure compliance with cybersecurity and audit requirements.
Security & Risk Management
• Define and maintain the Tier 0 security posture.
• Administer and govern the Microsoft PKI infrastructure (AD CS).
• Define and implement Active Directory hardening measures:
o LDAP Signing
o SMB Signing
o Kerberos Hardening
o NTLM Restrictions
• Support security audits and remediation plans.
• Ensure the security of authentication mechanisms and trust relationships.
IAM Architecture & Hybrid Identity
• Define the Microsoft Entra ID Connect architecture.
• Ensure consistency between Active Directory and Microsoft Entra ID.
• Validate IAM provisioning flows.
• Manage identity integration and migration strategies.
• Validate changes affecting IAM synchronizations and connectors.
Critical Incident Management
Handle major and complex incidents:
• Multi-site or multi-forest replication failures.
• SYSVOL / DFS-R malfunctions.
• Incidents with DNS impact on authentication.
• Kerberos and delegation issues.
• Domain controller failures or unavailability.
• Entra ID Connect malfunctions.
• PKI incidents and time synchronization problems.
You will ensure root cause analysis, corrective action plans, and long-term preventive measures.
Strategic Projects & Transformation
• Manage migration, carve-in, and carve-out projects.
• Design new identity architectures.
• Lead Active Directory modernization programs.
• Reduce technical debt and rationalize existing environments.
• Deploy Microsoft best practices around Zero Trust, hybrid identity, and Tier 0 security.
• Technically supervise L2 operations teams.
Profile sought
Education
• Master's degree (Bac+5) in Computer Science, Networks, Systems, or Cybersecurity.
• Significant experience (minimum 8 years recommended) in Active Directory administration and architecture in complex and international environments.
Technical skills
• Advanced expertise in Microsoft Active Directory Domain Services (AD DS).
• In-depth mastery of:
o FSMO
o AD Replication
o SYSVOL / DFS-R
o Active Directory Schema
o Kerberos
o LDAP / LDAPS
o NTLM
• Excellent understanding of DNS, PKI, time synchronization, and network dependencies.
• Expertise in Tier 0, Tiering, and Privileged Access Workstations (PAW) architectures.
• Very good knowledge of Active Directory cybersecurity:
o Privilege Escalation
o Attack Paths
o ADCS Security
o Hardening
• Expertise in Microsoft Entra ID, Entra Connect, and hybrid architectures.
• Mastery of PowerShell and automation.
Personal qualities
• Strategic vision and risk management-oriented approach.
• Excellent communication skills with technical teams and management.
• Technical leadership and ability to influence architectural decisions.
• Strong analytical and complex problem-solving skills.
• Ability to intervene effectively during critical incidents.
• Enjoy knowledge sharing and mentoring.
Search for new things / novelty Extraversion Need for objectivity Need for autonomy Involvement at work
Here you can find a recommendation rate for this vacancy, as well as information on how to promote your application. Log in / Register to view this personalised information.
ReKrute offers you this new personality test to help you get to know yourself better and make the most of your applications. Take it now, it only takes 5 minutes maximum.