About the job Active Directory Service Manager
Job Title: Active Directory Manager
Location: [Insert Location]
Department: IT / Infrastructure
Reports to: IT Director / Infrastructure Manager
Job Type: Full-Time
Remote Option: [Specify if applicable]
Job Summary
We are seeking a skilled and proactive Active Directory (AD) Manager to oversee and manage the enterprise Active Directory environment, including design, maintenance, policy enforcement, and security. The ideal candidate will play a key role in identity and access management (IAM), ensuring stability, scalability, and integrity of the directory infrastructure across all business units.
Key Responsibilities
-
Lead and manage the operation, maintenance, and security of the organizations Active Directory environment.
-
Plan, design, and implement AD architecture changes and upgrades.
-
Develop and enforce Group Policy Objects (GPOs), organizational units (OUs), and access control policies.
-
Maintain AD forests, domains, trusts, and domain controllers across on-premises and hybrid environments (e.g., Azure AD).
-
Ensure high availability, disaster recovery, and replication integrity.
-
Collaborate with cybersecurity teams to implement IAM best practices, security hardening, and compliance.
-
Oversee integration of AD with other systems (e.g., Exchange, Office 365, applications).
-
Manage privileged access, service accounts, and audit logs.
-
Lead a small team of directory services engineers (if applicable).
-
Maintain thorough documentation and change management procedures.
Requirements
Required:
-
Bachelors degree in Computer Science, Information Systems, or related field.
-
5+ years of experience managing Active Directory in a large enterprise environment.
-
Strong expertise with:
-
Active Directory and Group Policy
-
DNS/DHCP in relation to AD
-
Azure AD / Hybrid Identity
-
LDAP, Kerberos, SAML, OAuth
-
-
PowerShell scripting and automation of AD tasks.
-
Understanding of Zero Trust security models and IAM best practices.
Preferred:
-
Microsoft certifications (e.g., MS-100, AZ-104, SC-300, or older MCSA/MCSE).
-
Experience with ADFS, MFA, conditional access, and identity governance.
-
Familiarity with tools like Quest, Okta, or SailPoint.