
Active Directory Architect
Posted Jul 23

Posted Jul 23
This is a fully remote position, open to applicants in Texas.
• Evaluate the existing state of the client's Active Directory and Azure/Entra ID setup, which includes forest design, site design, domain design, security group topology, deployment architecture, organizational unit (“OU”) design, authentication, and group policy design.
• Execute PowerShell queries against the client's Active Directory to gather pertinent statistics on current AD and Azure objects, such as users, accounts, groups, organizational units (OUs), computer objects, and associated identity objects.
• Utilize SailPoint out-of-the-box reports to analyze AD connectivity, providing information about group and account ownership and membership.
• Examine AD configurations, processes, and documentation to gain insights into the client's existing deployment and operational model.
• Identify configuration and operational deficiencies within the client's AD domains, infrastructure, architecture, and deployment.
• Rank identified deficiencies by their criticality and associated risks.
• Offer recommendations for addressing significant gaps and risks across AD and Entra ID environments.
• Investigate and evaluate current processes related to AD group management, AD group policy management, and AD account management.
• Propose adjustments and enhancements to existing processes and develop new processes as necessary.
• Assess the resources and skills required to execute remediation activities and achieve specified milestones.
• Provide a projected budget to implement remediation as outlined during the assessment phases.
• Utilize client tools such as ADUC (Active Directory Users & Computers), ManageEngine, StealthAUDIT, or other AD scanning utilities as needed for data-gathering activities.
• Extensive experience as an Active Directory Architect, including domain consolidation, AD assessment, and enterprise identity infrastructure evaluation.
• Practical knowledge of Active Directory forest, site, domain, OU, security group, authentication, and group policy design.
• Experience in evaluating Azure/Entra ID deployments and hybrid identity environments.
• Capability to execute and interpret PowerShell queries against AD domains to collect statistics on users, accounts, groups, OUs, computer objects, and related AD/Azure entities.
• Familiarity with SailPoint reports for analyzing AD group and account ownership and membership.
• Ability to recognize configuration and operational deficiencies and prioritize them by their criticality and risk.
• Experience in reviewing AD configurations, processes, and documentation.
• Proficient with tools such as ADUC, ManageEngine, StealthAUDIT, and other AD scanning utilities.
• Ability to provide actionable recommendations, inputs for remediation planning, resource estimates, skill requirements, and budget estimates.
• Excellent communication skills to document findings, recommendations, risks, and remediation plans for stakeholders.
• Health insurance
• Flexible work arrangements
• Professional development
Turner & Townsend
Aperia
CB CONSTRUCTION
Oowlish
Get handpicked remote jobs straight to your inbox weekly.