The posting
We are looking for an experienced L2 Active Directory Engineer to support and administer enterprise Active Directory, Microsoft Entra ID (Azure AD), Identity & Access Management (IAM), authentication, and directory services.
The role will provide L2 support and act as an escalation point for identity-related incidents and service requests, working closely with Service Desk, Infrastructure, Security, and Application teams.
Key Responsibilities
Active Directory
- Administer and support Microsoft Active Directory environments.
- Manage users, groups, computers, OUs, and Group Policies (GPOs).
- Perform Joiner, Mover, Leaver (JML) processes.
- Monitor AD replication and directory health.
- Perform account audits and directory clean-up.
- Troubleshoot authentication and Active Directory issues.
Microsoft Entra ID / Azure AD
- Administer Microsoft Entra ID environments.
- Support hybrid identity and Azure AD Connect synchronization.
- Manage Conditional Access Policies and MFA.
- Support Self-Service Password Reset (SSPR).
- Troubleshoot authentication and synchronization issues.
- Support identity governance activities.
IAM & Access Management
- Provision, modify, and deprovision user access.
- Manage Role-Based Access Control (RBAC).
- Support privileged account administration.
- Perform access reviews and certification exercises.
- Ensure compliance with access control and segregation of duties requirements.
L2 Incident & Service Request Support
- Provide L2 support for identity and directory-related incidents.
- Troubleshoot account lockouts, authentication failures, access issues, and synchronization problems.
- Perform root cause analysis for recurring issues.
- Escalate and coordinate complex issues with Infrastructure, Security, and Application teams.
- Support major incident management when identity services are impacted.
Security, Automation & Documentation
- Support security hardening and vulnerability remediation.
- Participate in security audits and compliance activities.
- Develop PowerShell scripts to automate repetitive IAM tasks.
- Automate user provisioning, reporting, and operational processes.
- Maintain SOPs, runbooks, knowledge articles, and technical documentation.
Required Skills & Experience
- 5+ years of enterprise Active Directory support experience.
- Strong hands-on experience with:Microsoft Active DirectoryMicrosoft Entra ID / Azure ADAzure AD ConnectGroup Policy (GPO)LDAP and authentication servicesIAM and user lifecycle management (JML)Microsoft Windows ServerMFAPowerShell scripting
- Good understanding of DNS and DHCP.
- Strong L2 troubleshooting and incident management experience.
- Experience supporting enterprise identity and access environments.
Qualifications
- Bachelor's Degree in Computer Science, Information Technology, or related discipline.
- Microsoft Identity, Azure Administrator, or other relevant certifications are advantageous.



