In support of an infrastructure enhancement and development programme, an experienced Active Directory (AD) specialist is required to enhance and secure an existing AD environment and move to best practice to maintain hygiene of the environment and reduce risk. .
Working alongside cyber security, infrastructure and service delivery teams, you will lead practical remediation activity across on-premise AD and Microsoft Entra environments, prioritising quick wins while establishing a clear, iterative plan for longer-term identity security improvement.
This is an excellent opportunity to contribute to a large-scale transformation programme within a complex and diverse environment supporting thousands of users across a range of functions.
Key Responsibilities
- In conjunction with others, Identify and remediate Active Directory infrastructure vulnerabilities
- From existing reports and reviews, translate recommendations into a prioritised remediation plan
- Improve the organisation’s AD security posture through rapid hardening actions, followed by an iterative programme of risk reduction
- Support the migration of legacy applications from LDAP-based authentication to Microsoft Entra where appropriate
- Identify and reduce any risks linked to legacy protocols and services
- Implement controls to ensure best practice on service accounts
- Use provided tooling to review AD content, identify anomalies and remediate issues such as inappropriate group membership, stale objects and weak account configurations
- Work with others to agree remediation priorities Produce concise technical documentation, remediation evidence and knowledge transfer materials.
Essential Skills & Experience
- Extensive experience securing, administering and remediating Active Directory in large, complex enterprise environments
- Strong practical knowledge of AD security hardening, privilege escalation risks, least-privilege access and domain administration controls
- Experience interpreting test findings, AD hygiene assessments and remediation recommendations
- Strong understanding of Active Directory Domain Services, Group Policy, DNS, authentication flows, NTLM and hybrid identity patterns
- Hands-on experience with Microsoft Entra ID and the migration of legacy application authentication away from LDAP where required
- Experience identifying and mitigating risks associated with legacy protocols and services, such as TLS 1.0, TLS 1.1 and SMBv1
- Experience managing or remediating service accounts, password rotation, privileged groups and account hygiene
- Strong PowerShell scripting and reporting capability to support analysis, remediation and evidence capture
- Excellent troubleshooting, stakeholder engagement and documentation skills.
Desirable Experience
- Experience using PingCastle, SpecOps or similar AD assessment and password policy tooling
- Experience delivering identity remediation or cyber security improvement programmes
- Higher Education, Public Sector or similarly complex organisation experience
- Microsoft Defender for Identity, privileged access management or Zero Trust security experience
- Experience with Active Directory migrations, domain consolidations or hybrid identity modernisation.
What Success Looks Like including, but not limited to:
- Improved AD security and operational hygiene
- AD hygiene improves measurably through remediation of weak groups, stale objects, service accounts and configuration anomalies
- Legacy authentication and protocol risks, are reduced or removed
- The organisation has clearer remediation evidence, operational documentation and a stronger identity security baseline.
