We are looking for a senior Active Directory & Entra ID Architect to strengthen a global IT organization and drive innovation in identity and access management. The role is central to the design, governance, and resilience of a multinational hybrid identity infrastructure. Acting as both a technical leader and strategic advisor, the architect will enable secure access, ensure compliance, and align IAM strategies with business and security objectives.
Lead the architectural design and lifecycle management of Active Directory and Microsoft Entra ID in global environments.
Define and implement hybrid identity strategies integrating on-premises AD with cloud-based Entra ID.
Establish Zero Trust frameworks, including Conditional Access, MFA, and Identity Protection.
Drive migrations from legacy platforms to modern cloud-native solutions.
Collaborate with cybersecurity, compliance, and infrastructure teams to align IAM with regulations.
Design and manage RBAC, Privileged Identity Management (PIM), and identity governance models.
Automate identity operations with PowerShell and other tools.
Mentor IAM engineers and provide technical oversight across regions.
Define OU structures, forest/domain designs, trusts, and Group Policy strategies.
Integrate Entra ID with SaaS, MDM, and security tools for lifecycle management.
Implement high-availability, disaster recovery, and monitoring strategies.
Conduct audits and assessments to ensure compliance.
Deploy identity protection features like risk-based sign-in detection and JIT access.
Partner with security, application, and cloud teams for secure integrations.
Act as subject matter expert for identity initiatives and transformations.
Enterprise-level experience with Active Directory and Entra ID architecture/administration.
Hands-on expertise with Entra Connect, Conditional Access, MFA, SSO, and federation (SAML, OIDC, OAuth).
Strong knowledge of LDAP, Kerberos, Group Policy, DNS, and hybrid identity configurations.
Proficiency in Microsoft 365 security, Intune, Defender for Identity, and MFA/SSO implementations.
Advanced PowerShell scripting for automation and policy enforcement.
Solid understanding of compliance frameworks (ISO 27001, GDPR, NIS2).
Excellent communication skills with both technical and non-technical stakeholders.
Experience with Privileged Access Management tools (e.g., CyberArk, Microsoft PIM).
Familiarity with Zero Trust frameworks and security hardening.