Active Directory Business Analyst

Edison, NJ, US • Posted 14 hours ago • Updated 2 hours ago
Contract W2
On-site
USD50 - USD75/hr
Fitment

Dice Job Match Score™

🎯 Assessing qualifications...

Job Details

Skills

  • Active Directory Business Analyst

Summary

job summary:

Our enterprise client has an immediate opening for an experienced Business Analyst specializing in Active Directory.



In this role, you'll work directly with corporate end users to define AD groups while using Excel to manage and structure access data. Deep familiarity with AD support and data analysis is essential.







location: Edison, New Jersey

job type: Contract

salary: $50 - 75 per hour

work hours: 9am to 5pm

education: Bachelors



responsibilities:

The Business Analyst - Active Directory & Automation serves as the liaison between business stakeholders, Information Security, IAM engineering, application owners, and IT support teams. This role analyzes identity and access management processes, with a strong focus on Microsoft Active Directory, access provisioning, role and group management, and user lifecycle controls.



The position combines traditional business analysis responsibilities with hands-on technical analysis using PowerShell, Active Directory reporting tools, and structured data. The analyst will identify process gaps, analyze access and group membership data, develop requirements, support remediation initiatives, and automate recurring analysis and reporting activities.



The ideal candidate has a strong understanding of Active Directory structures, access governance, business process analysis, and data-driven problem solving.



Key Responsibilities



Business and Process Analysis




  • Partner with IAM, Information Security, Infrastructure, Human Resources, application owners, and business stakeholders to document active directory groups and access management requirements.


  • Analyze current-state IAM processes, including onboarding, transfers, terminations, access requests, approvals, provisioning, deprovisioning, and periodic access reviews.


  • Develop current-state and future-state process maps, business requirements, functional requirements, user stories, acceptance criteria, and workflow documentation.


  • Identify process gaps, control weaknesses, approval delays, manual dependencies, and opportunities for automation.


  • Facilitate requirements-gathering sessions, stakeholder interviews, working sessions, and process reviews.


  • Maintain project documentation, decision logs, requirements traceability, action items, and implementation status.



Active Directory Analysis






  • Perform detailed analysis of Active Directory users, groups, organizational units, group memberships, nested groups, ownership, and access relationships.


  • Identify inactive accounts, orphaned accounts, duplicate access, excessive permissions, unmanaged groups, stale memberships, and groups without valid owners.


  • Analyze security groups, distribution groups, privileged groups, service accounts, shared accounts, and role-based access structures.


  • Support Active Directory cleanup, access certification, entitlement rationalization, group ownership validation, and remediation initiatives.


  • Compare requested, approved, provisioned, and removed access to identify discrepancies.


  • Analyze user access based on department, title, manager, location, employment status, start date, termination date, and job function.


  • Assist with the development and validation of role-based access control and birthright-access models.


  • Support investigations involving access provisioning failures, inappropriate permissions, delayed onboarding, and incomplete deprovisioning.



PowerShell and Python Automation






  • Develop and maintain PowerShell scripts to query and analyze Active Directory objects, attributes, memberships, ownership, and account status.


  • Use Python to clean, transform, compare, reconcile, and analyze IAM and Active Directory datasets.


  • Automate recurring reports, data-quality checks, exception identification, access comparisons, and remediation tracking.


  • Extract and consolidate information from Active Directory, IAM platforms, ServiceNow, CSV files, Excel workbooks, databases, and other approved sources.


  • Build reusable scripts and analytical tools with appropriate logging, error handling, validation, and documentation.


  • Produce structured outputs for operational teams, auditors, control owners, and senior management.


  • Work with technical teams to transition approved scripts and analysis routines into controlled production processes.


  • Follow organizational standards for source control, code review, testing, security, and change management.



IAM Governance and Controls






  • Support access reviews, recertification campaigns, segregation-of-duties analysis, privileged-access reviews, and audit remediation.


  • Validate that access requests follow established approval, authorization, and provisioning requirements.


  • Assist in defining IAM policies, procedures, standards, controls, and operational metrics.


  • Identify exceptions that may create security, regulatory, audit, or operational risk.


  • Support internal and external audit requests by gathering evidence, validating data, and documenting control execution.


  • Track IAM issues and remediation activities through completion.


  • Help establish measurable service levels and key performance indicators for provisioning, approvals, access removal, and exception resolution.


  • Promote least-privilege access, role-based access, clear group ownership, and timely removal of unnecessary access.





qualifications:

Required Qualifications



Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Business Analysis, Information Systems, or a related discipline, or equivalent professional experience.



Three or more years of experience in business analysis, identity and access management, cybersecurity, Active Directory administration, or a related technology function.



Demonstrated experience analyzing Microsoft Active Directory users, groups, memberships, attributes, organizational units, and account status.



Hands-on experience writing and executing PowerShell scripts for Active Directory analysis and reporting.



Experience using Python for data analysis, reconciliation, automation, or reporting.



Strong understanding of identity lifecycle management, including onboarding, transfers, terminations, provisioning, deprovisioning, and access certification.



Experience gathering and documenting business requirements, functional requirements, user stories, workflows, and acceptance criteria.



Strong analytical skills with the ability to work with large and complex datasets.



Advanced proficiency with Microsoft Excel, including lookup functions, pivot tables, formulas, data validation, and data comparison.



Strong written and verbal communication skills.



Ability to explain technical IAM issues to both technical and nontechnical audiences.



Strong documentation, organization, problem-solving, and stakeholder-management skills.



Preferred Qualifications



Experience with Microsoft Entra ID, formerly Azure Active Directory.



Experience with IAM or identity governance platforms such as SailPoint, Saviynt, Okta, Microsoft Entra ID Governance, CyberArk, or similar technologies.



Experience with ServiceNow request, incident, change, or identity-related workflows.



Familiarity with SQL, REST APIs, JSON, Git, source-control practices, or data-visualization tools.



Knowledge of privileged access management, multifactor authentication, single sign-on, federation, and conditional-access concepts.



Experience supporting access certifications, entitlement reviews, audit requests, or regulatory-control testing.



Familiarity with RBAC, least privilege, segregation of duties, zero-trust principles, and identity-governance frameworks.



Relevant certifications such as CBAP, CCBA, Security+, Microsoft Identity and Access Administrator, ITIL, or equivalent credentials.



Technical Skills



Microsoft Active Directory



Microsoft Entra ID



PowerShell



Python



Microsoft Excel



IAM and identity-governance platforms



ServiceNow



Data analysis and reconciliation



Process mapping and requirements documentation



SQL and API integration knowledge



Reporting and dashboard development



Git or comparable source-control tools



Core Competencies



Analytical thinking and structured problem solving



Business and technical requirements translation



IAM process and control awareness



Data accuracy and attention to detail



Stakeholder facilitation and communication



Process improvement and automation



Risk identification and escalation



Documentation and knowledge management



Ownership and accountability



Ability to manage multiple priorities



Key Measures of Success



Improved accuracy and completeness of Active Directory and IAM data.



Redu


Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: cxsapwma1
  • Position Id: 1340635
  • Posted 14 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Parsippany-Troy Hills, New Jersey

Today

Full-time

USD 108,000.00 - 130,000.00 per year

Princeton, New Jersey

Today

Full-time

USD 141,000.00 - 157,000.00 per year

Hybrid in Jersey City, New Jersey

Today

Contract

75-87/hr

New York, New York

2d ago

Easy Apply

Contract, Third Party

Depends on Experience

Search all similar jobs