Job Title: Senior Security Architect – Active Directory
Experience: 15+ Years
Employment Type: Full-Time
We are seeking a highly experienced Senior Security Architect with deep expertise in Microsoft Active Directory (AD) and enterprise security architecture. The ideal candidate will be a strategic thinker and recognized technical leader who can design, secure, and modernize enterprise identity infrastructure while partnering closely with executive leadership, including the CTO.
Key Responsibilities
Lead the design, architecture, and security of enterprise Microsoft Active Directory environments (on-premises and hybrid).
Develop and implement Active Directory security strategies, standards, and best practices.
Architect secure identity solutions involving Active Directory, Microsoft Entra ID (Azure AD), authentication, authorization, and identity lifecycle management.
Strengthen the organization''s identity security posture through Active Directory hardening, Privileged Access Management (PAM), Multi-Factor Authentication (MFA), and Zero Trust principles.
Conduct security assessments, identify risks and vulnerabilities, and recommend mitigation strategies for Active Directory infrastructure.
Partner directly with the CTO and senior leadership to define enterprise security roadmaps and strategic initiatives.
Collaborate with Infrastructure, Cloud, and Security Operations teams to ensure secure identity integration across enterprise platforms.
Provide architectural guidance during security transformation and modernization initiatives.
Stay current with emerging cyber threats, identity security trends, and Microsoft security technologies.
Mentor technical teams and promote security best practices across the organization.
Required Qualifications
Bachelor''s or Master''s degree in Computer Science, Information Security, or a related field.
15+ years of experience in Enterprise Security Architecture or Cybersecurity.
Extensive hands-on experience with Microsoft Active Directory Domain Services (AD DS) and enterprise identity infrastructure.
Strong expertise in Active Directory security, Group Policy, Kerberos, LDAP, DNS, and hybrid identity environments.
Experience with Microsoft Entra ID (Azure AD) and hybrid identity architecture.
Strong understanding of Identity & Access Management (IAM), authentication, authorization, and identity governance.
Experience with Active Directory hardening, Tiered Administration, Privileged Access Management (PAM), and Identity Threat Detection.
Solid understanding of Zero Trust Architecture and modern cybersecurity frameworks.
Proven ability to communicate effectively with executive leadership and influence enterprise security decisions.
Preferred Skills
Experience with Microsoft Defender for Identity, Microsoft Defender XDR, Microsoft Sentinel, or similar security platforms.
Knowledge of CyberArk, BeyondTrust, Delinea, SailPoint, Okta, or other identity security solutions.
Experience securing cloud and hybrid enterprise environments.
Relevant certifications such as CISSP, Microsoft Certified: Cybersecurity Architect Expert (SC-100), Microsoft Identity and Access Administrator (SC-300), Azure Solutions Architect Expert (AZ-305), or equivalent.
Ideal Candidate
A recognized technical leader with deep expertise in Active Directory Security.
Strong architectural and strategic thinking skills.
Ability to work directly with executive leadership, including the CTO.
Excellent communication, presentation, and stakeholder management skills.
Passionate about building secure, resilient, and scalable enterprise security solutions.