L2 Active Directory Engineer
We are looking for an experienced L2 Active Directory Engineer to support and administer enterprise Active Directory, Microsoft Entra ID (Azure AD), Identity & Access Management (IAM), authentication, and directory services. The role will provide L2 support and act as an escalation point for identity-related incidents and service requests, working closely with Service Desk, Infrastructure, Security, and Application teams. Key Responsibilities Active Directory Administer and support Microsoft Active Directory environments. Manage users, groups, computers, OUs, and Group Policies (GPOs). Perform Joiner, Mover, Leaver (JML) processes. Monitor AD replication and directory health. Perform account audits and directory clean-up. Troubleshoot authentication and Active Directory issues. Microsoft Entra ID / Azure AD Administer Microsoft Entra ID environments. Support hybrid identity and Azure AD Connect synchronization. Manage Conditional Access Policies and MFA. Support Self-Service Password Reset (SSPR). Troubleshoot authentication and synchronization issues. Support identity governance activities. IAM & Access Management Provision, modify, and deprovision user access. Manage Role-Based Access Control (RBAC). Support privileged account administration. Perform access reviews and certification exercises. Ensure compliance with access control and segregation of duties requirements. L2 Incident & Service Request Support Provide L2 support for identity and directory-related incidents. Troubleshoot account lockouts, authentication failures, access issues, and synchronization problems. Perform root cause analysis for recurring issues. Escalate and coordinate complex issues with Infrastructure, Security, and Application teams. Support major incident management when identity services are impacted. Security, Automation & Documentation Support security hardening and vulnerability remediation. Participate in security audits and compliance activities. Develop PowerShell scripts to automate repetitive IAM tasks. Automate user provisioning, reporting, and operational processes. Maintain SOPs, runbooks, knowledge articles, and technical documentation. Required Skills & Experience 5+ years of enterprise Active Directory support experience. Strong hands-on experience with:Microsoft Active DirectoryMicrosoft Entra ID / Azure ADAzure AD ConnectGroup Policy (GPO)LDAP and authentication servicesIAM and user lifecycle management (JML)Microsoft Windows ServerMFAPowerShell scripting Good understanding of DNS and DHCP. Strong L2 troubleshooting and incident management experience. Experience supporting enterprise identity and access environments. Qualifications Bachelor's Degree in Computer Science, Information Technology, or related discipline. Microsoft Identity, Azure Administrator, or other relevant certifications are advantageous.