الوظائف الحالية

اكتشف و تقدم بالطلب الآن

Active Directory L2 Administrator (m/f/d)

FTE
Riyadh, Saudi Arabia
29.09.2025
Job Title: Active Directory L2 Administrator

Department: Infrastructure Services

Location: KSA

Job Summary:
The AD L2 Administrator will be responsible for the day-to-day operations, maintenance, and support of enterprise identity services including Active Directory, ADFS, PKI, Microsoft Entra ID (Azure AD), DNS, DHCP, and associated monitoring and self-service tools. This includes managing hybrid identity environments, troubleshooting replication and authentication issues, and implementing security and compliance controls.

Key Responsibilities:

Active Directory (On-Prem & Hybrid)
  • Manage multi-domain AD forest including replication, OU delegation, GPO enforcement, and health checks.
  • Perform daily operational tasks such as user/service account provisioning, password resets, and group management.
  • Monitor AD health using ManageEngine AD Audit Plus, Splunk, and Dynatrace.
  • Implement and maintain RBAC, MFA for privileged accounts, and CyberArk PAM integration.
ADFS (Active Directory Federation Services)
  • Maintain multiple ADFS farms for internal and external applications.
  • Manage relying party trusts, certificate rollover, and conditional access policies.
  • Coordinate with application and network teams for federation and high availability setup.
PKI (Public Key Infrastructure)
  • Operate and maintain a 2-tier PKI
  • Manage certificate templates, auto-enrolment and manual issuance for web servers and domain controllers.
  • Ensure CRL/CDP configurations and Splunk-based monitoring are in place.
Microsoft Entra ID (Azure AD)
  • Support hybrid identity architecture with Azure AD Connect sync from On-Prem AD.
  • Manage conditional access policies, licensing and integration with cloud applications.
  • Assist in certificate-based authentication (CBA) and governance activities.
DNS & DHCP
  • Administer DNS zones, scavenging, and secure updates (DNSSEC).
  • Manage DHCP scope configurations, reservations, and IP address management
  • Ensure compliance with naming conventions and subnet allocation policies.
ManageEngine AD Audit Plus
  • Configure and maintain auditing policies for AD changes, logon events, and GPO modifications.
  • Generate compliance reports and alerts for unauthorized access or privilege escalation.
  • Integrate with SIEM tools for centralized monitoring.
Self-Service Password Reset (SSPR)
  • Administer and support SSPR solutions for internal and external users.
  • Ensure secure enrolment, multi-factor authentication, and policy enforcement.
  • Monitor usage and troubleshoot issues related to password reset workflows.

Required Skills & Competencies:
  • Strong knowledge of Windows Server (2016/2019/2022), AD DS, ADFS, PKI, DNS, DHCP.
  • Experience with hybrid identity solutions including Azure AD and Entra ID.
  • Familiarity with tools: ManageEngine AD Audit Plus, CyberArk, Splunk, Dynatrace.
  • Scripting skills (PowerShell) for automation and reporting.
  • Understanding of ITSM processes, incident/change/problem management.

Qualifications:
  • Bachelor’s degree in computer science, Information Technology, or related field.
  • Certifications preferred: Microsoft Certified: Azure Administrator Associate (AZ-104), AD DS, PKI, ADFS, DNS/DHCP.
  • Minimum 5 years of experience in enterprise AD administration.
Halian Group:
With over 28 years of experience, we have come to understand that innovation is the only way to provide agile, practical solutions that transform businesses and careers. Our resourcing and smart services help you to realize tomorrow’s potential. Discover the amazing things possible when you bring the right people and the right technologies together.

At Halian, we recognize that diversity, equity, and inclusion (DEI) are essential to building high-performing teams for our clients. We are committed to connecting organizations with top talent from all backgrounds, ensuring that every individual feels valued, respected, and empowered to contribute their unique perspectives. We encourage applications from all qualified candidates, regardless of race, gender, disability, or any other characteristic that makes them unique. By fostering diverse and inclusive workplaces, we help our clients drive innovation, enhance collaboration, and better reflect the communities they serve.

#LI-CA1

هل أنت جاهز للغد؟

قم بالتسجيل الآن