O que a vaga pede
About the Role We are seeking an experienced Active Directory/AAD (Azure active Directory) L3 Support Engineer/Consultant responsible for the administration, governance, security, and optimization of the enterprise Active Directory infrastructure. The role will serve as the highest operational escalation point for Active Directory services and provide technical leadership for AD/AAD architecture, Group Policy management, identity integrations, automation, and security hardening. The engineer will work closely with IAM, Security, Infrastructure, Windows Server, Cloud, and Application teams to ensure the availability, integrity, and security of identity services across the enterprise. Key Responsibilities Manage and support enterprise Active Directory environments. Administer AD DS, DNS, users, groups, service accounts, and GPOs. Perform troubleshooting, security administration, backup/recovery, and PowerShell automation. Manage hybrid identity environments with Active Directory and Microsoft Entra ID. Administer Entra Connect, MFA, Conditional Access, Identity Protection, PIM, and RBAC. Support IAM integrations and authentication protocols (SAML, OAuth, OIDC). Apply AD security best practices and privileged access controls. Act as L3 escalation point for complex incidents and problem management. Support audits, compliance activities, and change management. Maintain technical documentation, runbooks, and standards. Provide knowledge transfer and support continuous improvement initiatives. Required Qualifications Bachelor or Master degree in Cybersecurity, Computer Science, Information Technology, Engineering or related disciplines. Fluent English (written and spoken) Strong experience with Active Directory (AD DS), Windows Server, DNS, DHCP and Group Policy . Knowledge of Microsoft Entra ID (Azure AD) , Hybrid Identity and authentication technologies (Kerberos, LDAP/LDAPS, MFA). Experience with Identity & Access Management (IAM) and Privileged Access Management (PAM). Understanding of PKI/Certificate Services , Backup & Disaster Recovery. PowerShell scripting and automation. Experience in multinational and multicultural environments. Preferred Skills Experience with IAM/PAM solutions such as CyberArk, Delinea, Saviynt or OneLogin . Experience with Azure and hybrid cloud identity environments . Active Directory security hardening and automation. Participation in enterprise AD transformation or migration projects. Familiarity with ITIL processes. Why Join Us?