IAM Active Directory in Canada Creek, Nova Scotia at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a IAM Active Directory based in Canada.
This role is focused on designing, maintaining, and securing enterprise identity infrastructure across complex hybrid environments.
You will take ownership of core Active Directory services while working extensively with Microsoft Entra ID and cloud platforms.
The position combines hands-on infrastructure engineering with identity, security, automation, and troubleshooting responsibilities.
You will help ensure reliable authentication, directory services, policy enforcement, and hybrid identity connectivity at enterprise scale.
The role requires strong technical depth across Active Directory, Azure, DNS, Group Policy, Kerberos, and related Microsoft technologies.
You will also contribute to security hardening, disaster recovery, incident resolution, and continuous infrastructure improvement.
This is an excellent opportunity for an experienced IAM engineer who enjoys solving complex infrastructure challenges and working in cloud-enabled environments.
- Design, implement, maintain, and optimize enterprise Active Directory infrastructure, including Domain Controllers, Global Catalogs, FSMO roles, Sites and Services, and AD replication.
- Perform Domain Controller promotions, demotions, migrations, upgrades, health validations, and related lifecycle activities.
- Troubleshoot complex issues involving Active Directory replication, authentication, Kerberos, DNS, LDAP, and Group Policy.
- Administer Active Directory users, groups, computers, Organizational Units, trusts, and other directory objects.
- Design, deploy, and troubleshoot Group Policy Objects and security baselines across enterprise environments.
- Support Microsoft Entra ID, Azure AD Connect, and hybrid identity architectures.
- Perform forest and domain upgrades, schema extensions, backup and restore operations, and disaster recovery testing.
- Monitor and validate Active Directory health using tools such as DCDIAG, REPADMIN, Event Viewer, Semperis, and Splunk.
- Implement identity security best practices, including tiered administration, Privileged Access Workstations, LAPS, gMSA, LDAP signing, SMB signing, Kerberos hardening, and RC4 remediation.
- Manage supporting Microsoft infrastructure services, including DNS, DHCP, and PKI/Certificate Services.
- Develop PowerShell automation to streamline administrative tasks, improve reliability, and reduce manual effort.
- Participate in change management, scheduled maintenance windows, and on-call support activities.
- Lead root cause analysis for critical incidents and produce clear technical documentation covering findings, resolutions, and preventative measures.
- Collaborate with infrastructure, security, and cloud teams to maintain reliable and secure identity services across enterprise environments.
- Strong professional experience engineering and supporting enterprise Active Directory and IAM environments.
- Hands-on expertise with Microsoft Active Directory infrastructure, including Domain Controllers, replication, FSMO roles, Sites and Services, trusts, DNS, LDAP, Kerberos, and Group Policy.
- Strong experience with Microsoft Entra ID (Azure AD), Azure AD Connect, and hybrid identity architectures.
- Practical cloud infrastructure experience with one or more major platforms, including AWS, Azure, or GCP.
- Experience should be focused on identity and infrastructure engineering rather than primarily on network administration or traditional end-user administration.
- Strong troubleshooting capabilities across authentication, replication, Group Policy, DNS, and directory services.
- Experience with Active Directory security hardening and privileged access concepts, including LAPS, gMSA, PAWs, LDAP/SMB signing, and Kerberos security.
- Experience with monitoring and diagnostic tools such as DCDIAG, REPADMIN, Event Viewer, Semperis, or Splunk.
- Working knowledge of DNS, DHCP, PKI, and Microsoft Certificate Services.
- Strong PowerShell scripting and automation capabilities.
- Experience performing migrations, upgrades, disaster recovery, and backup/restore activities for Active Directory environments.
- Strong incident management, root cause analysis, documentation, and change management skills.
- Ability to work independently, manage critical infrastructure responsibilities, and collaborate effectively with technical teams.
- Strong communication skills and a proactive approach to security, reliability, and continuous improvement.
- $60/hour on W2.
- Competitive compensation based on qualifications, experience, and location.
- Option to enroll in healthcare benefits, including medical, dental, and vision insurance.
- Major holiday benefits.
- Paid sick leave in accordance with applicable state law.
- Equal employment opportunity regardless of protected characteristics under applicable law.