T

Walk-in || Active Directory Subject Matter Expert

Tata Consultancy Services · Bengaluru, Karnataka, India

~₹18L (est.)5–12 yrs experiencefull_timePosted Yesterday
Apply now →

Job description

**Job Description** Required Technical Skill Set : ***Active Directory*** ***Desired Experience Range : 8 to 15 Years*** ***Location of Requirement Bengalauru Yeshwantpur*** Competencies (Technical/Behavioral Competency) **Must-Have\\*\\***Hands-on enterprise Active Directory / Windows Server (2016/2019/2022) administration at L3 level with deep expertise in AD DS design — multi-DC forests/domains, OUs, trusts, GPO management, DNS, Kerberos, and AD replication.Proven experience with HA / DR domain controller architecture and AD backup/restore (including krbtgt & DSRM recovery).Working knowledge of PAM and MFA integration and least-privilege / SoD / RBAC enforcement. Strong PowerShell scripting for automation and reporting. **Good-to-Have**Candidate should have strong hands-on knowledge in one or more of the following platforms:Exposure to Azure AD / Entra ID and hybrid identity setups.Hands-on with PAM tools (Arcon / BeyondTrust) and MFA solutions used in the SSC stack.Familiarity with ITSM tools (ServiceNow / ManageEngine ServiceDesk Plus) for request/change workflows.Understanding of BFSI regulatory compliance (RBI, CERT-In, MeitY) and sovereign / secure cloud operating models. Relevant certifications (e.g., Microsoft Certified: Windows Server / Identity & Access Administrator). **Responsibility of / Expectations from the Role** - Design and administer Active Directory Domain Services (AD DS) on Windows Server 2022 — forests, domains, OUs, trees, trusts, and Group Policy Objects (GPOs). - Architect and maintain High-Availability AD and multi-Domain-Controller setup with DR failover across data centers. - Manage the full identity lifecycle — user/admin/service account onboarding, modification, and offboarding — enforcing least privilege, Segregation of Duties, and RBAC. - Administer Kerberos authentication, DNS, NTP, AD replication, krbtgt/DSRM password resets, and scheduled AD backups & restores. - Integrate AD with PAM and MFA for privileged/vaulted account management. - Automate reporting and routine tasks via PowerShell, and produce audit/compliance evidence for security reviews.