Simeio is a recognized top IAM provider with a global presence, and they are seeking a Microsoft Security Engineer to support a US-based engagement. The role involves assessing the client's Active Directory and Azure/Entra ID deployment, identifying configuration gaps, and providing recommendations for remediation.
Responsibilities:
- Assess the current state of the client’s Active Directory and Azure/Entra ID deployment, including forest design, site design, domain design, security group topology, deployment architecture, organizational unit (“OU”) design, authentication, and group policy design
- Manage the migration of enterprise data governance and compliance frameworks to Microsoft Purview, ensuring secure data management and regulatory compliance
- Run PowerShell queries against the client AD to determine relevant statistics of current AD and Azure objects, including users, accounts, groups, organizational units (OUs), computer objects, and related identity objects
- Run SailPoint out-of-the-box reports against AD connectivity to provide group and account ownership and membership information
- Review AD configurations, processes, and documentation to understand the client’s current deployment and operating model
- Identify configuration and operational gaps in the client’s AD domains, infrastructure, architecture, and deployment
- Prioritize identified gaps based on criticality and risk
- Provide recommendations to address critical gaps and risks across AD and Entra ID environments
- Discover and assess current processes for AD group management, AD group policy management, and AD account management
- Suggest modifications and refinements to existing processes and create new processes if required
- Determine the resources and skills necessary to complete remediation activities and achieve defined milestones
- Provide an estimated budget to accomplish remediation as outlined during the assessment phases
- Leverage client tools such as ADUC (Active Directory Users & Computers), ManageEngine, StealthAUDIT, or other AD scanning utilities as needed to accomplish data-gathering activities
Requirements:
- Strong experience as an Active Directory Architect, including domain consolidation, AD assessment, and enterprise identity infrastructure review
- Hands-on knowledge of Active Directory forest, site, domain, OU, security group, authentication, and group policy design
- Experience assessing Azure/Entra ID deployments and hybrid identity environments
- Ability to run and interpret PowerShell queries against AD domains to gather statistics on users, accounts, groups, OUs, computer objects, and related AD/Azure objects
- Experience using SailPoint reports for AD group and account ownership and membership analysis
- Ability to identify configuration and operational gaps and prioritize them based on criticality and risk
- Experience reviewing AD configurations, processes, and documentation
- Working knowledge of tools such as ADUC, ManageEngine, StealthAUDIT, and other AD scanning utilities
- Ability to provide practical recommendations, remediation planning inputs, resource estimates, skill requirements, and budget estimates
- Strong communication skills to document findings, recommendations, risks, and remediation plans for stakeholders
- Prior experience with large-scale AD domain consolidation projects
- Experience supporting remediation roadmap planning for AD, Azure/Entra ID, and identity governance environments
- Familiarity with identity governance tools and reporting approaches, especially SailPoint