URGENT HIRING for Active Directory Security Specialist
Email ID:
[email protected]
Contact : (phone hidden)
Budget: Up to ₹20 LPA per position
Experience: • Six or more years working with Windows Server and Active Directory
Joining: Immediate
Location: Chennai or Bengaluru, with travel to client sites across India, Sri Lanka and the GCC
Practice: Security Consulting
1. Company is looking for an Active Directory Security Specialist to lead the design and delivery of AD security hardening for our clients. Red team exercises and compromise assessments consistently surface weaknesses in Active Directory, but the findings are rarely closed properly because doing so means changing authentication across the business without disrupting it. You will be the person who does that work: assessing the state of a client's Active Directory and Entra ID environment, translating findings from our own- and third-party assessments into a practical remediation plan, and driving that plan through to completion alongside the client's infrastructure team. The role is built on deep Active Directory architecture knowledge and hands on remediation experience, not on penetration testing.
1. Key Responsibilities
• Assess client Active Directory and Entra ID environments and produce a transparent picture of privileged access exposure, misconfiguration and architectural weakness.
- Take findings from red team exercises, compromise assessments and audits, and convert them into a prioritised, sequenced remediation plan with realistic effort and risk estimates.
- Execute and oversee remediation: privileged access tiering,
service account and delegation cleanup, group and permission rationalisation, Group Policy correction, certificate services configuration, legacy protocol retirement, LAPS deployment.
- Harden hybrid identity, including Entra Connect, Conditional Access, and privileged role management and federation configuration.
- Test proposed changes before they reach production and advise clients accurately on operational impact and rollback.
- Support Active Directory resilience work: backup isolation, forest recovery planning and tested recovery runbooks.
- Document methodology, checklists and runbooks so the work becomes a repeatable company’s service rather than an individual effort.
- Support scoping calls, technical proposals and findings walkthroughs with client CISOs and infrastructure leads.
- Mentor junior consultants and act as the escalation point for Active Directory questions across our engagements.
1. Minimum Requirements
• Six or more years working with Windows Server and Active Directory, including at least three years focused on Active Directory security or hardening.
- Robust architectural understanding of Active Directory: domains, forests, trusts, replication, sites, Group Policy, DNS and the Kerberos and NTLM authentication flows.
- Practical experience remediating Active Directory weaknesses in a live production environment, not in a lab.
- Hands on experience with Active Directory assessment tooling such as BloodHound, PingCastle or Purple Knight, and the ability to interpret and act on the output.
- Working knowledge of Entra ID and hybrid identity in production.
- PowerShell scripting for administration and automation.
- Ability to explain technical risk and remediation clearly to both engineers and senior business stakeholders.
- Bachelor's degree in computer science, information technology or a related field, or equivalent practical experience.
1. Preferred Qualifications
• Experience delivering a privileged access tiering or Tier 0 isolation programme end to end.
- Experience with Active Directory Certificate Services configuration and remediation.
- Familiarity with identity threat detection tooling such as Microsoft Defender for Identity or Semperis.
- Experience with Active Directory backup and forest recovery tooling.
- Consulting or professional services background, working across multiple client environments.
- Exposure to regulated environments and frameworks: RBI, SAMA, NCA ECC, PCI DSS, ISO 27001.
- Certifications such as Microsoft SC-300, AZ-800 or AZ-801, SANS SEC505, CRTP or CISSP.
- Working knowledge of how Active Directory is attacked, sufficient to validate that a remediation has actually closed the issue.
Interested candidates can apply along with their resume on the below mentioned email ID or whatsapp number
📌 Active Directory Specialist (Chennai)
🏢 White Force Group
📍 Chennai