The Active Directory Architect (Domain Consolidation) will support a US‑based engagement focused on assessing the client’s on‑premises Active Directory (AD) and Azure/Entra ID deployment. The role involves evaluating forest, site, domain, security group, organizational unit (OU), authentication, group policy, and deployment architecture, identifying configuration and operational gaps, and providing recommendations to address critical risks. The architect will also review existing AD management processes, gather data using tools such as PowerShell, ADUC, and help define the resources, skills, and budget required for remediation.
What You’ll Do:
- Assess the current state of the client’s Active Directory and Azure/Entra ID deployment, including forest design, site design, domain design, security group topology, deployment architecture, organizational unit (“OU”) design, authentication, and group policy design.
- Run PowerShell queries against the client AD to determine relevant statistics of current AD and Azure objects, including users, accounts, groups, organizational units (OUs), computer objects, and related identity objects
- Review AD configurations, processes, and documentation to understand the client’s current deployment and operating model.
- Identify configuration and operational gaps in the client’s AD domains, infrastructure, architecture, and deployment.
- Prioritize identified gaps based on criticality and risk.
- Provide recommendations to address critical gaps and risks across AD and Entra ID environments.
- Discover and assess current processes for AD group management, AD group policy management, and AD account management.
- Suggest modifications and refinements to existing processes and create new processes if required.
- Determine the resources and skills necessary to complete remediation activities and achieve defined milestones.
- Provide an estimated budget to accomplish remediation as outlined during the assessment phases.
- Leverage client tools such as ADUC (Active Directory Users & Computers), ManageEngine, StealthAUDIT, or other AD scanning utilities as needed to accomplish data-gathering activities.
- Strong experience as an Active Directory Architect, including domain consolidation, AD assessment, and enterprise identity infrastructure review.
- Hands-on knowledge of Active Directory forest, site, domain, OU, security group, authentication, and group policy design.
- Experience assessing Azure/Entra ID deployments and hybrid identity environments.
- Ability to run and interpret PowerShell queries against AD domains to gather statistics on users, accounts, groups, OUs, computer objects, and related AD/Azure objects.
- Ability to identify configuration and operational gaps and prioritize them based on criticality and risk.
- Experience reviewing AD configurations, processes, and documentation.
- Working knowledge of tools such as ADUC, Group Polcies, DNS, AD Trusts, AD Sites and services, AD Replications, and other AD scanning utilities.
- Ability to provide practical recommendations, remediation planning inputs, resource estimates, skill requirements, and budget estimates.
- Strong communication skills to document findings, recommendations, risks, and remediation plans for stakeholders.
- Disaster Recovery & Backup, review AD forest recovery readiness, backup schedules, and Azure Entra disaster recovery setup.
- Monitoring & Alerting, Evaluate monitoring tools (SCOM, ManageEngine, Azure Monitor) and alert thresholds for AD/Entra events.
- Privileged Access Management, Assess privileged account handling, tiered admin models, and PAM/JIT/JEA usage.
- Certificate & PKI Integration, Review AD CS/PKI setup, certificate lifecycle management, and Entra authentication integration.
- Hybrid Identity & Federation, Evaluate ADFS, Pass‑through Authentication, Seamless SSO, and hybrid identity configurations.
- Conditional Access & MFA, Review conditional access policies, MFA enforcement, and exception handling.
- Lifecycle Management, Assess joiner/mover/leaver processes, automation, and HR system integration.
- Audit & Compliance, Review logging, audit trails, and compliance with ISO, SOC2, GDPR, etc.
- Patch & Update Management, Validate patch/update cadence for Domain Controllers and Entra connectors.
- Third‑Party Integrations, Identify external apps/services integrated with AD/Entra and assess their security posture.
About Simeio and What We Do
Simeio has over 650 talented employees across the globe. We have offices in USA (Atlanta HQ and Texas), India, Canada, Costa Rica, and UK.
Founded in 2007, and now backed by private equity company ZMC, Simeio is recognized as a top IAM provider by industry analysts.
Alongside Simeio’s identity orchestration tool, Simeio IO’ - Simeio’ is also partners with industry leading IAM software vendors to provide access management, identity governance and administration, privileged access management and risk intelligence services across on-premises, cloud, and hybrid technology environments.
Simeio provides services to numerous Fortune 1000 companies across all industries including financial services, technology, healthcare, media, retail, public sector, utilities, and education.
Diversity & Inclusion
Simeio is an equal opportunity employer. If you require assistance with completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to our recruitment team - [email protected].
About Your Application
We carefully review every application we receive. If your skills and experience match our needs, we will be in touch. If you do not hear from us within 10 days, please do not be discouraged—we may retain your application for future opportunities. We also encourage you to check our careers page for other openings.
Skills Required
- Strong experience as an Active Directory Architect, including domain consolidation, AD assessment, and enterprise identity infrastructure review
- Hands-on knowledge of Active Directory forest, site, domain, OU, security group, authentication, and group policy design
- Experience assessing Azure/Entra ID deployments and hybrid identity environments
- Ability to run and interpret PowerShell queries against AD domains to gather statistics on users, accounts, groups, OUs, computer objects, and related AD/Azure objects
- Experience using SailPoint reports for AD group and account ownership and membership analysis
- Ability to identify configuration and operational gaps and prioritize them based on criticality and risk
- Experience reviewing AD configurations, processes, and documentation
- Working knowledge of ADUC, ManageEngine, StealthAUDIT, and other AD scanning utilities
- Ability to provide practical recommendations, remediation planning inputs, resource estimates, skill requirements, and budget estimates
- Strong communication skills to document findings, recommendations, risks, and remediation plans for stakeholders
- Prior experience with large-scale AD domain consolidation projects
- Experience supporting remediation roadmap planning for AD, Azure/Entra ID, and identity governance environments
- Familiarity with identity governance tools and reporting approaches, especially SailPoint
What We Do
Customers of all sizes globally rely on Simeio to help secure their organizations. An innovative and industry leader, Simeio offers professional services, Identity and Access Management (IAM) managed services and Identity as a Service (IDaaS). Its full range of services is powered by an industry-first IAM Virtualization Platform delivered via Simeio's Identity SOC. Simeio's Identity SOC is the first and only solution of its kind designed specifically to operate, monitor, and defend complex multi-vendor IAM infrastructures and deliver actionable business intelligence. Simeio's client base is expanding as interest in identity and access management and IT governance, risk and compliance grows across all sectors. Headquartered in Atlanta, Georgia, Simeio has operations in India, the United Kingdom, Europe, across North America, South America and Canada. We are a cutting-edge growing company with a strong dedication to our employees and their opportunity for growth and success. Simeio offers a state-of-the-art technology office with plans for continued growth and expansion. Our company culture is crucial to those driven for success with an entrepreneurial spirit, solution oriented, and individual contributors, as well as, team players.

.png)

.png)





