AD security engineer
Full Time | Gurugram | India
Role Overview
The Active Directory Security Engineer is responsible for securing, hardening, and maintaining on-premises Microsoft Active Directory (AD DS) environments. The role focuses on protecting AD infrastructure from credential theft, privilege escalation, lateral movement, and domain compromise through robust security architecture, controls, monitoring, and incident response.
The role requires deep technical expertise in Windows authentication internals, advanced threat mitigation, and large-scale AD environments, along with leadership in governance, standards, and secure design.
Active Directory Security & Hardening
· Secure and maintain Active Directory Domain Services (AD DS) environments
· Design and implement AD security baselines aligned with Microsoft best practices
· Apply tiered administration model (Tier 0, Tier 1, Tier 2)
· Harden domain controllers, FSMO roles, and replication topology
· Secure authentication protocols (Kerberos, NTLM, LDAP, LDAPS)
· Strong hands-on expertise in Active Directory Domain Services
· Deep understanding of Windows authentication and authorization mechanisms
· Experience securing multi-domain and multi-forest environments
· Proficiency in PowerShell for AD administration and security automation
· Strong troubleshooting skills for AD replication, DNS, and authentication failures