About the Role:The Active Directory Architect (Domain Consolidation) will support a US-based engagement focused on assessing the client’s current Active Directory (AD), Azure/Entra ID deployment, and related identity infrastructure. The role involves evaluating forest, site, domain, security group, organizational unit (OU), authentication, group policy, and deployment architecture, identifying configuration and operational gaps, and providing recommendations to address critical risks. The architect will also review existing AD management processes, gather data using tools such as PowerShell, SailPoint, ADUC, ManageEngine, and StealthAUDIT, and help define the resources, skills, and budget required for remediation.
What You’ll Do:- Assess the current state of the client’s Active Directory and Azure/Entra ID deployment, including forest design, site design, domain design, security group topology, deployment architecture, organizational unit (“OU”) design, authentication, and group policy design.
- Run PowerShell queries against the client AD to determine relevant statistics of current AD and Azure objects, including users, accounts, groups, organizational units (OUs), computer objects, and related identity objects.
- Run SailPoint out-of-the-box reports against AD connectivity to provide group and account ownership and membership information.
- Review AD configurations, processes, and documentation to understand the client’s current deployment and operating model.
- Identify configuration and operational gaps in the client’s AD domains, infrastructure, architecture, and deployment.
- Prioritize identified gaps based on criticality and risk.
- Provide recommendations to address critical gaps and risks across AD and Entra ID environments.
- Discover and assess current processes for AD group management, AD group policy management, and AD account management.
- Suggest modifications and refinements to existing processes and create new processes if required.
- Determine the resources and skills necessary to complete remediation activities and achieve defined milestones.
- Provide an estimated budget to accomplish remediation as outlined during the assessment phases.
- Leverage client tools such as ADUC (Active Directory Users & Computers), ManageEngine, StealthAUDIT, or other AD scanning utilities as needed to accomplish data-gathering activities.
What You Bring- Strong experience as an Active Directory Architect, including domain consolidation, AD assessment, and enterprise identity infrastructure review.
- Hands-on knowledge of Active Directory forest, site, domain, OU, security group, authentication, and group policy design.
- Experience assessing Azure/Entra ID deployments and hybrid identity environments.
- Ability to run and interpret PowerShell queries against AD domains to gather statistics on users, accounts, groups, OUs, computer objects, and related AD/Azure objects.
- Experience using SailPoint reports for AD group and account ownership and membership analysis.
- Ability to identify configuration and operational gaps and prioritize them based on criticality and risk.
- Experience reviewing AD configurations, processes, and documentation.
- Working knowledge of tools such as ADUC, ManageEngine, StealthAUDIT, and other AD scanning utilities.
- Ability to provide practical recommendations, remediation planning inputs, resource estimates, skill requirements, and budget estimates.
- Strong communication skills to document findings, recommendations, risks, and remediation plans for stakeholders.
Nice to have - Optional- Prior experience with large-scale AD domain consolidation projects.
- Experience supporting remediation roadmap planning for AD, Azure/Entra ID, and identity governance environments.
- Familiarity with identity governance tools and reporting approaches, especially SailPoint.
About Simeio and What We DoSimeio has over 650 talented employees across the globe. We have offices in USA (Atlanta HQ and Texas), India, Canada, Costa Rica and UK.
Founded in 2007, and now backed by private equity company ZMC, Simeio is recognized as a top IAM provider by industry analysts.
Alongside Simeio’s identity orchestration tool ‘Simeio IO’ - Simeio also partners with industry leading IAM software vendors to provide access management, identity governance and administration, privileged access management and risk intelligence services across on-premise, cloud, and hybrid technology environments.
Simeio provides services to numerous Fortune 1000 companies across all industries including financial services, technology, healthcare, media, retail, public sector, utilities and education.
Diversity & InclusionSimeio is an equal opportunity employer. If you require assistance with completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to our recruitment team - recruitment@simeio.com.
Thank you
About Your ApplicationWe carefully review every application we receive. If your skills and experience match our needs, we’ll be in touch. If you don’t hear from us within 10 days, please don’t be discouraged—we may retain your application for future opportunities. We also encourage you to check our careers page for other openings.
Simeio is an equal opportunity employer. If you require assistance with completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to any of the recruitment team at recruitment@simeio.com or +1 404-882-3700.