
Senior Active Directory Engineer - Riyadh📣 Job Ad
| Contract Type | Full-time | |
| Workplace type | On-site | |
| Location | Riyadh |
About the Role
Alnafitha IT is seeking a Senior Active Directory Engineer to join our team in Riyadh, Saudi Arabia. This role is responsible for maintaining the operational stability and security of a major banking client's Active Directory environment. The position also supports a significant identity modernization initiative, acting as the on-site technical liaison between the client and Alnafitha IT's global operations team to ensure the seamless execution of planned upgrades and daily business operations. This role is suited for an experienced professional who can manage ongoing operational demands alongside strategic project delivery within complex, regulated environments.
Key Responsibilities
- Monitor Active Directory health, including replication status, FSMO roles, SYSVOL integrity, event logs, and domain controller performance.
- Conduct daily health checks using tools like DCDIAG, REPADMIN, and NETDIAG, and perform proactive remediation.
- Manage DNS hygiene, ensuring proper scavenging, removal of stale records, and configuration of DNSSEC.
- Ensure accurate time synchronization by verifying the PDC emulator points to a reliable NTP source.
- Oversee backup success, including system state and full forest backups, and periodically test restore procedures.
- Apply operating system, security, and Active Directory cumulative updates during approved maintenance windows.
- Participate in planning sessions with global and local teams for changes such as forest consolidation, domain migration, schema upgrades, security overhauls, and site topology redesigns.
- Deploy new domain controllers or upgrade existing ones as part of modernization efforts.
- Modify site links, subnets, and replication schedules to optimize AD performance.
- Restructure Organizational Units (OUs) and migrate objects using tools like ADMT, PowerShell, and Quest.
- Implement new Group Policy Objects (GPOs) or refactor existing ones.
- Configure or reconfigure forest and domain trusts.
- Migrate service accounts to Group Managed Service Accounts (gMSA).
- Perform pre-change validation and testing in lab or staging environments before production execution.
- Execute planned changes during approved maintenance windows, respecting banking operational hours.
- Validate post-change health and performance, and execute rollback procedures if necessary.
- Maintain an Active Directory security baseline aligned with industry standards (CIS, NIST) and banking regulations (FFIEC, PCI, SWIFT CSP).
- Manage and monitor privileged groups to detect and prevent unauthorized changes.
- Review and clean up stale user, computer, and service accounts monthly.
- Enforce Kerberos AES encryption, restrict NTLM usage, and enable LDAP signing and channel binding.
- Manage and rotate service account credentials using solutions like LAPS and gMSA.
- Assist with the implementation and management of privileged access management (PAW) solutions, Just-In-Time (JIT) access, and break-glass accounts.
- Ensure audit policies are configured to forward logs to the SIEM system and investigate anomalies.
- Act as the primary technical liaison between the global Active Directory team and local bank operations.
- Participate in weekly design and status calls with the global office during the major change initiative.
- Translate global Active Directory standards and best practices into local implementation plans.
- Report on local environment health, identified risks, and change progress.
- Escalate issues requiring global decisions, such as schema changes or cross-forest trust policies.
- Diagnose and resolve Active Directory-related incidents, including authentication failures, replication breaks, GPO application issues, account lockouts, and Kerberos errors.
- Perform root cause analysis for recurring or critical issues and implement permanent solutions.
- Support application teams with Active Directory integration challenges, such as SPN misconfigurations, delegation issues, and permission problems.
- Participate in security incident response activities when Active Directory compromise is suspected.
- Maintain up-to-date documentation, including AD topology diagrams, domain controller inventory, FSMO role locations, site link configurations, GPO inventories, privileged group memberships, and service account lists.
- Document all changes performed during the major modernization initiative.
- Produce troubleshooting runbooks for common Active Directory issues.
- Provide training sessions for local junior administrators and global office teams.
- Maintain and regularly test Active Directory forest recovery procedures.
- Ensure backup integrity and the availability of off-site or air-gapped copies for ransomware resilience.
- Participate in annual Disaster Recovery (DR) drills.
- Provide regular status reports covering health metrics, change progress, security findings, incident summaries, and planned activities.
- Track and report on Key Performance Indicators (KPIs) such as domain controller uptime, replication latency, authentication success rates, backup success rates, stale object reduction, and audit log coverage.
Qualifications and Requirements
- Bachelor’s degree in Computer Science, Information Technology, or a related field, or equivalent practical experience.
- A minimum of 5 years of hands-on experience administering enterprise Active Directory environments.
- Proven experience delivering Active Directory migration, consolidation, or modernization projects.
- Experience operating within formal change management processes and approved maintenance windows in a 24/7 production environment.
Required Skills
- Deep expertise in Active Directory Domain Services, DNS, DHCP, Group Policy, and Kerberos/NTLM authentication.
- Strong PowerShell scripting and automation skills.
- Hands-on experience with Active Directory migration tooling such as ADMT and Quest Migration Manager.
- Knowledge of Active Directory security hardening principles and tools, including LAPS, gMSA, tiered administration, PAW, and JIT.
- Familiarity with security frameworks like CIS and NIST.
- Experience with SIEM platforms such as Splunk, Microsoft Sentinel, or QRadar, and configuring audit log forwarding.
- Proficiency in backup and recovery procedures, including Active Directory forest recovery.
- Working knowledge of hybrid identity solutions, specifically Entra ID / Azure AD Connect, is considered a plus.
- Strong analytical and root-cause troubleshooting skills.
- Clear written and verbal communication skills in English; proficiency in Arabic is an advantage.
- Ability to collaborate effectively with global and local stakeholders across different time zones.
- Discretion and reliability are essential for operating within a regulated banking environment.
Work Environment and Conditions
This is a full-time position based in Riyadh, Saudi Arabia. The standard working week is Sunday to Thursday during normal working hours. Annual leave is provided in accordance with KSA labor law. Work required outside normal working hours or days will be compensated as overtime. Change activities may necessitate night and weekend maintenance windows, scheduled to minimize impact on banking operations.
Microsoft certifications (*, MCSE, Identity and Access Administrator) are preferred. Security certifications such as Security+, GIAC, or CISSP are considered an advantage.
Requirements
- Requires 5-10 Years experience
Similar Jobs
You may also like
- Related Senior Active Directory Engineer - Riyadh Opportunities
- Marketing Specialist Jobs in Riyadh
- Chef Jobs in Riyadh
- Branch Supervisor Jobs in Riyadh
- Interior Architect Jobs in Riyadh
- Business Development Supervisor Jobs in Riyadh
- Other Job Fields in Riyadh
- Marketing Specialist Jobs in Riyadh
- Chef Jobs in Riyadh
- Branch Supervisor Jobs in Riyadh
- Interior Architect Jobs in Riyadh
- Business Development Supervisor Jobs in Riyadh
- Barista Jobs in Riyadh
- Receptionist Jobs in Riyadh
- Hairdresser Jobs in Riyadh
- Sales Representative Jobs in Riyadh
- Human Resources Specialist Jobs in Riyadh
- Explore Jobs Across Saudi Arabia
- Purchasing Manager Jobs in Makkah
- Chef Jobs in Makkah
- Speech Therapist Jobs in Riyadh
- Sales Manager Jobs in Tabuk
- Nursery Teacher Jobs in Tabuk
- Electric Appliances Maintenance Technician Jobs in Riyadh
- Sales Coordinator Jobs in Jazan
- General Security Manager Jobs in Dammam
- Business Analyst Jobs in Riyadh
- Guest Services Associate Jobs in Riyadh