job summary
we are seeking a highly experienced and dedicated service manager to oversee the delivery, operations, and continuous improvement of our active directory (ad) / entra id services. the ideal candidate will have a strong background managing enterprise-scale identity and access management (iam) systems, deep knowledge of common operational scenarios, and the ability to resolve complex challenges related to ad and entra id.
as a service manager, you will coordinate with cross-functional teams to ensure service stability, security, and scalability, and act as a key contributor in driving the success of identity management initiatives for the organization.
key responsibilities
1. service management and operations:
• manage the end-to-end lifecycle of active directory (including on-prem ad ds) and azure entra id (formerly azure ad) services.
• lead operational activities, including incident management, problem resolution, change management, and upkeep of runbooks and playbooks.
• ensure system reliability, scalability, and performance by implementing best practices in monitoring, maintenance, and capacity management.
• guarantee adherence to slas and kpis for service quality and availability.
2. incident and escalation management:
• act as the point of contact for escalated ad/entra id-related incidents.
• provide expert-level support for diagnosing and resolving complex technical issues in multi-site, hybrid, and cloud-based environments.
• drive root-cause analysis and implement corrective actions to mitigate recurring issues.
3. strategic planning and improvements:
• collaborate with stakeholders to define service improvement plans for enhancing ad/entra id stability, functionality, and user experience.
• lead upgrades, migrations, and enhancements of ad and entra id infrastructure, aligning with long-term it strategy and business requirements.
• stay updated on best practices in iam and recommend innovative solutions to advance the organization’s identity management capabilities.
4. governance, security, and compliance:
• ensure compliance with corporate security policies, industry standards, and regulatory requirements regarding identity and access management.
• manage role-based access controls, group policies, and secure authentication mechanisms such as mfa, sso, and conditional access policies.
• lead regular audits and health checks of the ad/entra id environment to ensure optimal security and configuration standards.
5. collaboration and team leadership:
• work closely with it operations, engineering, architecture, and security teams to maintain cohesive identity infrastructure.
• mentor, train, and guide junior team members or it staff on key ad/entra id operations and best practices.
• partner with external service providers (if applicable) to maintain a high degree of support excellence.
6. documentation and reporting:
• maintain detailed documentation of ad and entra id processes, configurations, standards, and issue resolutions.
• provide periodic service health reports, incident analysis, and improvement recommendations to it leadership.
________________________________________
skills and qualifications
required skills:
• especially 5–7+ years of progressive experience managing enterprise-scale active directory (ad) and azure entra id services, including hybrid configurations (on-prem/cloud).
• strong expertise in:
o identity lifecycle management, including user provisioning and deprovisioning.
o domain controllers (dc), group policies (gpo), trusts, dns, and federation services (., ad fs).
o azure entra id services, including conditional access, privileged identity management (pim), and mfa.
o single sign-on (sso), kerberos authentication, and oauth/ldap protocols.
• in-depth understanding of operational challenges such as:
o account lockouts, replication issues, permissions troubleshooting, schema updates, and hybrid integration challenges.
o monitoring and resolving synchronization challenges between ad, azure ad connect, and entra id.
• experience in incident management, root-cause analysis, and service improvement in iam contexts.
• strong knowledge of powershell scripting and automation for ad/entra id tasks.
• familiarity with modern identity frameworks, such as zero trust architecture and secure access service edge (sase).
preferred skills:
• experience with certificate services (adcs) and pki management.
• familiarity with third-party iam tools, such as oim, okta, ping identity, or sailpoint, integrated with ad/entra id.
• knowledge of devops principles and integration with identity management platforms.
• azure active directory b2c implementations or other external user management configurations.
soft skills:
• strong communication and stakeholder management skills for coordinating with technical and non-technical audiences.
• proven ability to lead cross-functional teams and establish trust with diverse stakeholders.
• analytical mindset with a problem-solving approach to managing complex systems and escalations.
educational background
• mandatory: bachelor’s degree in computer science, information technology, or a related field (or equivalent work experience).
• certifications (preferred):
o relevant microsoft certifications
o itil foundation certification