Active Directory & Entra ID Engineer
HybridFull-timeSenior · 6-8 yearsH1B likely
About this role
About Saarthee:
Saarthee is a Global Strategy, Analytics, Technology and AI consulting company, where our passion for helping others fuels our approach and our products and solutions. Our diverse and global team work with one objective in mind: Our Customers’ Success. At Saarthee, we are passionate about guiding organizations towards insights fueled success. That’s why we call ourselves Saarthee–inspired by the Sanskrit word ‘Saarthi’, which means charioteer, trusted guide, or companion. Cofounded in 2015 by Mrinal Prasad and Shikha Miglani, Saarthee already encompasses all the components of Data Analytics consulting. Saarthee is based out of Philadelphia, USA with office in UK and India.
Position Summary:
We are seeking a skilled Active Directory & Entra ID Engineer (L2) to support and maintain enterprise Identity and Access Management (IAM) services. The role involves managing day-to-day operations of Active Directory and Microsoft Entra ID (Azure AD) environments, ensuring availability, security, and compliance. The ideal candidate will have strong hands-on experience in AD and Entra ID administration, troubleshooting complex identity issues, and implementing automation, while working independently and collaborating closely with cross-functional engineering and IAM teams.
Your Role Responsibilities and Duties:
Active Directory Administration:
- Administer, manage, and support Domain Controllers across multiple domains and forests
- Perform promotion and demotion of domain controllers as required
- Manage forest-level administration, domain and forest trusts, and functional levels
- Configure and maintain Active Directory Sites and Services for optimized replication and authentication
- Design, implement, and manage Group Policies (GPOs) across enterprise environments
- Perform regular AD health checks, database maintenance, and replication remediations
- Manage SYSVOL, Global Catalog servers, FSMO roles, and Windows Time Services
- Implement and maintain AD backup and recovery strategies
- Build, configure, and troubleshoot Windows domain controllers (physical and virtual)
- Ensure vulnerability management and patch compliance for AD infrastructure
- Install and configure monitoring agents and support tools on domain controllers
- Manage Certificate Services and provide advanced support for PKI environments
- Administer user, group, and service accounts in Active Directory
- Manage roaming profiles, folder redirection, and cloud storage access controls
- Willingness to work in a 24×7 support environment
Hybrid Identity & Entra ID (Azure AD):
- Build, configure, and manage Entra Connect / Entra Sync servers
- Manage synchronization rules and resolve sync issues between AD and Entra ID
- Administer Azure roles, Administrative Units, and RBAC in Entra ID
- Manage Entra ID Application Registrations (OIDC and SAML-based)
- Design and implement Conditional Access Policies for secure access management
- Manage custom domains, service principals, privileged accounts, and dynamic groups
- Provide advanced support for Privileged Identity Management (PIM)
- Collaborate with IAM teams to integrate OKTA or other IAM tools
Operational Excellence & Support:
- Act as the first point of escalation for identity-related incidents and service requests
- Troubleshoot AD/Entra authentication, connectivity, and access issues
- Follow incident, problem, and change management processes
- Document issues, root causes, and resolutions in ticketing systems
- Develop and maintain standard operating procedures (SOPs)
- Participate in on-call rotations and after-hours support
- Escalate complex issues to SMEs with appropriate diagnostics
Automation, Reporting & Documentation:
- Use PowerShell and scripting tools for automation and reporting
- Maintain system configurations, health reports, and service dashboards
- Assist in developing automation scripts for account and environment management
- Ensure technical documentation and knowledge base articles are accurate and up to date.
Required Skills and Qualifications:
- 6–8 years of hands-on experience in Active Directory and Entra ID administration
- Strong understanding of Windows Server OS, DNS, PKI, and authentication concepts
- Hands-on experience with PowerShell scripting for identity and server management
- Good understanding of networking fundamentals and cloud identity concepts
- Familiarity with IAM tools such as OKTA, Ping, or similar (preferred)
- Excellent troubleshooting, communication, and documentation skills
- Ability to work independently and collaborate effectively in a team environment
Preferred Qualifications
- Engineering Graduate or equivalent qualification
- Microsoft Certified: Windows Server Hybrid Administrator Associate
- Microsoft Certified: Identity and Access Administrator (SC-300)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- ITIL Foundation Certification (preferred)
What we Offer:
- Opportunity to work in large-scale enterprise IAM environments
- Exposure to hybrid identity and cloud security architectures
- Hands-on experience with automation and modern identity platforms
- Collaborative and professional engineering culture
- Competitive compensation aligned with market standards.
