The Role
This role offers the opportunity to be part of a large-scale enterprise security transformation programme within a leading international retail and consumer business. The successful candidate will play a key role in strengthening the organisation's identity and access management landscape by addressing critical Active Directory security vulnerabilities, reducing cyber risk, and improving overall security resilience.
The role provides exposure to complex, multi-domain Active Directory environments and the opportunity to work with cutting-edge Microsoft identity and security technologies, including:
Active Directory Security Hardening and Remediation
Active Directory Certificate Services (AD CS)
Microsoft Identity & Access Management solutions
Group Managed Service Accounts (gMSA)
Privileged Access Management (PAM)
Kerberos Authentication & Delegation Controls
Enterprise Security Governance and Risk Management
Large-scale Production Change and Transformation Programmes
Working alongside senior security consultants, architects, project managers and infrastructure specialists, the individual will directly influence the delivery of a strategic security programme that enhances operational stability, regulatory compliance, and cyber resilience across a global enterprise environment.
Your responsibilities:
Lead Active Directory security remediation activities across complex enterprise environments.
Perform administration and governance of Active Directory at Domain Admin and Enterprise Admin levels.
Assess, prioritize, and remediate identity-related security vulnerabilities, misconfigurations, and privilege escalation risks.
Review and harden Active Directory Certificate Services (AD CS), authentication, and delegation configurations.
Manage privileged access controls, administrative groups, service accounts, and permissions governance.
Coordinate remediation activities across infrastructure, security, server, database, and application support teams.
Plan, implement, and govern production changes while ensuring minimal business disruption and effective risk management.
Produce remediation documentation, validation evidence, and executive-level progress reporting.
Collaborate with security architects, project managers, and customer stakeholders to drive remediation outcomes.
Support continuous improvement initiatives to strengthen identity security, compliance, and cyber resilience.
Your Profile
Essential skills/knowledge/experience:
Strong hands-on experience administering and securing Active Directory in large enterprise environments.
Proven expertise in Active Directory security remediation, hardening, and privilege reduction initiatives.
Deep knowledge of Active Directory Certificate Services (AD CS) and certificate-based authentication security.
Strong understanding of Kerberos authentication, delegation models, SPNs, and service account security.
Experience reviewing and remediating AD permissions, ACLs, privileged groups, and administrative access paths.
Knowledge of Microsoft Identity & Access Management, Privileged Access Management (PAM), and least-privilege principles.
Experience managing security remediation programmes within production environments, including change and risk management.
Ability to coordinate activities across infrastructure, security, application, database, and support teams.
Strong analytical, troubleshooting, and root-cause investigation skills for complex identity and security issues.
Excellent stakeholder management, communication, and documentation skills with experience working directly with customers and senior leadership.
Desirable skills/knowledge/experience:
Microsoft Entra ID (Azure AD) and hybrid identity management experience.
Experience with CyberArk, Beyond Trust, Delinea or other Privileged Access Management (PAM) platforms.
Exposure to Microsoft Defender for Identity and identity threat detection solutions.
Experience implementing Tiered Administration, ESAE/Red Forest, or other privileged access security models.
Knowledge of CIS, Microsoft Security Baselines, and industry best practices for Active Directory security.
Familiarity with vulnerability assessment tools such as PingCastle, BloodHound, Purple Knight, or similar AD security assessment platforms.
Experience supporting large-scale security transformation or remediation programmes in global enterprise environments.
Knowledge of SQL Server security, authentication, and privileged access governance.
Relevant certifications such as Microsoft Certified: Identity and Access Administrator, Security Operations Analyst, CISSP, CISM, or equivalent.
Experience working within regulated environments with strong governance, audit, and compliance requirements.
AD Security Remediation SME in Reading employer: Tcs Uk
As a Provisioning Engineer at our company, you will thrive in a dynamic work culture that prioritises innovation and collaboration. We offer competitive benefits, including professional development opportunities and a supportive environment that encourages growth in the rapidly evolving telecom sector. Located in a vibrant area, our team enjoys a balance of work and life, making it an excellent place for those seeking meaningful and rewarding employment.