FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive expertise in administering Active Directory Certificate Services (AD CS) and enterprise PKI, with strong skills in hybrid identity synchronization and certificate lifecycle management. Proficient in scripting for automation and compliance with security standards such as SOX, PCI-DSS, NIST, and ISO 27001.
Highest-signal resume keywords
Active Directory Certificate Services (AD CS)Hybrid Identity SynchronizationPowerShell ScriptingPKI ArchitectureMicrosoft Entra ID
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Active Directory AdministrationCertificate Lifecycle ManagementLDAP Directory ServicesSSL/TLS Certificate DeploymentSAML AuthenticationMFA ImplementationIncident ResponseLog AnalysisCertificate AutomationRoot Cause Analysis
Soft Skills
Strong Communication SkillsDocumentation SkillsTraining Ability
Tools & Technologies
Azure AD ConnectEntra ConnectSIEM IntegrationREST APIsDNSKerberosNTLM
Certifications & Qualifications
Microsoft Certified: Identity and Access Administrator (SC-300)
Industry Keywords
SOX CompliancePCI-DSS ComplianceNIST StandardsISO 27001Zero Trust Security Principles
Tech Stack
Tools & technologiesAWSAzureCloudCyber SecurityDNSGoogle Cloud PlatformPython
About the role
Key responsibilities & impact- Administer and maintain Active Directory Certificate Services (AD CS), including root and issuing certificate authorities, certificate templates, and enrollment policies.
- Manage the end-to-end certificate lifecycle, including issuance, renewal, revocation, expiration monitoring, and CRL/OCSP.
- Administer and maintain Active Directory and LDAP directory services, including forest/domain architecture, replication, group policy, OU structure, and schema management.
- Manage hybrid identity synchronization via Azure AD Connect/Entra Connect and troubleshoot synchronization failures.
- Support Microsoft Entra ID administration, certificate-based authentication, conditional access, and device trust.
- Configure and manage SSL/TLS certificate deployment for servers, applications, and network devices.
- Troubleshoot directory and certificate connectivity issues involving DNS, Kerberos/NTLM, LDAPS, and certificate chains.
- Support authentication and authorization troubleshooting across Active Directory/LDAP, SAML, MFA, and SSO integrations.
- Develop PowerShell and Python/REST API scripts for certificate automation, directory reporting, and PKI health monitoring.
- Monitor AD CS, directory, and network logs; support SIEM integration, PKI health monitoring, and incident response.
- Apply directory and PKI security best practices and support SOX, PCI-DSS, NIST, and ISO 27001 compliance.
- Partner with Security, Infrastructure, and Application teams on certificate authority hierarchy, directory architecture changes, and migrations.
- Document procedures, configurations, and incident reports; train end users and application teams.
- Plan and execute directory and PKI disaster recovery, including CA backup/restore and forest recovery readiness.
Requirements
What you’ll need- Bachelor's degree recommended; equivalent experience considered.
- 10+ years of experience in cybersecurity, systems administration, or identity and access management, including 5+ years hands-on experience administering Active Directory Certificate Services (AD CS) and enterprise PKI.
- Strong understanding of PKI architecture, including certificate authority hierarchy, certificate templates, CRL/OCSP, and key management.
- Deep working knowledge of Active Directory and LDAP, including forest/domain design, replication, group policy, and schema administration.
- Experience with hybrid identity synchronization (Entra Connect or equivalent) and Microsoft Entra ID, including conditional access and certificate-based authentication.
- Proficiency in DNS, Kerberos/NTLM authentication, and certificate chain troubleshooting across on-premises and cloud environments (AWS, Azure, GCP).
- Experience with SAML, MFA, and SSO authentication and authorization troubleshooting.
- Scripting experience in PowerShell and Python, with working knowledge of REST APIs and certificate automation tooling.
- Experience with log analysis and SIEM integration, incident response, and root cause analysis.
- Knowledge of SOX, PCI-DSS, NIST, ISO 27001, and zero trust security principles.
- Microsoft Certified: Identity and Access Administrator (SC-300) or equivalent certification preferred; cloud platform or security certifications a plus.
- Strong communication and documentation skills, including explaining technical concepts to non-technical stakeholders and training end users and application teams.
- Ability to operate across enterprise and OpCo environments and multiple time zones and cultures.
- Alignment with Ralliant values and the Ralliant Business System (RBS).
