Jobs and Careers
AT

Active Directory & Identity and Access Management Architect

Atos
Braşov, Romaniafull_timeVerifiedPosted 15 May 2025

About the role

<p><span><span>Eviden, part of the Atos Group, with an annual revenue of circa € 5 billion is a global leader in data-driven, trusted and sustainable digital transformation. As a next generation digital business with worldwide leading positions in digital, cloud, data, advanced computing and security, it brings deep expertise for all industries in more than 47 countries. By uniting unique high-end technologies across the full digital continuum with 47,000 world-class talents, Eviden expands the possibilities of data and technology, now and for generations to come.</span></span></p> <p><span><span><b>Active Directory &amp; Identity and Access Management Architect</b></span></span></p> <p> </p> <p><span><span>We are looking for an experienced <b>Active Directory &amp; IAM Architect</b> to lead the design and implementation of a comprehensive <b>Identity and Access Management (IAM)</b> strategy with a strong focus on <b>Privileged Access Management (PAM)</b>, fully deployed <b>on-premises</b>. The role involves securing and managing <b>Active Directory</b> environments, implementing <b>PAM solutions</b>, and ensuring that all identity and access-related processes align with best security practices and compliance requirements, all within an on-premises infrastructure.</span></span></p> <p align="center"> </p> <p><span><span><b>Key Responsibilities:</b></span></span></p> <p> </p> <ul> <li><span><span>Lead the design and deployment of a secure <b>Active Directory (AD)</b> infrastructure, ensuring high availability, redundancy, and compliance within an <b>on-premises</b> environment.</span></span></li> <li><span><span>Architect and implement a complete <b>Identity and Access Management (IAM)</b> framework to manage users, groups, roles, and policies on an on-premises basis.</span></span></li> <li><span><span>Implement and manage <b>Privileged Access Management (PAM)</b> solutions such as <b>CyberArk</b>, <b>BeyondTrust</b>, or similar, ensuring that privileged accounts and access are fully controlled, monitored, and secured.</span></span></li> <li><span><span>Oversee the deployment and management of <b>Active Directory Federation Services (ADFS)</b>, <b>LDAP</b>, and <b>Kerberos</b> for secure authentication and internal identity federation.</span></span></li> <li><span><span>Design and enforce <b>multi-factor authentication (MFA)</b> and <b>single sign-on (SSO)</b> solutions strictly within the on-premises environment.</span></span></li> <li><span><span>Lead the implementation of <b>role-based access control (RBAC)</b> and <b>attribute-based access control (ABAC)</b> for IAM processes, ensuring robust identity governance.</span></span></li> <li><span><span>Ensure that all identity-related processes, including <b>user provisioning</b>, <b>de-provisioning</b>, and <b>identity lifecycle management</b>, are executed using on-premises tools and platforms.</span></span></li> <li><span><span>Collaborate with security and networking teams to align <b>IAM</b> solutions with the overall on-premises security architecture.</span></span></li> <li><span><span>Design, configure, and manage <b>Active Directory</b> replication, trust relationships, group policies, and organizational units (OUs).</span></span></li> <li><span><span>Develop and document <b>technical solutions</b> for on-premises IAM and PAM systems, including architecture diagrams, deployment guides, and SOPs.</span></span></li> <li><span><span>Continuously monitor and assess <b>Active Directory</b> and <b>PAM systems</b> for security vulnerabilities and operational performance.</span></span></li> </ul> <p align="center"> </p> <p><span><span><b>Required Skills &amp; Experience:</b></span></span></p> <p> </p> <ul> <li><span><span>Minimum 5-7 years of experience in <b>Active Directory</b> architecture and <b>IAM</b> within an <b>on-premises</b> environment.</span></span></li> <li><span><span>Proven experience with <b>Privileged Access Management (PAM)</b> tools such as <b>CyberArk</b>, <b>BeyondTrust</b>, or other enterprise-level on-premises solutions.</span></span></li> <li><span><span>Deep expertise in managing and securing <b>Active Directory</b> environments, including replication, trusts, and group policies.</span></span></li> <li><span><span>Experience in implementing <b>multi-factor authentication (MFA)</b> and <b>single sign-on (SSO)</b> within an on-premises framework.</span></span></li> <li><span><span>Familiarity with <b>role-based access control (RBAC)</b> and <b>attribute-based access control (ABAC)</b> models.</span></span></li> <li><span><span>Experience with <b>identity lifecycle management</b>, including user provisioning and de-provisioning, specifically within a controlled on-premises environment.</span></span></li> <li><span><span>Knowledge of <b>network security</b> protocols such as <b>Kerberos</b>, <b>LDAP</b>, and <b>SSL/TLS</b> for securing internal communications.</span></span></li> <li><span><span>Strong understanding of security compliance

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Atos

View company profile →