Job Summary
We are seeking experienced Active Directory Engineers to support a critical infrastructure initiative: the full rebuild of our domain environment within a new Azure Landing Zone. You will work alongside our internal AD and Azure Operations teams to promote new Domain Controllers, resolve infrastructure issues, and systematically decommission legacy on-premises and Azure DCs. This is a hands-on, technically demanding engagement requiring deep Active Directory expertise, strong collaboration skills, and comfort working in complex hybrid cloud environments.
Key Responsibilities
Phase 1 — Domain Controller Promotion (Azure Landing Zone) • Promote new Domain Controllers within the Azure Landing Zone environment • Begin with dev/test domains and progress through production environments • Identify and resolve issues encountered during promotion, including: o Firewall and network configuration o Security policy alignment o DNS and replication troubleshooting • Support scripting and automation of DC promotion tasks (~80 DCs in scope) Phase 2 — DC Decommissioning (On-Premises & Azure) • Analyse DNS debug logs to identify active DC dependencies • Conduct scream testing to validate readiness for decommissioning • Coordinate with AD and Azure Ops teams to safely decommission legacy DCs • Manage the complexity of Azure DC decomissions, which require additional analysis • Adapt to scope changes as the decommission programme evolves
Skill Requirements
Strong hands-on experience with Active Directory (domain design, DC promotion, replication, DNS, Group Policy) • Experience working in hybrid environments (on-premises AD + Azure / Azure AD / Entra ID) • Familiarity with Azure Landing Zone architecture and Azure networking concepts • Proven ability to troubleshoot firewall rules, network routing, and security policies in the context of AD • Experience with DNS debug log analysis and dependency mapping • Strong communication and collaboration skills — you will work closely with internal ops teams
Other Requirements
PowerShell scripting — ability to script and automate DC promotion/decommission workflows is a significant advantage • Experience with large-scale DC decommissioning programmes • Familiarity with scream testing methodologies for AD infrastructure