Active Directory SME - DV Cleared
Randstad · Erskine, Scotland
Active Directory SME - DV Cleared at Randstad, based in Erskine, Scotland. This is a permanent role.
- Salary
- Competitive
- Location
- Erskine, Scotland
- Contract
- Permanent
- Posted
- 2 days ago
- Closes
- 8 Sep 2026
- Sector
- Security
Reference PR-1534855
About the role
Active Directory SME - DV Cleared
We are seeking a highly skilled Microsoft Active Directory Subject Matter Expert (SME) to lead the design, implementation, and optimization of enterprise directory services within secure, high-assurance environments. As a key member of our build engineering team, you will be responsible for implementing sophisticated cloud solutions and ensuring the integrity of identity services for a critical UK secure account.
Key Responsibilities
Lead the architecture, design, and evolution of on-premises Microsoft Active Directory environments.
Implement secure AD architectures, including domains, forests, trusts, and replication strategies.
Create Cloud landing zones and develop CloudFormation templates for base infrastructure.
Develop and enforce Group Policy (GPO) strategies aligned with high-security requirements.
Define and implement tiered administration models and privileged access controls.
Onboard customer accounts to Service Now and publish standard/custom templates.
Required Experience & Skills
Proven experience in an Active Directory Architect or Senior SME role
Deep hands-on expertise with:
Microsoft Active Directory (multi-domain/forest environments)
Group Policy design and management
DNS, DHCP, and core supporting infrastructure
Strong experience in designing and implementing enterprise-scale AD environments
Demonstrable experience producing high-quality design documentation, including:
High-Level Designs (HLDs)
Low-Level Designs (LLDs)
Security architecture documentation
Operational procedures and runbooks
Strong understanding of identity security, including:
Tiered administration models
Least privilege access
Privileged Access Workstations (PAWs)
Privileged access Management Toolset
Knowledge of authentication protocols (Kerberos, NTLM, LDAP, SAML, OAuth)
Experience with PowerShell scripting and automation
Familiarity with integrating AD into enterprise security and monitoring tooling (e.g., SIEM)
Excellent stakeholder engagement, communication, and documentation skills
Industry Experience
Experience working within the Defence and/or Aerospace sector is highly desirable
Familiarity with policies, standards, and security frameworks (e.g., JSP series, NCSC guidance)
Familiarity with high-security, regulated environments and secure system delivery
Desirable Certifications
Microsoft certifications (e.g., Identity and Access Administrator, Windows Server)
CISSP, CISM, or equivalent security certifications
TOGAF or other architecture frameworks (desirable)
Lead the architecture, design, and evolution of on-premises Microsoft Active Directory environments.
Implement secure AD architectures, including domains, forests, trusts, and replication strategies.
Create Cloud landing zones and develop CloudFormation templates for base infrastructure.
Develop and enforce Group Policy (GPO) strategies aligned with high-security requirements.
Define and implement tiered administration models and privileged access controls.
Onboard customer accounts to Service Now and publish standard/custom templates.
The role is idealaly based on-site in Erskine but we can also consider appliacnts who can work hybrisd form Farnborough, Corsham or Newcastle.
So if you have the required level of Clearance to DV level then apply today as I have interview slots ready to be filled.
Randstad Technologies is acting as an Employment Business in relation to this vacancy.
skills
cloud,cloud services
education
university
Reference: PR-1534855 · Posted 2 days ago · Closes 8 Sep 2026 · Listed via Randstad
Apply for this job
This role is listed via Randstad. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.