Company Description
A leading global commercial vehicle manufacturer specializing in trucks and buses, with a strong presence across North America, Europe, and Asia. The company is recognized for its engineering excellence, strong brand portfolio, and focus on delivering reliable and efficient transportation solutions at scale.
- Location Bangalore
- Industry Automotive
- Experience Range 5+ years
- Must-have Skills Active Directory (AD) and Tier-0 Infrastructure Automation Engineer, Active Directory Trusts, AD Replication, AI-Assisted Operations, DC Recovery, DNS, Domain Controllers, GPO, Kerberos / NTLM, Monitoring & SIEM, PAM, PowerShell automation, Runbooks, Tier-0 Security
Job Summary
The Active Directory (AD) and Tier-0 Infrastructure Automation Engineer is responsible for designing, securing, automating, and modernizing enterprise authentication platforms. The role focuses on Tier-0 security hardening, identity infrastructure resilience, Active Directory modernization, Infrastructure-as-Code, self-healing automation, and AI-assisted identity operations while maintaining strict security controls for privileged environments.
Key Responsibilities
- Own and improve Tier-0 identity infrastructure including AD DS forests/domains, Domain
- Controllers, DNS, PKI dependencies, ADFS where applicable, and privileged access pathways.
- Implement Tier-0 security hardening through secure administration tiers, PAW/SAW strategies, GPO baselines, authentication policies, and privileged group governance.
- Design and execute AD modernization initiatives including domain restructuring, consolidation/separation, trust management, and authentication redesign.
- Ensure business continuity through backup/restore drills, authoritative restores, Domain Controller recovery, tombstone/lingering object prevention, and disaster recovery readiness.
- Perform Tier-0 risk assessments and remediate delegation risks, unconstrained delegation, weak ACLs, stale privileged accounts, and legacy authentication protocols.
- Build AD operational automation using advanced PowerShell and Python, including user/group/OU lifecycle workflows, GPO deployment validation, DC health monitoring, DNS and replication checks, and privileged group reviews.
- Implement Infrastructure-as-Code patterns through automation pipelines, configuration baselines, and golden templates.
- Develop self-service identity capabilities with approval workflows, audit trails, and rollback mechanisms.
- Integrate AI-assisted workflows for incident triage, root-cause analysis, runbook recommendations, and internal knowledge management.
- Establish AI guardrails for Tier-0 environments, including data classification, redaction, privileged-secret protection, auditability, and approval gates.
- Own identity logging pipelines using platforms such as Microsoft Sentinel, Splunk, ELK, or Log Analytics.
- Develop dashboards and alerts covering AD health, authentication anomalies, replication issues, and privileged-access abuse.
- Support SOX, ISO/IEC, and industry compliance audits through evidence collection, control mapping, and remediation tracking.
- Collaborate with Cybersecurity, IAM, Networking, Endpoint Engineering, and GRC teams.
- Provide technical documentation, runbooks, architecture diagrams, and executive summaries.
- Participate in on-call and major incident bridge support for Tier-0 services when required.
Required Skills & Experience
- 5+ years of experience in Active Directory engineering/operations within large enterprise environments.
- Strong hands-on expertise in:
AD DS
Domain Controllers
Sites & Services
DNS
Kerberos / NTLM
Active Directory trusts - Strong understanding of Tier-0 security concepts, privileged administration models, and GPO security baselines.
- Experience troubleshooting AD replication, authentication failures, and Domain Controller recovery.
- Advanced PowerShell automation skills, including scripting standards, modules, and CI/CD integration.
- Familiarity with Python.
- Experience with security monitoring, identity analytics, and log analysis.
Preferred Qualifications
- Python automation experience.
- Experience implementing Infrastructure-as-Code and self-healing automation.
- Experience integrating AI-assisted operations into identity/security environments.
- Experience with Microsoft Sentinel, Splunk, ELK, or Log Analytics.
- Exposure to PAM, hybrid identity, and enterprise compliance environments.
Other Requirements
- Strong understanding of privileged/Tier-0 security boundaries.
- Ability to work with multiple security and infrastructure teams.
- Strong documentation and technical communication skills.
- Ability to participate in on-call and major incident support.
- Ability to implement AI solutions while maintaining security, compliance, auditability, and approval controls.