Title: Azure/Active Directory Administrator
Duration: 6 Months
Location: Raleigh, NC
Client: State of NC
***This is a six month engagement. However, the AOC roles can not cross fiscal years. There will be an extension after 06/30/22.
***The candidate will be allowed to work remotely until all staff return to site. At that point the candidate will be required to come onsite.
***The candidate will need to come onsite the first day to collect equipment.
The NC Administrative Office of the Courts (NCAOC), Technology Services Division (TSD), seeks a qualified Active Directory/Azure Administrator to manage the administration, implementation, and maintenance of Active Directory and Azure infrastructures. This position provides 24x7x365 operational support for 25,000+ Judicial and non-Judicial branch users across the state. On call responsibilities include evenings and weekends to support all described infrastructure.
As the subject matter expert for AD/Azure, the person in this position provides non-supervisory technical leadership for the team and ensures that all new and existing AD/Azure technologies are successfully deployed and maintained.
Responsibilities include but are not limited to the following:
- Active Directory Administration
- Manage operation, health, and security of a multi-site domain.
- Manage on-prem active directory environment and associated services like DNS, certificate services, etc.
- Administer and support NCAOC Identity Management platform.
- Azure AD Administration
- Administer and maintain the hybrid and cloud-only identities across multiple Azure AD tenants.
- Create and maintain Conditional Access Policies.
- Support SAML and OAuth application configurations.
- Active Directory Security
- Manage Group Policy Objects (GPOs).
- Support on-prem, hybrid, and cloud identity and access management.
- Support identity and asset lifecycle management.
- Assist with potential compromised account investigations.
- Create and tune DLP and AIP policies.
- Special Data Requests
- Handle access investigation requests as required.
- Respond to data access and loss investigations.
- General Administration
- Perform troubleshooting, root cause analysis, and performance benchmarking.
- Respond to help desk tickets.
- Generate and distribute monthly statistical reporting.
- Provide support for issues ranging from single-user issues to system-wide problems.
- Assist with periodic testing of disaster preparedness for the NC Judicial Center Data Center.
- And other assigned duties.
The person in this position reports to the Distributed Computing Manager. Work hours are 8:00 AM - 5:00 PM, Monday - Friday plus on-call responsibilities as scheduled.
Skills and Abilities:
Knowledge of: advanced level administrative knowledge of Microsoft Active Directory, Azure Active Directory, and hybrid identities; and familiarity with creating and tuning data loss prevention policies and data classification policies.
Skills in: managing and monitoring user activity and risk for on-prem, cloud only, and hybrid identities.
Ability to: to create and manage on-prem, cloud only, and hybrid identities across multiple tenants either through the GUI or programmatically using PowerShell; utilize configuration management to meet the goals of security and compliance; create and manage Azure Conditional Access Policies to meet organizational access and security objectives; work efficiently and effectively with little oversight; manage a mature operation based on repeatable processes and appropriate metrics; communicate effectively with both technical and non-technical stakeholders at all levels; diagnose issues and apply appropriate trouble-shooting analysis; prepare and present facts clearly and concisely in both written and oral form; evaluate and document processes and record keeping methods; and contribute to process improvements.
Minimum Education and Experience Requirements
Bachelor's degree in computer science or another related information technology field and four (4) years of IT related work experience; or an equivalent combination of education and experience.
Management recommends that candidates have five (5) years of directly related experience in Windows Active Directory and three (3) years of directly related experience to Azure Active Directory Administration within an enterprise environment.
Management prefers candidates with:
• experience with PowerShell tool scripting.
• cloud services management experience, preferably Azure and AWS.
• IAM experience within multi domain and cloud tenant environments.
• experience writing complex search queries in response to security incidents.
• experience configuring custom monitoring KPIs.
• knowledge of common security standards such as PCI, FERPA, and NIST.
• familiarity with NC Statewide security standards.
Skills:
| Skill | Required / Desired | Amount | of Experience |
Group Policy Management | Required | 5 | Years | |
| | | | | |
PowerShell Scripting Experience | Required | 5 | Years |
Active Directory Management | Required | 8 | Years |
Azure Active Directory Management | Required | 3 | Years |
AD Connect Troubleshooting | Required | 3 | Years |
ManageEngine AD-Audit Tool experience | Highly desired | 2 | Years |
Microsoft Identity Manager Management | Highly desired | 3 | Years |