AD & Entra ID Expert
13 hours ago
The Edenred Digital Center (EDC) in Bucharest, Romania is Edenred Group's new Digital hub for strategic IT projects.
The Identity expert will be responsible for designing, implementing, operating, securing, and evolving the organization's hybrid identity infrastructure, spanning on-premises
Active Directory (AD DS, AD CS) and Microsoft Entra ID.
This role ensures the availability, security, compliance, and governance of Tier 0 identity assets, supports global IT operations, and contributes to the transition toward cloud-native identity and Zero Trust models
Your role:
- Design, implement, and
manage AD & Entra ID architecture
, including hybrid identity, conditional access, identity governance, identity protection, hybrid identity, and privileged identity management. - Co-lead the
migration of AD to Entra ID for Workstations. - Develop, implement, and support automation for provisioning/deprovisioning across AD DS and Entra ID.
- Develop and enforce identity lifecycle policies, including provisioning, deprovisioning, and role-based access control (RBAC).
- Collaborate with cybersecurity, infrastructure, and application teams to ensure secure and compliant identity solutions.
- Provide technical leadership on Identity-related projects and support audits and compliance reviews.
- Serve as a subject matter expert and product owner for AD & Microsoft Entra ID across the enterprise.
- Contribute to Identity roadmap in alignment with security, compliance, and digital workplace strategies.
- Propose and lead initiatives to improve identity lifecycle management, access governance, and user experience.
- Monitor and optimize AD & Entra ID performance, availability, and security posture.
- Take part of the day-to-day operational tasks:
- Create, manage, and maintain AD users, groups, organizational units, and Entra ID objects.
- Operate and secure Tier 0 assets: Domain Controllers, Entra ID tenants, Entra ID Connect, AD CS (PKI), and Privileged Access Workstations.
- Lead lifecycle tasks: FSMO role management, SYSVOL replication, GPO management, krbtgt password rotation, and Windows Time Service synchronization.
- Monitor and maintain synchronization health for hybrid identity environments (Entra ID Connect, staging nodes, synchronization rules, outbound trusts).
- Enforce least privilege and role-based access through Entra ID PIM, RBAC, and Conditional Access policies.
- Collaborate with SOC and Cyber teams on identity-related threat detection and response (MDI, MDE, Identity Protection).
- Resolve existing findings from Vulnerability management tools such as PingCastle
- Define and enforce governance for SSO integrations (SAML, OAuth, OIDC) and Entra ID app registrations / enterprise applications.
- Ensure compliance with frameworks (PCI DSS, ISO 27001, internal policies).
- Maintain audit logs, operational runbooks, and documentation to support annual reviews and audits.
- Partner with Digital Workplace, Application, and Infrastructure Teams to resolve incidents, perform root cause analysis, and ensure continuity of service.
- Participate in Change Advisory Board (CAB) reviews, risk assessments, and operational acceptance for new services.
Your profile:
You will have to demonstrate:
- Extensive hands-on experience with Microsoft EntraID / Azure AD in a complex enterprise environment.
- At least 6 Years at managing and maintaining Active Directory Services (AD DS): Domain Controller operations, FSMO roles, SYSVOL replication, GPO management, krbtgt password rotation.
- Microsoft Entra ID: Tenant administration, Entra ID Connect (Staging/Active nodes), synchronization health, role management, Conditional Access, PIM/RBAC.
- Single Sign-On & Applications: Governance of Entra ID App Registrations, Enterprise Apps, OAuth/SAML configurations, API permissions, and application security reviews.
- AD CS (PKI): Certificate authority operations, key management, certificate lifecycle management.
- Experience with hybrid identity (on-prem AD + EntraID).
- Good experience of Azure
- Strong knowledge of identity federation (SAML, OAuth, OpenID Connect), MFA, and conditional access policies.
- Automation & Scripting: Strong proficiency in PowerShell for reporting, auditing, provisioning, and automation of hybrid identity operations.
- Familiarity with Microsoft Intune and Microsoft 365 security tools.
- Identity Security & Governance: Tiering Model, Zero Trust principles, identity lifecycle management (IGA/IAM), privileged access governance, least privilege enforcement.
- Threat Detection & Response: Familiarity with Microsoft Defender for Identity (MDI), Defender for Endpoint (MDE), SIEM/SOAR (e.g., Splunk, Sentinel), and incident response workflows.
- Compliance & Audit: Knowledge of regulatory requirements (PCI DSS, ISO 27001, SOX), documentation practices, and evidence gathering for audits.
Core Competencies
- Analytical & Problem-Solving: Ability to assess complex hybrid identity issues and propose effective, business-aligned solutions.
- Collaboration: Work effectively across global IT, Security, and Infrastructure teams in different regions (EMEA, APAC, Americas).
- Communication: Ability to explain technical issues to non-technical stakeholders (e.g., managers, compliance teams).
- Security Mindset: Strong focus on safeguarding Tier 0 identity assets, incident prevention, and proactive risk management.
- Process Orientation: Knowledge of ITIL/ITSM practices, CAB participation, and change management to minimize operational risks.
- Continuous Improvement: Drive automation, efficiency, and modernization of identity services toward cloud-native and Zero Trust approaches.
- Fluent English speaker
Joining us means:
- Taking part in an ambitious corporate project
- Becoming part of a team that embraced the digitalization challenge and enjoys this transformation every day
- Living our values every day: passions for customers, respect, imagination, simplicity, entrepreneurial spirit.
Because:
- You will greatly contribute to build the project that will improve the customers' experience on an international level
- You will get exposure to various global cultures and teams
- You will be working with the newest technologies to build a new platform from scratch
- We offer you a very pleasant working environment, close to Bucharest city center
- We also have for you: meal tickets, holiday vouchers, health subscription, flexible hours, a work policy with 2 days per week in the office, flexible benefits system, on-the-job training & e-learning platforms.
-
AD & EntraID Engineer
6 days ago
Bucharest, Bucureşti, Romania Edenred Digital Center Bucharest Full time 40,000 - 80,000 per yearThe Edenred Digital Center (EDC) in Bucharest, Romania is Edenred Group's new Digital hub for strategic IT projects.The Identity expert will be responsible for designing, implementing, operating, securing, and evolving the organization'shybrid identity infrastructure, spanning on-premises Active Directory (AD DS, AD CS) and Microsoft Entra ID.This role...
-
Nexus Smart ID Implementation Specialist
2 weeks ago
Bucharest, Bucureşti, Romania Decillion Digital Limited Full time €40,000 - €120,000 per yearJob Title: Nexus Smart ID Implementation Specialist / IAM EngineerLocation: BulgariaExperience: 5–10+ yearsPreferred Certifications: SAML, PKI, MFA, FIDO2, Identity FederationPosition Summary:We are looking for an experienced Nexus Smart ID Implementation Specialist / IAM Engineer to lead the deployment, configuration, and integration of Nexus Smart ID...
-
Digital Ads
13 hours ago
Bucharest, Bucureşti, Romania RSight® Full time 40,000 - 60,000 per yearWe are looking for our client, aregional Leader in the healthcare industry, adigital ads specialist.You will manage and optimize cutting-edge digital marketing campaigns by leveraging AI tools and platforms such as Google Ads and SEMrush. This role involves integrating automation, creating premium product strategies, and working for a company that values...
-
Bucharest, Bucureşti, Romania myGwork - LGBTQ+ Business Community Full time €30,000 - €60,000 per yearThis job is with European Investment Bank - EIB, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.Job ID:110796Entity:European Investment BankDeadline:TheEIB, the European Union's bank, is seeking to recruit for its Projects Directorate (PJ) -...
-
Senior Specialist Directory Services
2 days ago
Bucharest, Bucureşti, Romania MSD Full time 60,000 - 80,000 per yearSenior member of DS Operation working as part of a global team to support a fast-paced environment. Ensure conformance to established system architecture, security, regulations, standards and practices, and participate\drive their creation and upkeep. In addition to technical expertise must be proficient in managing projects through to completion,...
-
IT Systems Engineer
4 days ago
Bucharest, Bucureşti, Romania PSI CRO Full time €30,000 - €60,000 per yearCompany Description PSI is a leading Contract Research Organization (CRO) with 30 years of experience in the pharmaceutical industry. Originated in Switzerland, PSI is a privately owned, full-service CRO with a global reach, supporting clinical trials across multiple countries and continents. Our reputation for being highly selective about the projects we...
-
senior cloud engineer
2 weeks ago
Bucharest, Bucureşti, Romania Brightgrove Full time €90,000 - €120,000 per yearABOUT THE CLIENTOur customer is an international trade organization established over 70 years ago by a group of airlines. The organization represents around 330 airlines, accounting for more than 80% of the world's air traffic.PROJECT DETAILSOur customer, a global organization in the aviation sector, is launching a strategic revamp of its Statistics program...
-
Marketing Specialist
2 weeks ago
Bucharest, Bucureşti, Romania CONVERTOP EXPERT Full time 25,000 - 35,000 per yearMarketing SpecialistLocation:BucureștiJob Type:Full-timeNivel experiență:1-3 aniDescrierea postuluiCăutăm unMarketing Specialistpasionat, creativ și orientat spre rezultate, care să contribuie activ la creșterea vizibilității brandului nostru, atât online, cât și offline. Vei fi responsabil(ă) de crearea și implementarea de campanii de...
-
ASPICE Process Expert
2 weeks ago
Bucharest, Bucureşti, Romania Harman Full time €60,000 - €120,000 per yearLocation:Bucharest - Bucharest, RomaniaJob Family:EngineeringWorker Type Reference:Regular - PermanentPay Rate Type:SalaryCareer Level:T4Job ID:R Description & RequirementsA Career at HARMAN AutomotiveWe're a global, multi-disciplinary team that's putting the innovative power of technology to work and transforming tomorrow. At HARMAN Automotive, we give you...
-
Microsoft Defender
2 weeks ago
Bucharest, Bucureşti, Romania Decillion Digital Limited Full time €40,000 - €120,000 per yearJob Title: Microsoft Defender & Sentinel Security EngineerLocation: BulgariaExperience: 5–10+ yearsPreferred Certifications:Microsoft Certified: Security Operations Analyst Associate (SC-200)Microsoft Certified: Azure Security Engineer Associate (AZ-500)Position Summary:We are seeking a highly skilled and proactive Microsoft Defender & Sentinel Security...