Haystack
← Back to Jobs
Temporary/Casual
Other

Active Directory Architect/SME

Lucid Support Services LtdCorsham, Wiltshire🇬🇧United KingdomPosted 7 Aug 2026

Quick Overview

Work Type
On Site
Schedule
Temporary/Casual
Level
Mid Senior

Job Description

Job title: Active Directory Architect/SME

Duration: 9 months

Clearance required: DV or DV Eligible

Rate: To be discussed

Location: Hybrid, onsite in Corsham twice a week

Specification: Below

Overview:

  • We are seeking a highly skilled Microsoft Active Directory Subject Matter Expert (SME) to lead the design, implementation, and optimisation of enterprise directory services within secure, high-assurance environments.
  • This role requires deep technical expertise in Active Directory architecture, strong delivery experience, and the ability to operate both strategically and hands-on. The successful candidate will support a UK secure account, working closely with stakeholders and delivering solutions on customer sites.

Key Responsibilities:

  • Lead the architecture, design, and evolution of Microsoft Active Directory environments (on premises)
  • Act as the technical SME for Active Directory, providing expert guidance on best practices, policies, and standards
  • Design and implement secure AD architectures, including domains, forests, trusts, and replication strategies
  • Develop and enforce Group Policy (GPO) strategies aligned with security and operational requirements
  • Deliver identity services integration, including federation (ADFS)
  • Define and implement tiered administration models, privileged access controls, Integration with Privileged access Management tooling, and secure identity design patterns
  • Conduct health checks, security assessments, and remediation planning for AD environments
  • Support incident resolution and root cause analysis relating to identity and authentication services
  • Produce and maintain comprehensive design and operational documentation
  • Work closely with security, infrastructure, and application teams to ensure secure and efficient identity services
  • Engage directly with Tech Lead, Programme Manager and customers on-site, supporting delivery and building trusted relationships

Experience Required:

  • Proven experience in an Active Directory Architect or Senior SME role

Deep hands-on expertise with:

  • Microsoft Active Directory (multi-domain/forest environments)
  • Group Policy design and management
  • DNS, DHCP, and core supporting infrastructure
  • Strong experience in designing and implementing enterprise-scale AD environments

Demonstrable experience producing high-quality design documentation, including:

  • High-Level Designs (HLDs)
  • Low-Level Designs (LLDs)
  • Security architecture documentation
  • Operational procedures and runbooks

Strong understanding of identity security, including:

  • Tiered administration models
  • Least privilege access
  • Privileged Access Workstations (PAWs)
  • Privileged access Management Toolset
  • Knowledge of authentication protocols (Kerberos, NTLM, LDAP, SAML, OAuth)
  • Experience with PowerShell Scripting and automation
  • Familiarity with integrating AD into enterprise security and monitoring tooling (eg, SIEM)
  • Excellent stakeholder engagement, communication, and documentation skills

Industry Experience:

  • Experience working within the Defence and/or Aerospace sector is highly desirable
  • Familiarity with policies, standards, and security frameworks (eg, JSP series, NCSC guidance)
  • Familiarity with high-security, regulated environments and secure system delivery

Desirable Certifications

  • Microsoft certifications (eg, Identity and Access Administrator, Windows Server)
  • CISSP, CISM, or equivalent security certifications
  • TOGAF or other architecture frameworks (desirable)

If you are available and interested in this opportunity, please apply for further information. Please note that due to high volumes of applications we are unable to contact every applicant. If you do not hear back from us within 7 days of sending your application, please assume that you have not been successful on this occasion.

At Lucid, we celebrate difference and value diverse perspectives, underpinned by our values 'Honesty, Integrity and Pragmatism'. We are proud to provide equal opportunities in line with our Diversity and Inclusion policy and welcome applications from all suitably qualified or experienced people, regardless of personal characteristics. If you have a disability or health condition and seek support throughout the recruitment process, please do not hesitate to contact us via the details below.

Skills

OAuth
SAML
Active Directory
DNS
LDAP
PowerShell
Root Cause Analysis

Similar jobs