lead client-facing engagements involving Active Directory (AD) migration, restructuring, and hybrid coexistence scenarios across on-prem, cloud, and hybrid environments
serve as a product expert and trusted advisor for the Semperis migration product suite (e.g., SMAD, DSP, ADFR, and Delegation Manager)
assess and document client AD topology, technical readiness, and business goals, and define a migration roadmap aligned to Semperis product capabilities
lead pre-sales and post-sales technical activities, including: architecture design and migration job creation, directory sync modeling and attribute transformation logic, deployment of SACA agents and execution of migration workflows
contribute to ongoing development of reusable documentation, scripts, best practices, and internal knowledge bases to improve product deployments and delivery repeatability
install, configure, and validate Semperis products including: SMAD (Migrator for AD) on AKS or MicroK8s, DSP for continuous sync visibility and rollback protection, ADFR for cyber-first recovery and test clone validation
design, implement, and optimize migration projects within SMAD, including attribute filtering, group mapping, and transformation rules
use PowerShell and logging diagnostics to troubleshoot agent issues (Directory Sync and SACA)
lead beta testing and field feedback initiatives to validate new product releases, build product demonstrations, and contribute to internal QA and training efforts
Requirements
15 years of experience in Active Directory design, administration, and migration across large, complex environments (5,000+ users)
expertise in: Active Directory schema and replication, SID History, ACL models, and Group Policy migration, Azure AD / Microsoft Entra ID, AAD Connect, and ADFS, PowerShell scripting and automation, DNS, DHCP, and enterprise networking
recent experience with enterprise AD migration tools (e.g., SMAD, Quest Migration Manager, Binary Tree, ForensiT, ADMT) is required. Experience with Semperis tools is a strong plus
ability to install and configure software within Kubernetes (AKS/MicroK8s) and familiarity with Helm, Ingress Controllers, and TLS certificate management
demonstrated ability to lead customer conversations and present complex AD and identity topics to technical and executive stakeholders
experience with incident response workflows, particularly in recovering or securing compromised AD environments, is a plus
prior work in enterprise software or consultancy settings, delivering solutions within defined SOWs and SLAs
excellent English communication skills (written and verbal); other languages a plus
must be able to work from a home office with occasional travel (domestic and international)
Microsoft and identity certifications (e.g., Microsoft Certified: Identity and Access Administrator, Certified Azure Solutions Architect) are a plus
Benefits
health insurance
retirement plans
paid time off
flexible work arrangements
professional development
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
Active Directory designActive Directory administrationActive Directory migrationPowerShell scriptingKubernetesAzure ADAAD ConnectADFSDNSDHCP