About the Company
GoPomelo is seeking an experienced Active Directory & Identity Engineer to support Client as part of a managed Workspace Day 2 support engagement. The successful candidate will be the primary AD and hybrid identity resource, responsible for the day-to-day administration and health of Client's on-premises Active Directory environment and its integration with Microsoft Entra ID (Azure AD). This is a fully remote, contract role. The engineer will work within GoPomelo's service delivery framework and adhere to the SLAs and KPIs agreed with Client.
About the Role
The engineer will be responsible for the day-to-day administration and health of Client's on-premises Active Directory environment and its integration with Microsoft Entra ID (Azure AD).
Responsibilities
On-Premises Active Directory
- Day-to-day AD account lifecycle management - creation, modification, suspension, and deletion
- Account lockout resolution and password resets within SLA
- Group Policy Object (GPO) creation, modification, and auditing to enforce security baselines (e.g. USB restrictions, screen lock timers)
- Security template administration and OU structure management
- ADFS relying party trust management, monitoring, and maintenance
- On-premises domain join support coordination with the EUC team
- Execution of AD auto-provisioning scripts triggered by HR onboarding workflows
Hybrid Identity (Entra ID / Azure AD)
- Monitor and maintain Azure AD Connect / Entra Connect sync health; resolve UPN mismatches and sync errors
- Implement, maintain, and monitor Entra ID Conditional Access policies based on device health, location, and user risk
- Investigate and remediate Entra ID sign-in risk alerts and flagged accounts
- Support MFA configuration and troubleshooting for end users
Service Operations
- Respond to AD/identity-related tickets within agreed SLA (P1: 15 min, P2: 30 min)
- Produce monthly AD service reports - account activity, GPO changes, sync health, incident summary
- Maintain and update SOPs for all AD processes within the GoPomelo knowledge base
- Participate in weekly operational review calls with GoPomelo SDM and Client IT team
Qualifications
3+ years managing on-premises Active Directory in an enterprise environment
Required Skills
- Strong GPO management - creation, troubleshooting, security hardening
- ADFS - relying party trusts, claims rules, federation troubleshooting
- Azure AD Connect / Entra Connect - sync configuration, error resolution
- Entra ID (Azure AD) - user management, licensing, roles
- Conditional Access - policy design, named locations, device compliance
- PowerShell scripting for AD automation and reporting
- Understanding of identity protocols - Kerberos, NTLM, LDAP, SAML
Preferred Skills
- Experience with Microsoft Intune or SCCM
- Google Workspace identity integration (GCDS, SAML SSO via ADFS)
- Experience supporting hybrid environments alongside Google Workspace
- ITIL Foundation certification or equivalent
- Prior managed services / MSP experience
- Experience with SailPoint, CyberArk, or similar PAM tools