Consultant
Responsibilities
EN Active Directory Expert / Identity Architect Identity & Directory Services Tech Lead – Workplace & Security Positioning within the Organization Reporting line: IT Production – Run / Workplace / Infrastructure Scope: Identity & Directory Services – Global Workplace environments Job location: Offshore – India (fully integrated within the global Workplace organization) Key interfaces: • L1 / L2 Support (Onshore & Offshore) • L3 Workplace / Infrastructure / Security teams • IT Projects / Build / Transformation teams • Change, Release & CAB • Security, IAM & Compliance teams • AYVENS / Société Générale environments Role Context The Active Directory Expert / Identity Architect role is part of a major Workplace and Identity transformation, operating in a hybrid Microsoft environment combining On-Prem Active Directory and Microsoft Entra ID, deployed across more than 43 countries. The role combines advanced technical expertise, Run accountability, security reinforcement and architectural contribution, in an international, complex and security-critical environment, subject to strong regulatory and compliance constraints. This is a senior N3 / global reference role, embedded within a global Workplace organization composed of onshore (France) and offshore (India) resources. The expert acts as the ultimate technical reference for Identity and Active Directory, ensuring standards, consistency and best practices across all environments. Key Responsibilities 1. Active Directory Architecture Reference (core responsibility) • Act as the global technical reference for Active Directory architecture • Own and promote AD standards at enterprise scale • Design, maintain and evolve: o Forest and domain architectures o Trust relationships o Replication models • Challenge project design choices and ensure Run, security and resilience compliance • Validate Active Directory and Identity designs from a production and security standpoint This is a decision-making and reference role, not limited to administration. 2. Hybrid Identity & Microsoft Entra ID (reinforced expectations) • Advanced expertise in Hybrid Identity architectures • Full mastery of integration between: o Active Directory On-Prem o Microsoft Entra ID (Azure AD) • Strong experience with: o Azure AD Connect / Cloud Sync o Hybrid authentication flows o Complex identity synchronization scenarios • Ability to analyze and explain Identity impacts on: o Workplace services o Security o Business applications The role requires a functional and security-oriented understanding of authentication flows, not just directory synchronization. 3. Active Directory Security & Hardening (key pillar) • Act as a key authority on Active Directory security posture • Deep understanding of Active Directory attack techniques and attack paths • Implement, maintain and enforce best practices including: o Tiering model (Tier 0 / 1 / 2) o Privileged account separation o Domain Controller hardening • Actively challenge projects and changes that do not meet security requirements • Contribute to: o Security audits o Risk assessments o Remediation action plans The role includes real technical and security authority over the Identity perimeter. 4. Core AD Services (DNS, GPO, Dependencies) • Strong expertise in Active Directory-integrated DNS, considered a critical service • Ability to design, operate and troubleshoot: o Complex DNS architectures o Name resolution issues impacting authentication and services • Advanced mastery of: o Group Policy design, optimization and troubleshooting o GPO impacts on security and Workplace services • Understanding of DHCP dependencies, where applicable 5. PKI & Identity-Related Security Services • Strong hands-on knowledge of Enterprise PKI • Clear understanding of: o Certificate lifecycle management o Certificate roles in authentication and encryption • Ability to troubleshoot complex certificate-related identity issues • Awareness of data protection and classification services (AIP) 6. Run, N3 Support & Advanced Troubleshooting • Act as N3 Identity / Active Directory expert, final escalation point • Handle incidents that are: o Complex o Critical o Non-documented • Advanced troubleshooting on: o AD replication issues o Authentication failures o Trust and federation problems • Ability to analyze: o System logs o Security events o Abnormal infrastructure behavior • Ability to operate under high operational pressure and crisis situations 7. Change Management, Standards & Governance • Own Identity-related changes presented in CAB • Perform impact analyses and define rollback strategies • Define, formalize and enforce Active Directory and Identity standards • Produce, validate and maintain: o Technical procedures o Architecture documentation (DAT) o Runbooks • Actively contribute to the maturity and autonomy of L2 teams 8. Automation & Continuous Improvement • Expert use of PowerShell for: o Administrative automation o Run activities o Reporting and AD health checks • Identify structural weaknesses and recurring incidents • Propose and lead continuous improvement initiatives for Identity services Required Skills Technical Skills • Expert-level Active Directory knowledge • Strong experience with: o Microsoft Entra ID o Complex hybrid Identity architectures • Strong expertise in: o Active Directory security and hardening o DNS / GPO o PKI • Recognized advanced troubleshooting capabilities • Strong PowerShell proficiency Functional Skills • Ability to operate in a global, multi-entity environment • Strong understanding of Run / Build / Project organizations • Solid familiarity with ITIL processes • Proven experience working with onshore and offshore teams Posture & Soft Skills • Senior N3 / global reference expert posture, credible and recognized • Natural technical authority and ability to challenge decisions • High autonomy and strong sense of ownership • Structured, rigorous and security-driven mindset • Excellent communication skills in international contexts Target Profile • Bachelor’s to Master’s degree in IT (or equivalent experience) • 5 to 8+ years of experience in Active Directory / Identity • Strong experience in hybrid Microsoft environments • International exposure is a strong plus • Professional English mandatory (written and spoken) What This Role Is Not An L2 support role A simple Active Directory administrator position A purely operational role This is a senior Active Directory / Identity expert role, acting as a global technical reference, accountable for stability, security and evolution of enterprise Identity services. FR Expert Active Directory / Architecte Identité Tech Lead Identité & Services d’Annuaire – Workplace & Sécurité Positionnement dans l’organisation Rattachement : IT Production – Run / Workplace / Infrastructure Périmètre : Identité & Services d’Annuaire – Environnements Workplace globaux Localisation du poste : Offshore – Inde (intégré aux équipes Workplace globales) Interfaces principales : • Support L1 / L2 (Onshore & Offshore) • Équipes L3 Workplace / Infrastructure / Sécurité • Équipes Projets IT / Build / Transformation • Change, Release & CAB • Équipes Sécurité, IAM, Conformité • Environnements AYVENS / Société Générale Contexte du poste Le poste d’Expert Active Directory / Architecte Identité s’inscrit dans une transformation majeure du Workplace et des services d’Identité, dans un environnement Microsoft hybride combinant Active Directory On-Premise et Microsoft Entra ID, déployé dans plus de 43 pays. Le rôle combine expertise technique avancée, responsabilité Run, renforcement de la sécurité et contribution à l’architecture, dans un contexte international, complexe et fortement contraint par des enjeux de sécurité, de conformité et de stabilité opérationnelle. Il s’agit d’un poste d’expert N3 / référent global, intégré à une équipe Workplace composée de ressources onshore (France) et offshore (Inde). L’expert agit comme point de référence ultime sur le périmètre Identité / AD, garant des standards, de la cohérence et des bonnes pratiques techniques à l’échelle internationale. Missions principales 1. Référent Architecture Active Directory (rôle central) • Être le référent technique global sur l’architecture Active Directory • Porter la vision et les standards AD à l’échelle des environnements • Maîtriser et faire évoluer les architectures : o Forêts et domaines o Relations de confiance (trusts) o Modèles de réplication • Challenger les choix techniques projets et garantir leur compatibilité Run & Sécurité • Valider les designs AD et Identité du point de vue production, sécurité et résilience Le rôle ne se limite pas à l’administration : il s’agit d’un poste de référence et de décision technique. 2. Identité hybride & Microsoft Entra ID (attente renforcée) • Expertise avancée des architectures d’Identité hybrides • Maîtrise complète de l’intégration entre : o Active Directory On-Prem o Microsoft Entra ID (Azure AD) • Expertise sur : o Azure AD Connect / Cloud Sync o Flux d’authentification hybrides o Scénarios de synchronisation complexes • Capacité à analyser et expliquer les impacts Identity sur : o Workplace o Sécurité o Applications métiers L’expert est attendu sur une compréhension fonctionnelle et sécuritaire des flux d’authentification, pas uniquement sur le mécanisme de synchronisation. 3. Sécurité Active Directory & Hardening (pilier clé) • Acteur majeur du renforcement de la posture de sécurité AD • Excellente compréhension des attaques et chemins d’attaque Active Directory • Mise en œuvre, maintien et contrôle des bonnes pratiques : o Modèle de tiering (Tier 0 / 1 / 2) o Séparation stricte des comptes à privilèges o Hardening des contrôleurs de domaine • Capacité à challenger les projets et changements non conformes aux exigences sécurité • Contribution active aux : o Audits de sécurité o Analyses de risques o Plans de remédiation Le poste inclut une véritable autorité technique et sécurité sur le périmètre Identité. 4. Services cœur AD (DNS, GPO, dépendances) • Forte expertise du DNS intégré à Active Directory, considéré comme un service critique • Capacité à concevoir, exploiter et dépanner : o Architectures DNS complexes o Problèmes de résolution impactant l’authentification et les services • Maîtrise avancée : o Des Group Policy (design, optimisation, troubleshooting) o De leurs impacts sur la sécurité et le Workplace • Compréhension des dépendances DHCP, le cas échéant 5. PKI & services de sécurité liés à l’Identité • Très bonne connaissance des PKI d’entreprise • Compréhension approfondie : o Du cycle de vie des certificats o Des liens entre certificats, authentification et chiffrement • Capacité à diagnostiquer des incidents complexes liés aux certificats • Sensibilité aux services de classification et protection des données (AIP) 6. Run, Support N3 & Troubleshooting avancé • Agir comme expert N3 Identity / AD, point d’escalade technique ultime • Prise en charge d’incidents : o Complexes o Critiques o Non documentés • Troubleshooting avancé sur : o Réplication AD o Échecs d’authentification o Problèmes de trusts et de fédération • Capacité à analyser : o Logs systèmes o Événements de sécurité o Comportements anormaux des infrastructures • Capacité à intervenir en contexte de crise ou forte pression opérationnelle 7. Change Management, Standards & Gouvernance • Portage des changements Identité en CAB • Réalisation d’analyses d’impact et plans de rollback • Définition, formalisation et application des standards Active Directory • Rédaction, validation et maintien de : o Procédures techniques o DAT o Runbooks • Contribution directe à la montée en maturité des équipes L2 8. Automatisation & amélioration continue • Utilisation experte de PowerShell pour : o Automatisation administrative o Tâches Run o Reporting et contrôles de santé AD • Identification des fragilités structurelles ou incidents récurrents • Proposition et pilotage d’actions d’amélioration continue Compétences requises Compétences techniques • Expertise Active Directory de niveau expert • Solide expérience en : o Microsoft Entra ID o Architectures hybrides complexes • Forte compétence en : o Sécurité Active Directory o DNS / GPO o PKI • Capacité reconnue de troubleshooting avancé • Très bonne maîtrise de PowerShell Compétences fonctionnelles • Évolution dans un environnement international et multi-entités • Bonne compréhension des organisations Run / Build / Projet • Aisance avec les processus ITIL • Expérience confirmée avec des équipes onshore / offshore Posture & soft skills • Posture d’expert N3 / référent, crédible et reconnu • Autorité technique naturelle et capacité à challenger • Forte autonomie et sens des responsabilités • Approche structurée, rigoureuse et orientée sécurité • Excellent relationnel en contexte international Profil recherché • Bac+3 à Bac+5 en informatique ou équivalent • 5 à 8 ans minimum d’expérience en Active Directory / Identité • Expérience confirmée en environnement Microsoft hybride • Expérience internationale appréciée • Anglais professionnel obligatoire (écrit et oral) Ce que ce poste n’est pas Un poste de support L2 Un simple administrateur Active Directory Un rôle purement opérationnel C’est un poste d’expert / architecte Active Directory, référent global, garant de la stabilité, de la sécurité et de l’évolution des services d’Identité à l’échelle internationale.
Profile required
EN Active Directory Expert / Identity Architect Identity & Directory Services Tech Lead – Workplace & Security Positioning within the Organization Reporting line: IT Production – Run / Workplace / Infrastructure Scope: Identity & Directory Services – Global Workplace environments Job location: Offshore – India (fully integrated within the global Workplace organization) Key interfaces: • L1 / L2 Support (Onshore & Offshore) • L3 Workplace / Infrastructure / Security teams • IT Projects / Build / Transformation teams • Change, Release & CAB • Security, IAM & Compliance teams • AYVENS / Société Générale environments Role Context The Active Directory Expert / Identity Architect role is part of a major Workplace and Identity transformation, operating in a hybrid Microsoft environment combining On-Prem Active Directory and Microsoft Entra ID, deployed across more than 43 countries. The role combines advanced technical expertise, Run accountability, security reinforcement and architectural contribution, in an international, complex and security-critical environment, subject to strong regulatory and compliance constraints. This is a senior N3 / global reference role, embedded within a global Workplace organization composed of onshore (France) and offshore (India) resources. The expert acts as the ultimate technical reference for Identity and Active Directory, ensuring standards, consistency and best practices across all environments. Key Responsibilities 1. Active Directory Architecture Reference (core responsibility) • Act as the global technical reference for Active Directory architecture • Own and promote AD standards at enterprise scale • Design, maintain and evolve: o Forest and domain architectures o Trust relationships o Replication models • Challenge project design choices and ensure Run, security and resilience compliance • Validate Active Directory and Identity designs from a production and security standpoint This is a decision-making and reference role, not limited to administration. 2. Hybrid Identity & Microsoft Entra ID (reinforced expectations) • Advanced expertise in Hybrid Identity architectures • Full mastery of integration between: o Active Directory On-Prem o Microsoft Entra ID (Azure AD) • Strong experience with: o Azure AD Connect / Cloud Sync o Hybrid authentication flows o Complex identity synchronization scenarios • Ability to analyze and explain Identity impacts on: o Workplace services o Security o Business applications The role requires a functional and security-oriented understanding of authentication flows, not just directory synchronization. 3. Active Directory Security & Hardening (key pillar) • Act as a key authority on Active Directory security posture • Deep understanding of Active Directory attack techniques and attack paths • Implement, maintain and enforce best practices including: o Tiering model (Tier 0 / 1 / 2) o Privileged account separation o Domain Controller hardening • Actively challenge projects and changes that do not meet security requirements • Contribute to: o Security audits o Risk assessments o Remediation action plans The role includes real technical and security authority over the Identity perimeter. 4. Core AD Services (DNS, GPO, Dependencies) • Strong expertise in Active Directory-integrated DNS, considered a critical service • Ability to design, operate and troubleshoot: o Complex DNS architectures o Name resolution issues impacting authentication and services • Advanced mastery of: o Group Policy design, optimization and troubleshooting o GPO impacts on security and Workplace services • Understanding of DHCP dependencies, where applicable 5. PKI & Identity-Related Security Services • Strong hands-on knowledge of Enterprise PKI • Clear understanding of: o Certificate lifecycle management o Certificate roles in authentication and encryption • Ability to troubleshoot complex certificate-related identity issues • Awareness of data protection and classification services (AIP) 6. Run, N3 Support & Advanced Troubleshooting • Act as N3 Identity / Active Directory expert, final escalation point • Handle incidents that are: o Complex o Critical o Non-documented • Advanced troubleshooting on: o AD replication issues o Authentication failures o Trust and federation problems • Ability to analyze: o System logs o Security events o Abnormal infrastructure behavior • Ability to operate under high operational pressure and crisis situations 7. Change Management, Standards & Governance • Own Identity-related changes presented in CAB • Perform impact analyses and define rollback strategies • Define, formalize and enforce Active Directory and Identity standards • Produce, validate and maintain: o Technical procedures o Architecture documentation (DAT) o Runbooks • Actively contribute to the maturity and autonomy of L2 teams 8. Automation & Continuous Improvement • Expert use of PowerShell for: o Administrative automation o Run activities o Reporting and AD health checks • Identify structural weaknesses and recurring incidents • Propose and lead continuous improvement initiatives for Identity services Required Skills Technical Skills • Expert-level Active Directory knowledge • Strong experience with: o Microsoft Entra ID o Complex hybrid Identity architectures • Strong expertise in: o Active Directory security and hardening o DNS / GPO o PKI • Recognized advanced troubleshooting capabilities • Strong PowerShell proficiency Functional Skills • Ability to operate in a global, multi-entity environment • Strong understanding of Run / Build / Project organizations • Solid familiarity with ITIL processes • Proven experience working with onshore and offshore teams Posture & Soft Skills • Senior N3 / global reference expert posture, credible and recognized • Natural technical authority and ability to challenge decisions • High autonomy and strong sense of ownership • Structured, rigorous and security-driven mindset • Excellent communication skills in international contexts Target Profile • Bachelor’s to Master’s degree in IT (or equivalent experience) • 5 to 8+ years of experience in Active Directory / Identity • Strong experience in hybrid Microsoft environments • International exposure is a strong plus • Professional English mandatory (written and spoken) What This Role Is Not An L2 support role A simple Active Directory administrator position A purely operational role This is a senior Active Directory / Identity expert role, acting as a global technical reference, accountable for stability, security and evolution of enterprise Identity services. FR Expert Active Directory / Architecte Identité Tech Lead Identité & Services d’Annuaire – Workplace & Sécurité Positionnement dans l’organisation Rattachement : IT Production – Run / Workplace / Infrastructure Périmètre : Identité & Services d’Annuaire – Environnements Workplace globaux Localisation du poste : Offshore – Inde (intégré aux équipes Workplace globales) Interfaces principales : • Support L1 / L2 (Onshore & Offshore) • Équipes L3 Workplace / Infrastructure / Sécurité • Équipes Projets IT / Build / Transformation • Change, Release & CAB • Équipes Sécurité, IAM, Conformité • Environnements AYVENS / Société Générale Contexte du poste Le poste d’Expert Active Directory / Architecte Identité s’inscrit dans une transformation majeure du Workplace et des services d’Identité, dans un environnement Microsoft hybride combinant Active Directory On-Premise et Microsoft Entra ID, déployé dans plus de 43 pays. Le rôle combine expertise technique avancée, responsabilité Run, renforcement de la sécurité et contribution à l’architecture, dans un contexte international, complexe et fortement contraint par des enjeux de sécurité, de conformité et de stabilité opérationnelle. Il s’agit d’un poste d’expert N3 / référent global, intégré à une équipe Workplace composée de ressources onshore (France) et offshore (Inde). L’expert agit comme point de référence ultime sur le périmètre Identité / AD, garant des standards, de la cohérence et des bonnes pratiques techniques à l’échelle internationale. Missions principales 1. Référent Architecture Active Directory (rôle central) • Être le référent technique global sur l’architecture Active Directory • Porter la vision et les standards AD à l’échelle des environnements • Maîtriser et faire évoluer les architectures : o Forêts et domaines o Relations de confiance (trusts) o Modèles de réplication • Challenger les choix techniques projets et garantir leur compatibilité Run & Sécurité • Valider les designs AD et Identité du point de vue production, sécurité et résilience Le rôle ne se limite pas à l’administration : il s’agit d’un poste de référence et de décision technique. 2. Identité hybride & Microsoft Entra ID (attente renforcée) • Expertise avancée des architectures d’Identité hybrides • Maîtrise complète de l’intégration entre : o Active Directory On-Prem o Microsoft Entra ID (Azure AD) • Expertise sur : o Azure AD Connect / Cloud Sync o Flux d’authentification hybrides o Scénarios de synchronisation complexes • Capacité à analyser et expliquer les impacts Identity sur : o Workplace o Sécurité o Applications métiers L’expert est attendu sur une compréhension fonctionnelle et sécuritaire des flux d’authentification, pas uniquement sur le mécanisme de synchronisation. 3. Sécurité Active Directory & Hardening (pilier clé) • Acteur majeur du renforcement de la posture de sécurité AD • Excellente compréhension des attaques et chemins d’attaque Active Directory • Mise en œuvre, maintien et contrôle des bonnes pratiques : o Modèle de tiering (Tier 0 / 1 / 2) o Séparation stricte des comptes à privilèges o Hardening des contrôleurs de domaine • Capacité à challenger les projets et changements non conformes aux exigences sécurité • Contribution active aux : o Audits de sécurité o Analyses de risques o Plans de remédiation Le poste inclut une véritable autorité technique et sécurité sur le périmètre Identité. 4. Services cœur AD (DNS, GPO, dépendances) • Forte expertise du DNS intégré à Active Directory, considéré comme un service critique • Capacité à concevoir, exploiter et dépanner : o Architectures DNS complexes o Problèmes de résolution impactant l’authentification et les services • Maîtrise avancée : o Des Group Policy (design, optimisation, troubleshooting) o De leurs impacts sur la sécurité et le Workplace • Compréhension des dépendances DHCP, le cas échéant 5. PKI & services de sécurité liés à l’Identité • Très bonne connaissance des PKI d’entreprise • Compréhension approfondie : o Du cycle de vie des certificats o Des liens entre certificats, authentification et chiffrement • Capacité à diagnostiquer des incidents complexes liés aux certificats • Sensibilité aux services de classification et protection des données (AIP) 6. Run, Support N3 & Troubleshooting avancé • Agir comme expert N3 Identity / AD, point d’escalade technique ultime • Prise en charge d’incidents : o Complexes o Critiques o Non documentés • Troubleshooting avancé sur : o Réplication AD o Échecs d’authentification o Problèmes de trusts et de fédération • Capacité à analyser : o Logs systèmes o Événements de sécurité o Comportements anormaux des infrastructures • Capacité à intervenir en contexte de crise ou forte pression opérationnelle 7. Change Management, Standards & Gouvernance • Portage des changements Identité en CAB • Réalisation d’analyses d’impact et plans de rollback • Définition, formalisation et application des standards Active Directory • Rédaction, validation et maintien de : o Procédures techniques o DAT o Runbooks • Contribution directe à la montée en maturité des équipes L2 8. Automatisation & amélioration continue • Utilisation experte de PowerShell pour : o Automatisation administrative o Tâches Run o Reporting et contrôles de santé AD • Identification des fragilités structurelles ou incidents récurrents • Proposition et pilotage d’actions d’amélioration continue Compétences requises Compétences techniques • Expertise Active Directory de niveau expert • Solide expérience en : o Microsoft Entra ID o Architectures hybrides complexes • Forte compétence en : o Sécurité Active Directory o DNS / GPO o PKI • Capacité reconnue de troubleshooting avancé • Très bonne maîtrise de PowerShell Compétences fonctionnelles • Évolution dans un environnement international et multi-entités • Bonne compréhension des organisations Run / Build / Projet • Aisance avec les processus ITIL • Expérience confirmée avec des équipes onshore / offshore Posture & soft skills • Posture d’expert N3 / référent, crédible et reconnu • Autorité technique naturelle et capacité à challenger • Forte autonomie et sens des responsabilités • Approche structurée, rigoureuse et orientée sécurité • Excellent relationnel en contexte international Profil recherché • Bac+3 à Bac+5 en informatique ou équivalent • 5 à 8 ans minimum d’expérience en Active Directory / Identité • Expérience confirmée en environnement Microsoft hybride • Expérience internationale appréciée • Anglais professionnel obligatoire (écrit et oral) Ce que ce poste n’est pas Un poste de support L2 Un simple administrateur Active Directory Un rôle purement opérationnel C’est un poste d’expert / architecte Active Directory, référent global, garant de la stabilité, de la sécurité et de l’évolution des services d’Identité à l’échelle internationale.
Why join us
“We are committed to creating a diverse environment and are proud to be an equal opportunity employer. All qualified applicants receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status”.
Business insight
At Société Générale, we are convinced that people are drivers of change, and that the world of tomorrow will be shaped by all their initiatives, from the smallest to the most ambitious. Whether you’re joining us for a period of months, years or your entire career, together we can have a positive impact on the future. Creating, daring, innovating, and taking action are part of our DNA. If you too want to be directly involved, grow in a stimulating and caring environment, feel useful on a daily basis and develop or strengthen your expertise, you will feel right at home with us!
Still hesitating?
You should know that our employees can dedicate several days per year to solidarity actions during their working hours, including sponsoring people struggling with their orientation or professional integration, participating in the financial education of young apprentices, and sharing their skills with charities. There are many ways to get involved.
We are committed to support accelerating our Group’s ESG strategy by implementing ESG principles in all our activities and policies. They are translated in our business activity (ESG assessment, reporting, project management or IT activities), our work environment and in our responsible practices for environment protection.