DTICI_IAM_ActiveDirectory_T9

Daimler Truck
Bengaluru
Workplace: HybridFull timeFunction: Executive & General ManagementExperience: 5+ yearsSkills: ["Governance","Least-privilege mindset","Risk management","Audit readiness","Stakeholder collaboration"]

Own Tier-0 identity lifecycle management for privileged Active Directory accounts, including joiner–mover–leaver provisioning and role-based access changes. Govern Tier-0 AD groups and delegated rights, drive least-privilege role engineering, and remediate privilege escalation paths. Build PowerShell/Python automation for provisioning, access reviews, and privilege-drift detection, integrating approval workflows with ITSM tools like ServiceNow while maintaining audit-ready logs and evidence for SOX/ISO and internal audits.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Daimler Truck
Daimler Truck
22 hours ago

DTICI_IAM_ActiveDirectory_T9

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 9 hours agoStatus: Live

Job Summary

Own Tier-0 identity lifecycle management for privileged Active Directory accounts, including joiner–mover–leaver provisioning and role-based access changes. Govern Tier-0 AD groups and delegated rights, drive least-privilege role engineering, and remediate privilege escalation paths. Build PowerShell/Python automation for provisioning, access reviews, and privilege-drift detection, integrating approval workflows with ITSM tools like ServiceNow while maintaining audit-ready logs and evidence for SOX/ISO and internal audits.
Location: Bengaluru
Workplace: Hybrid
Employment Type: Full time
Job Function: Executive & General Management

Key Responsibilities

  • •Own end-to-end joiner–mover–leaver lifecycle for Tier-0/privileged identities, including provisioning, modifications, and de-provisioning.
  • •Govern Tier-0 AD groups and delegated rights (e.g., Domain/Enterprise/Schema Admins), including GPO delegation and OU ACLs.
  • •Implement time-bound and just-in-time access where feasible, including approvals/expiry, identity proofing, segregation of duties, and removal of stale privileges.
  • •Build automation for ILM workflows using PowerShell (and/or Python) for provisioning/de-provisioning, approval-controlled group membership changes, and scheduled access reviews with evidence.
  • •Ensure compliance and audit readiness (SOX/ISO/internal audit support), maintain SOPs/runbooks and control mappings, and track remediation based on access review results.

Key Requirements

  • •5+ years of Active Directory operations/engineering in enterprise-scale environments.
  • •Strong expertise in AD DS/DCs, Sites & Services, trusts, and DNS basics.
  • •Knowledge of AD security fundamentals including privileged groups, GPO, delegation, and ACLs.
  • •Understanding of identity lifecycle (JML) and privileged access governance with approvals and access review cycles.
  • •Advanced PowerShell scripting for automation (modules, error handling, structured logging).
Experience:5+ years
Skills:GovernanceLeast-privilege mindsetRisk managementAudit readinessStakeholder collaboration
Tech Stack:Active DirectoryAD DSDNSPowerShellPythonServiceNowITSMGPOACLsDCsSites & Services

Company Brief

Daimler Truck
Designs, manufactures and sells commercial vehicles including trucks, buses and related services. Focuses on global transportation solutions, powertrains, electrification and digital services for freight and passenger mobility across multiple regions.
Industry: Automotive
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Leinfelden-Echterdingen, Germany
Founded: 2021
WebsiteLinkedIn