Identity & Directory Services Engineer (m/w), Madrid
22 hours ago
Madrid
As an Identity & Directory Services Engineer (m/f/d), you are responsible for the stable, secure, and standardized operation of our identity and directory services. You manage Active Directory (AD DS), Microsoft Entra ID (including hybrid scenarios/synchronization), and Group Policies (GPOs), and you further develop global standards for identities and access models. You ensure that our organization can operate securely, efficiently, and in a future‑proof manner, making you a key component of our IT security and productivity strategy. Key Responsibilities Operation and continuous development of AD DS, Entra ID, and Hybrid Identity (stability, troubleshooting, standards) GPO management: design, hardening, maintenance, and structured rollout of policies Identity lifecycle (Join/Move/Leave): provisioning and deprovisioning, groups/roles/permissions, including regular reviews Security & compliance: implementation of least privilege, separate admin accounts, MFA, and traceable logging Automation & documentation (e.g., PowerShell/Graph) and close collaboration with Security, Infrastructure, HR/People, and application owners Essential Requirements Several years of experience with Active Directory and GPOs (design, hardening, troubleshooting) Hands‑on experience with Microsoft Entra ID (users/groups/roles, RBAC, access models) Solid understanding of Identity & Access Management (lifecycle, permission and role concepts, least privilege) Good knowledge of server and Azure administration Experience in the Microsoft 365 / O365 environment Structured, solution‑oriented working style Very good Spanish (minimum C1) and good English (minimum B2) Advantageous Experience with Privileged Access Management (PAM) and SSO fundamentals (SAML/OIDC) Experience working in global teams or matrix organizations and with standardizing identity data Benefits Structured start: individual onboarding, organized networking. Goodies: life cover and health insurance and Company Share Ownership Program (WESOP). Modern working model: trust‑based working hours, flexible working hours, possibility of hybrid working. Career development/prospects: team or role‑based development/training, individual development/training, national and international career prospects within the RIB Group or Schneider Electric. RIB podrá exigir a todos los candidatos seleccionados que superen un control de experiencia y antecedentes antes de empezar a trabajar. La verificación de precedentes se llevará a cabo de acuerdo con las leyes locales y puede, sujeto a dichas leyes, incluir prueba de nivel educativo, verificación de historial de empleo, prueba de autorización de trabajo, antecedentes penales, verificación de identidad, verificación de crédito. Ciertos puestos que tratan con datos personales sensibles y/o de terceros pueden implicar la comprobación de criterios adicionales. RIB es una empresa que ofrece igualdad de oportunidades. Somos y estamos comprometidos a ser un empleador ejemplar con una cultura inclusiva, desarrollando un entorno de trabajo en el que todos nuestros empleados son tratados con dignidad y respeto. Valoramos la diversidad y la experiencia que personas de diferentes orígenes aportan a nuestro negocio. #J-18808-Ljbffr