Microsoft Windows Infrastructure Security and Domain Administrator
PT Daya Medika Pratama
Key Responsibilities Active Directory and Identity Management: • Design, administer, and maintain a complex Microsoft Active Directory Domain Services (AD DS) environment, including domain controllers, forests, domains, and trusts. • Manage Group Policy Objects (GPOs) for security hardening, software deployment, and user configuration across the enterprise. • Administer Azure Active Directory (Azure AD) and hybrid identity solutions (Azure AD Connect). • Implement and manage identity and access management (IAM) solutions, including user provisioning, de-provisioning, and role-based access control (RBAC). • Troubleshoot and resolve complex AD replication, authentication, and DNS issues. Windows Server Management: • Install, configure, patch, and maintain Windows Server operating systems (2016, 2019, 2022). • Manage core infrastructure services including DNS, DHCP, DFS, and File/Print services. • Implement and manage Hyper-V or VMware virtualization platforms. • Perform system monitoring, performance tuning, and capacity planning. Security and Compliance: • Harden Windows servers and Active Directory according to industry benchmarks (e.g., CIS Benchmarks, NIST guidelines). • Develop and execute a rigorous patch management strategy for all Windows systems. • Implement and manage endpoint security solutions (Microsoft Defender for Endpoint, CrowdStrike, etc.). • Configure and manage security tools such as Microsoft Defender for Identity, and Azure Sentinel for threat detection and response. • Conduct regular security audits, access reviews, and vulnerability assessments. • Respond to security incidents, participate in investigations, and implement remediation plans. • Ensure compliance with organizational policies and relevant regulations (e.g., SOX, HIPAA, GDPR). Automation and Scripting: • Automate repetitive administrative tasks using PowerShell scripting. • Utilize DevOps principles and infrastructure-as-code (IaC) tools like Ansible, Terraform, or DSC for configuration management. Backup, Disaster Recovery, and High Availability: • Design, test, and maintain robust backup and disaster recovery solutions for critical infrastructure. • Implement high-availability configurations like Failover Clustering. Collaboration and Support: • Serve as an escalation point for help desk and other IT teams for complex issues. • Create and maintain detailed system documentation, network diagrams, and operational procedures. • Collaborate with network, security, and application teams on projects and initiatives.
Bandung