Job Description
Job Title:
Cloud Solution Architect (v-CSA) - Active Directory & PKI
Job Description
We are looking for a Cloud Solution Architect (CSA) with deep expertise in Active Directory (AD) and Public Key Infrastructure (PKI) to support enterprise and regulated customers in identity, security, and hybrid infrastructure scenarios.
This is a customer-facing role responsible for driving secure identity architecture, acting as a trusted technical advisor, and delivering resilient AD and PKI solutions across on-premises and hybrid environments. Depth in AD and PKI is the primary requirement; broader technical coverage is valuable when it supports identity, security, and regulated customer scenarios.
Key Responsibilities
- Active Directory & PKI Architecture
- Design and implement enterprise Active Directory Domain Services (AD DS) architectures.
- Design and implement Public Key Infrastructure (PKI), Certificate Services, and certificate lifecycle management solutions.
- Support AD domain design, consolidation, modernization, and operational governance.
- Guide customers on secure identity architecture, authentication, authorization, and certificate-based trust models.
- Customer Delivery & Execution
- Lead end-to-end delivery of AD and PKI engagements, including assessment, design, implementation, migration, and troubleshooting.
- Troubleshoot complex identity, authentication, DNS, Group Policy, and certificate-related issues.
- Deliver high-quality, repeatable technical engagements for enterprise and regulated customers.
- Trusted Advisor & Stakeholder Management
- Act as a trusted technical advisor for customers and internal stakeholders.
- Translate business, compliance, and security requirements into practical technical architecture.
- Communicate clearly with technical teams, customer decision makers, CSAMs, partners, and engineering teams.
- Operations, Resilience & Optimization
- Improve operational stability, monitoring, and reliability of identity and certificate services.
- Support disaster recovery, backup, and business continuity planning for AD and PKI services.
- Drive performance, maintainability, and operational maturity improvements.
- Security & Governance
- Guide customers on secure-by-design identity and certificate architectures.
- Support security hardening for Active Directory, Windows Server, PKI, and related infrastructure.
- Advise on access control, governance, compliance, and identity protection practices.
- Collaboration & Knowledge Sharing
- Collaborate closely with CSAMs, partners, engineering teams, and other CSA communities to deliver customer outcomes.
- Contribute to reusable assets, delivery IP, technical guidance, and best practices for AD, PKI, and hybrid identity scenarios.
- Share knowledge with the broader team to strengthen depth in identity, security, and high-security customer delivery.
Required Technical Skills
Core Must-have Skills: Onprem strong experience is must to have
- Minimum 2 of the following 3 skills:
- Expert-level Active Directory Domain Services (AD DS), including architecture, operations, troubleshooting, and modernization.
- Expert-level Public Key Infrastructure (PKI) / Active Directory Certificate Services (AD CS), including certificate lifecycle, templates, enrollment, governance, and troubleshooting.
- Strong Windows Server knowledge, including DNS, Group Policy, authentication protocols such as Kerberos and NTLM, and security hardening.
- And:
- Knowledge of recent Windows Server functionalities and enhancements required.
- Strong ability to operate confidently across on-premises and hybrid identity environments.
Additional Skills - Strongly Preferred
- Microsoft Sentinel experience is preferred, especially where it supports identity threat detection, security monitoring, and high-security customer scenarios.
- Microsoft Defender for Identity or related identity threat detection experience.
- Conditional Access, Identity Protection, privileged access, or identity governance experience.
- PowerShell scripting and automation for AD, PKI, operational reporting, and repeatable delivery.
Hybrid & Identity Integration -Better to have
- Microsoft Entra ID and hybrid identity concepts.
- Microsoft Entra Connect / AD Connect and synchronization fundamentals.
- Identity federation such as ADFS and enterprise application / SSO integration.
Security & High-Security Environment Requirements
- Proven experience working in environments with high security, compliance, confidentiality, or regulated customer requirements.
- Strong awareness of classified, regulated, sovereign, public sector, defense, or critical infrastructure IT environments where applicable.
- Ability to follow strict confidentiality expectations and demonstrate professionalism, integrity, reliability, and accountability.
- Ability to work effectively in complex enterprise IT landscapes and fast-moving customer situations.
- Where customer engagements require it, the candidate must be able to meet applicable security screening, background check, or clearance requirements.
- Finland citizenship and need to apply for security clearance
Language & Location Requirements
- Fluent English, spoken and written, is mandatory.
- Finnish is strongly preferred.
- Relevant Nordic language capability is considered a plus, depending on customer and country needs.
- Ability to work onsite as required for customer delivery, workshops, or high-security engagement needs.
- Flexibility to travel as needed.
Core Qualifications & Capabilities
- Experience working with enterprise customers in customer-facing technical delivery or advisory roles.
- Strong troubleshooting and problem-solving skills, especially in critical identity, authentication, and certificate-related situations.
- Excellent communication, presentation, and stakeholder engagement skills.
- Strong balance between deep technical expertise and business understanding.
- Ability to adapt quickly in changing environments and manage multiple stakeholders under pressure.
- Strong ownership mindset, delivery discipline, and ability to contribute to team knowledge and repeatable IP.
What Makes This Role Unique
- Deep specialist role focused on Active Directory and PKI rather than broad generalist coverage.
- Combines architecture design, hands-on delivery, customer advisory, and high-security environment readiness.
- Provides an opportunity to strengthen team capability in identity security while expanding into adjacent areas such as Microsoft Sentinel and identity threat protection.
Location
FIN -Work-at-Home
Language Requirements:
Time Type: