At Alcon , we're passionate about helping the world see brilliantly. With over 25,000 associates globally, we innovate fearlessly and act decisively to advance eye health. Within our Information Technology function, we deliver cutting-edge digital solutions to empower associates, protect our systems, and support our mission to improve sight worldwide.
We are seeking an AD / PKI Operations Engineer – Connectivity Security (Science / Tech / Engineering Path) to support and enhance our enterprise identity, authentication, and certificate management infrastructure. In this role, you will ensure secure operations of Active Directory (AD) and Public Key Infrastructure (PKI) systems, applying cybersecurity best practices to maintain system integrity, data protection, and compliance.
Key Responsibilities :
Active Directory Operations :
- Manage and maintain multi-domain Active Directory environments across global operations.
- Troubleshoot AD authentication, LDAP, DNS, and replication issues to ensure availability and reliability.
- Administer Group Policies, Organizational Units (OUs), and user / computer objects.
- Support AD Federation Services (ADFS) and integrations using SAML, OAuth, and Azure Entra ID.
- Perform upgrades, migrations, and patching of AD infrastructure in compliance with security standards.
- Monitor AD system health, event logs, and configuration compliance.
- Automate administrative and maintenance tasks using PowerShell scripting.
- Collaborate with IAM teams to implement secure authentication, SSO, MFA, and PAM solutions.
- Familiarity with IAM and security tools such as Saviynt, Secret Server, and Okta is a plus.
PKI Operations :
Deploy, manage, and maintain Certificate Authorities (CAs), certificate templates, and certificate lifecycle management processes.Administer and troubleshoot Active Directory Certificate Services (ADCS), Network Device Enrollment Service (NDES), and Autoenrollment configurations.Collaborate with cybersecurity teams to maintain certificate-based security policies and resolve PKI-related incidents.Security & Compliance :
Support the monitoring of system security and assist in identifying and mitigating vulnerabilities.Ensure alignment of systems and processes with cybersecurity best practices and organizational policies.Document operational activities and provide support for security audits and compliance initiatives.Continuously expand knowledge of new technologies, security methodologies, and best practices.Key Requirements / Minimum Qualifications :
3–4 years of hands-on experience in Active Directory and PKI administration within enterprise environments.Strong proficiency in PowerShell scripting for automation and operational efficiency.In-depth knowledge of Azure Active Directory / Entra ID and hybrid identity management models.Understanding of IAM principles, including authentication, authorization, SSO, MFA, and PAM.Familiarity with tools such as Saviynt, Thycotic Secret Server, and Okta preferred.Strong troubleshooting, analytical, and problem-solving abilities.Excellent documentation and collaboration skills with cross-functional IT and security teams.Bachelor's degree in Computer Science, Engineering, Information Technology, or related field.Skills Required
Active Directory, Powershell, Dns, Security Compliance