Account / Access Management Specialist

Empower AIQuantico, VA
Onsite

About The Position

Empower AI is seeking a Systems Administrator (Identity and Access Management) to administer directory services, account lifecycle, and access management capabilities for a Department of War agency supported by an enterprise IT Customer Support Services program. The administrator manages Active Directory and related identity services across multiple security enclaves, supports the Active Directory orchestration and ServiceNow AI Ops automation that delivers Tier 0 self-service password resets and account unlocks, and serves as the Tier III escalation point for complex account, permission, and authentication issues. As a privileged user, this role is central to both the customer experience objective of the program (resolve at the lowest tier) and its cybersecurity posture (least privilege, auditable access). This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers. THIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED.

Requirements

  • Bachelor's degree and a minimum of 3 years of related experience (an additional 4 years of related experience may be substituted for the degree).
  • Must be a U.S. Citizen.
  • Must have an Active Top Secret Clearance (favorably adjudicated T5/T5R) to start; this is a Privileged User position.
  • Must be willing and able to obtain TS/SCI eligibility after start , if required by mission needs.
  • Must be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting.
  • Must possess and maintain a current DoD 8570/8140 IAT Level II baseline certification (e.g., CompTIA Security+ CE, CySA +, GSEC, SSCP, or CCNA-Security).
  • Demonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision.
  • Minimum of 3 years of experience administering Active Directory and identity and access management services in an enterprise environment.
  • Strong knowledge of Active Directory architecture, Group Policy, DNS, Kerberos/NTLM authentication, PKI/CAC-based logon, and Windows Server.
  • Proficiency in PowerShell scripting for account administration and automation.
  • Experience with identity governance concepts: least privilege, role-based access, privileged account management, and access reviews.
  • Experience applying DISA STIGs and remediating vulnerabilities on Windows Server and directory services.
  • Experience executing changes through formal Change Management; ability to participate in an after -hours on-call rotation and Saturday maintenance windows.
  • Strong analytical, documentation, and customer communication skills.

Nice To Haves

  • Microsoft Certified: Identity and Access Administrator Associate or Windows Server Hybrid Administrator; CompTIA Security+ CE or CySA +.
  • Experience with ServiceNow AI Ops, Virtual Agent, or Active Directory orchestration for self-service password reset and account unlock.
  • Experience with Entra ID (Azure AD), conditional access, ADFS, and Microsoft 365 GCC High identity integration.
  • Experience supporting Department of War ( DoW ), DoD, or Intelligence Community environments across multiple enclaves.
  • Familiarity with DoD ICAM Strategy, Zero Trust Reference Architecture, and privileged access management tools.
  • Familiarity with eMASS , ACAS, and RMF control evidence for identity systems.
  • Experience using ServiceNow (incident, request, knowledge, CMDB, Service Catalog, Virtual Agent) or a comparable enterprise ITSM platform.

Responsibilities

  • Administer Active Directory domains, organizational units, groups, Group Policy, DNS/DHCP as applicable, and related identity services (e.g., Entra ID/Azure AD synchronization, ADFS, certificate-based authentication) across NIPRNet, SIPRNet, and JWICS enclaves.
  • Manage the user, service, and privileged account lifecycle: provisioning, modification, deprovisioning, group membership, permissions, and periodic access reviews, in accordance with approved processes and least-privilege principles.
  • Support, maintain , and enhance the Active Directory orchestration and ServiceNow AI Ops/Virtual Agent integrations that enable Tier 0 self-service password resets, account unlocks, and status checks, and measure their contribution to ticket deflection.
  • Serve as the Tier III escalation point for complex authentication, authorization, CAC/PKI logon, group policy, and account issues escalated from Tier I/II, resolving PL1-PL4 tickets within PRS timeframes and following the Customer-Confirmed Ticket Closure process.
  • Automate identity and access management tasks with PowerShell and workflow tools, develop request fulfillment workflows with the ITSM platform team, and reduce manual account administration effort.
  • Apply DISA STIGs to directory and identity systems, remediate vulnerabilities within policy timeframes , support audit log review and privileged access monitoring, and provide control evidence and POA&M inputs for RMF packages in eMASS .
  • Support ICAM and Zero Trust initiatives, including attribute-based access, conditional access, and identity governance improvements, and coordinate with cybersecurity, endpoint, and collaboration platform administrators.
  • Maintain identity and access documentation, SOPs, knowledge articles, and Tier I enablement content, and provide account and access performance data for the Customer Support Metrics Dashboard.

Benefits

  • This is a salaried, FLSA-exempt position
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service