IT System Administration – Senior/Specialist

State of WashingtonThurston County – Lacey, WA
Hybrid

About The Position

The Department of Ecology is hiring an IT System Administration – Senior/Specialist within the Information Technology Security Services Office. This role involves being the senior Identity and Access Management Administrator, responsible for Windows Domain Controllers and a cloud-based identity management platform, including Azure. The position focuses on architecting and modernizing Ecology's Identity and Access Management strategy through the adoption of cloud-native technologies. Key activities include mentoring other Domain Administrators, providing customer service, collaborating with teams to improve security posture, communicating strategy to management, assessing and optimizing the current Windows Domain Controller and Group Policy Objects architecture, improving the security posture of the Identity and Access Management strategy and infrastructure, and planning the adoption of Intune-based policy management and Azure technologies for cloud-native Identity and Access Management.

Requirements

  • Seven years of experience and/or education related to the duties of the position.
  • Critical Thinking & Decision-Making – Proven track record evaluating risks, analyzing complex IAM, AD, DNS, and GPO issues, and making informed decisions to maintain secure and stable operations.
  • Security & Compliance – Demonstrated ability to apply and uphold security policies, governance requirements, and best practices to maintain compliant and secure identity, directory, and DNS environments.
  • Identity & Access Management Administration – Demonstrated ability to manage identity lifecycles, authentication, permissions, and roles to ensure secure and efficient access control.
  • Active Directory & Entra ID Management – Proven track record configuring, maintaining, modernizing, and troubleshooting Active Directory and Azure Entra ID to ensure reliable identity and directory services.
  • Group Policy Architecture & Management – Demonstrated ability to design, implement, and troubleshoot GPOs to enforce secure configurations and agency-wide standards.
  • Ability to translate GPO’s to Intune and Azure Policies.
  • DNS Administration & Architecture – Proven track record designing, implementing, securing, and troubleshooting on-premise and cloud DNS services to ensure accurate and reliable name resolution.
  • System Maintenance & Continuity Planning – Demonstrated ability to apply updates, monitor performance, and implement disaster recovery strategies to maintain secure and resilient IAM, AD, and DNS operations.
  • Education involving a major study in Computer Science, Information Technology (IT), Science, Technology, Engineering, Mathematics (STEM), or closely related field.
  • Applicants may meet the qualification requirement through experience alone or through any combination of experience and education totaling seven years.
  • Education in a related field may be applied year-for-year toward the seven-year requirement, as long as the applicant has at least three years of directly related experience and meets all the required competencies listed above.
  • Must be able to provide transportation to and from office or offsite trainings or assignments.
  • This position requires training to keep consistent with industry best practices.
  • Staff within this division are provided two (2) hours per week for training.
  • It is expected that this position will take what is learned in their training and apply it to their daily work.

Nice To Haves

  • Cloud Infrastructure Familiarity – Ability to understand and work with broader Azure services (beyond Entra ID and DNS) to support identity integrations across cloud environments.
  • Scripting & Automation – Ability to use tools like PowerShell to automate identity, AD, DNS, and GPO tasks to improve efficiency and consistency.
  • Identity Governance & Administration (IGA) Tools – Ability to work with identity governance platforms and workflows to support lifecycle automation, attestation, and compliance.
  • Hybrid Identity Architecture – Ability to design and support hybrid identity environments that integrate on-premise AD with cloud identity platforms.
  • Network Infrastructure Awareness – Ability to understand related network components (firewalls, VLANs, routing) that affect IAM and DNS performance and security.

Responsibilities

  • Mentor and guide other Domain Administrators.
  • Provide excellent customer service and collaborate with other teams to improve the security posture of Ecology's Identity and Access Management strategy.
  • Communicate effectively with Management to articulate Ecology's strategy for modernizing Identity and Access Management.
  • Assess the current Windows Domain Controller architecture and health and identify optimization opportunities.
  • Assess the current Group Policy Objects architecture and health and identify opportunities to streamline.
  • Assess and identify opportunities to improve the security posture of Ecology's Identity and Access Management strategy and infrastructure.
  • Assess and plan the adoption of Intune based policy management.
  • Design and plan the use of Azure technologies for cloud native Identity and Access Management.

Benefits

  • Medical/Dental/Vision for employee & dependent(s)
  • Public Employees Retirement System (PERS)
  • Vacation, Sick, and other Leave
  • 11 Paid Holidays per year
  • Public Service Loan Forgiveness
  • Tuition Waiver
  • Long Term Disability & Life Insurance
  • Deferred Compensation Programs
  • Dependent Care Assistance Program (DCAP)
  • Flexible Spending Arrangement (FSA)
  • Employee Assistance Program
  • Commute Trip Reduction Incentive
  • Combined Fund Drive
  • SmartHealth
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service