This role involves leading the design and deployment of Active Directory forest and domain architecture, including multi-domain and multi-forest environments. The engineer will architect and implement Active Directory Federation Services (ADFS) solutions for single sign-on (SSO) across classified and unclassified systems, and design/configure cross-domain and cross-forest trust relationships in complex, segmented network environments. Responsibilities include developing and enforcing role-based access control (RBAC) frameworks, group policy objects (GPOs), and delegation models aligned with least-privilege principles. The position requires aligning directory services architecture with DISA STIG requirements, NIST 800-53 controls, and program-specific security policies. Collaboration with cybersecurity teams for ATO processes, RMF documentation, and identity-related continuous monitoring is essential. The engineer will serve as the subject matter expert for identity and directory services, providing technical leadership and mentorship. Troubleshooting complex Active Directory, ADFS, and identity federation issues, evaluating emerging identity and access management technologies, and producing technical documentation are also key aspects of the role.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
Associate degree