Sr. Systems Engineer

TEKSYSTEMS INC.
Cedar Rapids, IA, United States
about 1 month ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Active Directory Active Directory Federation Services Systems Engineering Federated Identity Management Identity and Access Management OAuth Public Key Infrastructure Windows PowerShell Role-Based Access Control Azure Active Directory Security Assertion Markup Language (SAML) Single Sign-On
+4 more
Smart Cards Cyberark Ws-federation Information Technology

Job description

The Sr. Systems Engineer must be familiar with the following:

  • AD forest design
  • ADFS SSO
  • trust configuration
  • RBAC mapping
  • Security alignment

Systems Engineer’s Responsibilities: -Lead the design and deployment of Active Directory forest and domain architecture, including multi-domain and multi-forest environments. -Architect and implement Active Directory Federation Services (ADFS) solutions to enable single sign-on (SSO) across classified and unclassified systems. -Design and configure cross-domain and cross-forest trust relationships in complex, segmented network environments. -Develop and enforce role-based access control (RBAC) frameworks, group policy objects (GPOs), and delegation models aligned with least-privilege principles. -Align directory services architecture with DISA STIG requirements, NIST 800-53 controls, and program-specific security policies. -Collaborate with cybersecurity teams to support ATO processes, RMF documentation, and identity-related continuous monitoring requirements. -Serve as the subject matter expert for identity and directory services, providing technical leadership and mentorship to junior engineers. -Troubleshoot and resolve complex Active Directory, ADFS, and identity federation issues across multi-domain environments. -Evaluate emerging identity and access management technologies and recommend solutions aligned with program roadmaps and government requirements. -Produce and maintain technical documentation including forest design diagrams, trust maps, RBAC matrices, and configuration baselines.

Requirements

8-10+ years of hands-on experience in systems engineering with deep expertise in Active Directory architecture and identity management. -Demonstrated experience designing and deploying AD forest and domain structures in large-scale enterprise or government environments. -Strong working knowledge of ADFS, SSO federation protocols (SAML, OAuth, WS-Federation), and identity provider configuration. -Experience designing and managing cross-domain and cross-forest trust relationships in segmented or classified network environments. -Deep understanding of RBAC frameworks, GPO design, and least-privilege access models. -Working knowledge of DISA STIGs, NIST 800-53, and RMF as applied to directory services and identity infrastructure. -Active Top Secret security clearance required; TS/SCI eligibility strongly preferred., Prior experience supporting classified programs in a DoD, IC, or cleared defense contractor environment. -Familiarity with Azure Active Directory, hybrid identity architectures, and cloud identity integration. -Experience with Privileged Access Management (PAM) solutions such as CyberArk or BeyondTrust. -Familiarity with PKI infrastructure, certificate services, and smart card authentication in DoD environments. -Experience with PowerShell scripting for AD automation and administration. -Bachelor’s degree in Computer Science, Information Technology, Systems Engineering, or a related field; equivalent experience considered.

Benefits & conditions

Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following:

  • Medical, dental & vision
  • Critical Illness, Accident, and Hospital
  • 401(k) Retirement Plan - Pre-tax and Roth post-tax contributions available
  • Life Insurance (Voluntary Life & AD&D for the employee and dependents)
  • Short and long-term disability
  • Health Spending Account (HSA)
  • Transportation benefits
  • Employee Assistance Program
  • Time Off/Leave (PTO, Vacation or Sick Leave)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

3:09 min

Balancing data science skillings alongside systems engineering rigor

Nico Schmidt · LIVE

46 sec

Brokering third-party APIs with OAuth federation

Deepu Deepu · WWC 2025

Videos

See all

Related articles

See all