Active Directory Engineer

TEKSYSTEMS INC.
Cedar Rapids, IA, United States
23 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Active Directory Active Directory Federation Services Domain Controllers User Authentication Microsoft Azure Domain Name System (DNS) Identity and Access Management Public Key Infrastructure Windows PowerShell Role-Based Access Control Azure Active Directory Smart Cards
+1 more
User Provisioning Software

Job description

TEKsystems is seeking and Active Directory Engineer with an active Top Secret clearance in Richardson, TX to support a Secure Distribution Environment (SDE) Infrastructure Deployment.

This effort supports classified engineering workloads associated with Department of Defense (DoD) programs. The environment architecture has already been defined, and the team is focused on implementation, configuration, integration, validation, troubleshooting, and operational readiness of the Active Directory infrastructure. The engagement is projected to last up to 12 months, with an initial 6-month funding period. During deployment, engineers will support implementation activities in Richardson, TX and Cedar Rapids, IA. All travel expenses associated with deployment activities will be covered.

What You’ll Do

  • Implement and configure Active Directory environments in accordance with established architecture documentation and engineering standards.
  • Configure and maintain Active Directory forests, domains, trusts, and organizational units in support of classified environments.
  • Implement and manage Group Policy Objects (GPOs) aligned with DISA STIG requirements and organizational security standards.
  • Perform Active Directory administration including user provisioning, account management, role assignments, and access control management.
  • Support identity lifecycle management including onboarding, offboarding, account modifications, and RBAC administration.
  • Configure and support Active Directory Federation Services (ADFS) and identity federation capabilities.
  • Support cross-domain and cross-forest trust implementation and maintenance activities.
  • Maintain Active Directory operational health including replication monitoring, DNS administration, domain controller management, and troubleshooting.
  • Support implementation of least-privilege access controls and role-based access frameworks.
  • Assist with security hardening, STIG implementation, and identity-related compliance activities.
  • Support ATO documentation, RMF activities, continuous monitoring requirements, and audit readiness efforts.
  • Troubleshoot and resolve Active Directory, Group Policy, DNS, authentication, and identity-related issues.
  • Maintain accurate technical documentation, configuration records, operational runbooks, and change management records.
  • Collaborate with infrastructure, cybersecurity, virtualization, and networking teams throughout deployment efforts.

Requirements

  • Active Top Secret security clearance.
  • 5+ years of experience supporting Active Directory engineering, administration, or identity management in large enterprise environments.
  • Experience implementing and administering Active Directory in enterprise-scale environments.
  • Strong experience with:
  • Active Directory
  • Group Policy (GPO)
  • DNS
  • Domain Controllers
  • Forests and Trusts
  • Identity and Access Management
  • Experience managing user lifecycle processes, permissions, and RBAC models.
  • Experience supporting Active Directory operational health and troubleshooting activities.
  • Familiarity with DISA STIG requirements and secure configuration practices.
  • Strong troubleshooting and problem-solving skills.
  • IAT II certification such as Security+ or higher (CASP+, CISSP)
  • Ability to work onsite in classified environments., * Experience supporting DoD, IC, or cleared defense contractor programs.
  • Experience with ADFS, SSO, and identity federation technologies.
  • Familiarity with RMF, NIST 800-53, and ATO processes.
  • Experience supporting classified environments with Active Directory infrastructure.
  • Experience with PowerShell scripting and Active Directory automation.
  • Familiarity with PKI, certificate services, smart card authentication, or privileged access management solutions.
  • Azure Active Directory / Entra ID experience.
  • Microsoft certifications (MCSA, MCSE, Azure Administrator, Azure Identity, or equivalent).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · WWC 2022

1:45 min

Evolution from manual setups to automated monolith deployments

Axel Barbier · WWC 2023

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi · WWC 2022

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

3:18 min

Eliminating passwords using Azure managed identities

Markus Möller · WWC 2021

Videos

See all

Related articles

See all