Directory Services Associates

Alight, Inc.
United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Active Directory Agile Methodology Amazon Web Services Apache Tomcat Systems Engineering User Authentication Authentication Protocols Microsoft Azure Bash Shell Software as a Service Cloud Computing Continuous Integration
+36 more
Dynamic Host Configuration Protocol Domain Name System (DNS) Failover Clustering Hyper-V Infrastructure as a Service (IaaS) Identity and Access Management Internet Information Services (IIS) Python (Programming Language) Lightweight Directory Access Protocols (LDAP) OAuth OpenID Platform as a Service (PAAS) Performance Tuning Public Key Infrastructure Windows PowerShell Scrum Methodology Query Optimization Role-Based Access Control Azure Active Directory Cloud Services Ansible Security Assertion Markup Language (SAML) Security Information and Event Management Software Engineering Systems Integration TCP/IP Virtualization Technology Software Repository Scripting Load Balancing Okta System Availability Pingfederate SailPoint Terraform Vmware

Job description

The Directory Services Associates within the Alight Identity Security team is responsible for securing, maintaining, and ensuring high availability of enterprise directory and identity platforms. They will support Tier 0/1 systems, protect privileged access, integrate identity/security technologies, and provide operational and incident-response support. Ideal candidates bring strong experience with directory services, scripting, cloud platforms, IAM technologies, and modern authentication protocols., + Ensure Directory Services platforms are secure, compliant, and highly available.

  • Prioritize and protect privileged identities - leverage RBAC, ACLs, etc. to uphold least privilege and Just-In-Time access.

  • Support performance, resilience, and availability of Tier 0/Tier 1 systems.

  • Provide technical assistance to support team members.

  • Proactively monitor systems for performance and reliability.

  • Assist security and compliance audits.

  • Help with maintaining and developing technical documentation, code repositories, and training materials.

  • Coordinate maintenance and support activities.

  • Communicate with application development groups and end-users to resolve issues and complete requests.

  • Integration of Identity/Security platforms and associated lifecycles (ex: implementation/maintenance/upgrades/etc.).

  • Incident response - may require off-hours support.

Requirements

  • 3+ years of professional experience in Directory Services and/or Identity and Access Management.

  • Understanding of AD DS architecture, including forests, domains, trusts, FSMO roles, replication, and multi-site topology.

  • Experience integrating with IAM platforms such as Saviynt, Entra ID, SailPoint, Okta, and PingFederate.

  • Understanding of LDAP concepts, schema extensions, and directory query optimization.

  • Experience with PKI, certificate lifecycle management, CRL distribution, NDES/SCEP, and AD-integrated certificate services.

  • Scripting and automation experience (Bash, PowerShell, Python, or Ansible).

  • Proficiency with Group Policy (GPO) design and implementation.

  • Experience with Cloud service providers (ex: AWS/Azure/etc.) and cloud service models (IaaS/PaaS/SaaS), and cloud networking constructs.

  • Excellent verbal and written communication skills.

Preferred Qualifications

  • Managing directories such as Active Directory, eDirectory, and Radiant Logic (FID/SaaS).

  • Familiarity and experience with CI/CD and Infrastructure-as-Code (ex: Terraform).

  • Experience with Azure AD/Entra conditional access policies and Entra Connect.

  • Privileged Access Management (PAM).

  • In-depth knowledge of authentication (Authn) and authorization (Authz) concepts.

  • Experience with ITSM platforms (ex: SNOW/BMC Remedy).

  • Knowledge of SSO and federation standards (SAML 2.0, OAuth 2.0, OIDC).

  • Technical troubleshooting skills that follow engineering principles.

  • Understanding of Agile process and concepts (ex: SCRUM/SAFe/Kanban).

  • Monitoring platform experience and tuning (ex: performance thresholds/connectivity/availability/alert conditions/etc.).

  • Systems Engineering proficiency with DNS, DHCP, TCP/IP, UDP, Failover Clustering, SIEM, IIS/Tomcat, Virtualization (VMWare/Hyper-V), Load Balancing (ex: F5/NLB/ALB/etc.)

Benefits & conditions

We offer you a competitive total rewards package, continuing education & training, and tremendous potential with a growing worldwide organization.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all