Identity & Access Management Lead

General Dynamics Information Technology
Chantilly, VA, United States
3 days ago
Apply on gdit.wd5.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$212,500.0 - $287,500.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Active Directory Federation Services Artificial Intelligence Amazon Web Services Systems Engineering Microsoft Azure Cloud Computing Configuration Management Dynamic Host Configuration Protocol Distributed File Systems Domain Name System (DNS)
+25 more
Multi-Factor Authentication VMware ESX Servers Identity and Access Management Information Systems Security Architecture Professional Lightweight Directory Access Protocols (LDAP) Citrix XenApp System Center Operations Management System Center Configuration Manager Windows Servers OAuth OpenID Public Key Infrastructure Windows PowerShell Openid Connect Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Security Content Automation Protocol Single Sign-On Virtualization Technology Software Vulnerability Management HybridCloud Deployment Automation Splunk Dynatrace

Job description

Own your opportunity to serve as a critical component of our nation’s safety and security. Make an impact by using your expertise to protect our country from threats., The Identity & Access Management Lead serves as the lead engineer and technical authority for a complex privileged access management ecosystem supporting password vaulting, just-in-time administration, and hardened identity operations. This role requires deep expertise in Active Directory engineering, enterprise identity security, and automation, combined with strong leadership capabilities to guide a small team of engineers delivering mission-critical authentication and access services.

The ideal candidate brings extensive experience designing, securing, and modernizing Windows-based identity platforms across large, multi-domain environments. They demonstrate exceptional problem-solving skills, clear communication, and a proven ability to operate independently or collaboratively within cross-functional teams. Core Responsibilities:

  • Lead Identity Architecture for a privileged access management solution, including password vaulting, JIT access workflows, and Tier-0 protection aligned to Zero Trust principles.
  • Design, secure, and maintain Windows-based Active Directory forests and domains, including Group Policy, DNS, DHCP, PKI, MFA and hybrid identity integrations
  • Develop automation and tooling using PowerShell to standardize operations, reduce manual effort, and improve reliability across identity services.
  • Oversee engineering lifecycle delivery-requirements refinement, architecture documentation, installation instructions, deployment plans, and O&M support.
  • Engineer solutions for geographically dispersed environments, hybrid cloud integrations, and automated deployment via configuration management platforms.
  • Harden identity infrastructure to meet STIG, SCAP, and enterprise security compliance requirements.
  • Perform advanced systems engineering, including modeling, simulation, analysis, and architectural enhancements.
  • Plan and direct OS upgrades, directory modernization efforts, and enterprise-wide identity improvements.
  • Develop technical documentation for new and existing systems, ensuring clarity, repeatability, and operational readiness.
  • Identify, analyze, and resolve complex system issues, including authentication failures, directory inconsistencies, and privileged access anomalies.
  • Provide training and technical guidance to engineers and operational support staff.
  • Serve as a client-facing liaison, ensuring requirements are met and technical solutions align with mission needs.
  • Maintain current knowledge of identity security, Windows infrastructure, and emerging directory technologies.
  • Manage and mentor a small engineering team, providing leadership, direction, and professional development.
  • Tier 0 & Cloud Identity plane governance: Serves as the primary authority for Tier 0 Access Plane Management across Azure and Microsoft Entra ID. Responsible for designing and enforcing strict identity boundary controls, privileged access management (PAM), and Directory-level security architectures, while overseeing secure application registration and single sign-on (SSO) integrations using SAML 2.0, OpenID Connect (OIDC), and OAuth.

Preferred Experience & Technical Strengths

  • Directory Services: Active Directory, Group Policy, LDAP, DNS, ADCS, OCSP, DHCP, DFS, ADFS, Entra ID, hybrid identity
  • Security & Identity: PKI, MFA, privileged access controls, STIG compliance, ACAS, vulnerability mitigation
  • Automation & Systems: PowerShell, Windows Server, SCCM/MCM, SCOM, Splunk, Dynatrace
  • Cloud & Virtualization: Azure, AWS, VMware ESX, Citrix Xen Desktop/App
  • Leadership: Technical leadership, identity operations management, cross-functional coordination

Requirements

Years of Experience

5 + years of related experience

  • may vary based on technical training, certification(s), or degree Certification

Benefits & conditions

At GDIT, the mission is our purpose, and our people are at the center of everything we do.

  • Growth: AI-powered career tool that identifies career steps and learning opportunities
  • Support: An internal mobility team focused on helping you achieve your career goals
  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
  • Community: Award-winning culture of innovation and a military-friendly workplace, The likely salary range for this position is $212,500 - $287,500. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

About the company

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on gdit.wd5.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all