Enterprise Active Directory & Email Services Lead
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+13 more
Job description
The Enterprise Active Directory & Email Services Lead will lead the team responsible for enterprise identity, directory, authentication, and messaging services across a large hybrid environment. This role provides hands-on senior technical leadership, people management, and day-to-day delivery accountability for Active Directory, Microsoft Entra ID, identity synchronization, ADFS/federation, MFA, Conditional Access, hybrid Exchange, Exchange Online, Microsoft 365 messaging, mail flow, email security, and related DNS/certificate dependencies. The Lead will directly manage approximately 12 engineers and administrators - including staffing, performance, coaching, and workload management - ensure service reliability and compliance, drive modernization and automation, and act as the senior escalation point for complex identity and messaging issues.
The successful candidate will be accountable for team leadership and staff development, operational excellence, L2/L3 engineering support, incident and problem management, change quality, security hardening, service monitoring, audit readiness, documentation, stakeholder communication, and continuous improvement., Team Leadership & People Management
- Directly supervise a team of ~12 AD, identity, Exchange, M365, and messaging engineers/administrators, including hiring, onboarding, and offboarding support.
- Set individual and team goals; conduct regular 1:1s, performance reviews, and career development/coaching conversations.
- Manage team schedules, on-call/rotation coverage, workload balancing, and staffing/backfill needs.
- Approve timesheets, PTO, and other administrative HR actions per company policy.
- Identify skill gaps and drive training, upskilling, and certification plans across the team.
- Foster a positive, accountable team culture; handle performance issues, conflict resolution, and disciplinary actions in partnership with HR as needed.
- Run regular team meetings, tech syncs, and knowledge-sharing sessions to build bench strength.
- Mentor engineers on technical growth paths and support internal mobility/promotion readiness.
Technical & Service Leadership
- Own enterprise service health, reliability, security posture, and L2/L3 support for AD, Entra ID, ADFS, identity synchronization, hybrid Exchange, Exchange Online, and email security platforms.
- Govern AD forest/domain design, sites/services, domains/trusts, GPO, delegation, DNS, replication, SYSVOL, and functional-level standards.
- Govern Entra ID, Conditional Access, MFA, SSO, authentication methods, application integrations, modern authentication, and legacy protocol reduction.
- Own hybrid Exchange and Exchange Online service health, mail routing, connectors, SMTP relays, transport rules, mail traces, certificates, and Exchange hybrid optimization.
- Drive SPF, DKIM, DMARC, anti-phishing controls, email security gateway tuning, retention-related controls, and messaging compliance readiness.
- Lead high-severity incident response, root-cause analysis, corrective-action planning, and problem management.
- Define and monitor service KPIs/SLOs for directory, authentication, synchronization, mail flow, and email security.
- Review and approve complex architectural and operational changes, ensuring risk assessment, rollback planning, and documentation.
- Drive modernization, automation, technical debt reduction, configuration baselines, and runbook maturity.
- Partner with cybersecurity, cloud, VMware, platform, network, application, and compliance teams.
- Lead client/service governance forums and communicate priorities, risks, incidents, and service health in business terms., Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM’s overall compensation and benefits package for employees.
Requirements
- Secret clearance required, or as specified by the account/client.
- 10+ years of experience in enterprise infrastructure, identity, directory, messaging, or Microsoft platform operations/engineering.
- 5+ years of experience with Active Directory and Microsoft identity services in large hybrid enterprise environments.
- 5+ years of experience with Exchange, Exchange Online, Microsoft 365 messaging, SMTP/mail flow, and email security operations.
- 3+ years directly leading, supervising, or managing technical teams (preferably 10+ personnel), including performance management, staffing, and coaching.
- Demonstrated experience with ITSM, incident/problem/change management, service metrics, documentation, and client/stakeholder governance.
Preferred Qualifications
- Experience with Microsoft Defender for Office 365, Proofpoint, Mimecast, Cisco email security, CyberArk, SailPoint, Infoblox, VMware, Azure, and ServiceNow.
- Experience with PowerShell automation, configuration-as-code, infrastructure-as-code, and operational dashboarding.
- Experience in regulated, public sector, defense, or other secured environments requiring audit evidence, privileged access controls, and formal change governance.
- Experience leading identity and messaging modernization programs (ADFS reduction, Conditional Access rollout, Exchange Online migration, on-prem decommissioning, DMARC enforcement).
- Experience with formal people-management training, performance management frameworks, or supervisory/leadership certifications.
Job Specific Skills
- Active Directory & Entra ID administration
- Hybrid Exchange / Exchange Online engineering
- Identity federation (ADFS), MFA, Conditional Access
- Email security (SPF/DKIM/DMARC, gateway tuning)
- Incident, problem, and change management (ITSM)
- People management and team leadership (~12 FTEs)
- PowerShell automation
- Stakeholder/client governance communication, The physical requirements described in “Knowledge, Skills and Abilities” above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, “light office duties’ or “lifting up to 50 pounds” or “some travel” required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
About the company
ASM Research, An Accenture Federal Services Company
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Fully Remote Software Engineer Jobs
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Highest Paying Tech Companies for Developers
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.