Windows Server Hybrid Administrator Associate

Nabout Leidos
United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$131,300.0 - $237,350.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory Domain Controllers Microsoft Online Services Cloud Computing Disaster Recovery Domain Name System (DNS) Monitoring of Systems Identity and Access Management Python (Programming Language) Kerberos (Protocol) Microsoft Servers NT LAN Manager
+9 more
Public Key Infrastructure Windows PowerShell Azure Active Directory Ansible Zero Trust Network Access Okta Infrastructure Automation Frameworks Information Technology CIS Benchmarks

Requirements

  • Bachelor’s degree in Computer Science, Information Technology, Engineering, OR in a related field and 12+ years of relevant experience OR Masters degree with 10+ years of relevant experience . Additional years of experience will be considered/accepted in lieu of a degree. \n
  • 12+ years of hands-on experience as an Active Directory Architect, Engineer, OR Senior Administrator in complex enterprise environments. \n
  • Deep expertise in designing, deploying, upgrading, and administering Microsoft Active Directory Domain Services (AD DS), including domain controllers, multi-domain/forest architectures, trusts, replication topologies, Group Policy Objects (GPOs), OU design, and security baselines. \n
  • Strong experience with hybrid identity solutions, including synchronization and integration between on-premises AD DS and Microsoft Entra ID (formerly Azure AD). \n
  • Proven track record in troubleshooting and resolving complex AD issues (authentication failures, replication, DNS, Kerberos/NTLM, etc.). \n
  • Experience with Active Directory migrations, consolidations, forest/domain functional level upgrades, and infrastructure modernization. \n
  • Solid understanding of disaster recovery, backup/restore procedures for AD (including AD Recycle Bin and authoritative restores). \n
  • Experience implementing and managing Privileged Access Management (PAM), Just-In-Time (JIT) access, tiered administration models, and Least Privilege principles. \n
  • Working knowledge of Public Key Infrastructure (PKI), Zero Trust Network Access (ZTNA), secure enclaves, and defense-in-depth security strategies. \n
  • Familiarity with compliance frameworks and federal standards such as NIST, DISA STIGs, SOC 2, ISO 27001, HIPAA, and CMMC. \n
  • Proficiency in automation and scripting using PowerShell, Microsoft Graph, Python, and Infrastructure as Code tools (e.g., Ansible). \n
  • Experience collaborating with Security, Cloud, Endpoint, and Application teams on identity-related initiatives and incident response. \n
  • Strong communication skills and ability to work independently as a contractor in a dynamic environment. \n
  • U.S. Citizenship required. \n
  • Ability to obtain and maintain a Public Trust security clearance. \n, * Experience with Okta for identity management and federation. \n
  • Background supporting federal or regulated industries with strict compliance requirements. \n
  • Experience using monitoring tools such as Microsoft System Center, Azure Monitor, or third-party AD health solutions. \n
  • Knowledge of modern identity security practices and integration with cloud platforms. \n

Benefits & conditions

n Looking for an opportunity to make an impact? \n \n At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers’ success. \n \n We empower our teams, contribute to our communities, and operate sustainable. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. \n \n Our Mission, Vision, and Values guide the way we do business. \n \n If this sounds like the kind of environment where you can thrive, keep reading! \n \n The Digital Modernization Sector brings together our digital transformation and IT programs, allowing us to better serve our customers through scale and repeatability. \n, Leidos is seeking a highly skilled \nActive Directory Architect / Engineer to review and re-architect ATR’s Microsoft Active Directory and hybrid identity environments. The candidate will be responsible for overseeing the implementation, optimization, and ongoing management of the updated architecture and will play a key role in maintaining integrity, availability, and security of identity and access management systems that support the entire ATR organization. This position focuses on both the on-premises Active Directory Domain Services (AD DS) and integration with Microsoft Entra ID (formerly Azure AD). \n \n \nPlease Note: This work is located onsite in the DC area. \n \n \nKey Responsibilities: \n \n \n

  • Design, deploy, upgrade, and administer Active Directory Domain Services, including domain controllers, forests, domains, trusts, and replication topologies (i.e. Manage and optimize Group Policy Objects (GPOs), OU structures, and security baselines; including object management through bulk operations and automation, Troubleshoot and resolve complex AD-related issues, including authentication failures, replication problems, DNS issues, and Kerberos/NTLM problems, Plan and execute Active Directory migrations, consolidations, and upgrades (of both underlying server infrastructure and overall forest/domain functional levels), Develop and maintain disaster recovery, backup, and restore procedures for AD environments (including AD Recycle Bin and authoritative restores), Monitor AD health and performance using tools such as Microsoft System Center, Azure Monitor, or third-party solutions). \n
  • Implement and maintain Advanced Microsoft Entra ID (Azure AD), Okta, hybrid identity models, Privileged Access Management (PAM), and Public Key Infrastructure services in compliance with federal standards (e.g. NIST and DISA STIG). \n
  • Engineer and implement security best practices including: (i.e. Privileged Access Management (PAM), Just-In-Time (JIT) access, tiered administration, and Least Privilege principles, Zero Trust network access (ZTNA), secure enclave integration, and defense-in-depth methodologies, Compliance with security standards, regulatory requirements (SOC 2, ISO 27001, HIPAA, CMMC, etc.), and internal policies. \n
  • Collaborate with Security, Endpoint, Cloud, and Application teams on identity-related projects and incident response. \n
  • Automate repetitive tasks using PowerShell, Microsoft Graph, Python, and Infrastructure as Code (leveraging Ansible) where applicable. \n, Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system - never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at LeidosCareersFraud@leidos.com. \n \n If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission. \n \n \nCommitment to Non-Discrimination \n \n All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.”, “hiringOrganization”: {“@type”: “Organization”, “name”: “Leidos”, “logo”: “https://jobs.military.com/attachments/employer/0/962/152/273.svg”}, “jobLocation”: {“address”: {“addressCountry”: “United States”, “streetAddress”: “Not specified”, “@type”: “PostalAddress”, “postalCode”: “20090”, “addressLocality”: “Washington”, “addressRegion”: “D.C. - DC”}, “@type”: “Place”}, “industry”: “Information”, “identifier”: {“@type”: “PropertyValue”, “name”: “Leidos”, “value”: “R-00185716”}, “baseSalary”: {“@type”: “MonetaryAmount”, “currency”: “USD”, “value”: {“minValue”: “131300”, “@type”: “QuantitativeValue”, “maxValue”: “237350”, “value”: “131300”, “unitText”

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on military.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · WWC 2024

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:48 min

Daily responsibilities and alignment practices for technical engineering leadership

Edoardo Dusi · LIVE

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · WWC 2023

Videos

See all

Related articles

See all