> Markdown version of [/jobs/ext/734270-sr-systems-engineer](https://www.wearedevelopers.com/jobs/ext/734270-sr-systems-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr Systems Engineer - **Company:** TEKSYSTEMS INC. - **Location:** Dallas, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Active Directory Federation Services, Systems Engineering, Federated Identity Management, Identity and Access Management, OAuth, Public Key Infrastructure, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Security Assertion Markup Language (SAML), Single Sign-On, Smart Cards, Cyberark, Ws-federation, Information Technology - **Published:** June 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9002096/sr-systems-engineer ## About the Role 8-10+ years of hands-on experience in systems engineering with deep expertise in Active Directory architecture and identity management -Demonstrated experience designing and deploying AD forest and domain structures in large-scale enterprise or government environments -Strong working knowledge of ADFS, SSO federation protocols (SAML, OAuth, WS-Federation), and identity provider configuration -Experience designing and managing cross-domain and cross-forest trust relationships in segmented or classified network environments -Deep understanding of RBAC frameworks, GPO design, and least-privilege access models -Working knowledge of DISA STIGs, NIST 800-53, and RMF as applied to directory services and identity infrastructure -Active Top Secret security clearance required; TS/SCI eligibility strongly preferred -Microsoft certifications (MCSE, Azure AD, or equivalent) a strong plus Preferred Qualifications -Prior experience supporting classified programs in a DoD, IC, or cleared defense contractor environment -Familiarity with Azure Active Directory, hybrid identity architectures, and cloud identity integration -Experience with Privileged Access Management (PAM) solutions such as CyberArk or BeyondTrust -Familiarity with PKI infrastructure, certificate services, and smart card authentication in DoD environments -Experience with PowerShell scripting for AD automation and administration -Bachelor's degree in Computer Science, Information Technology, Systems Engineering, or a related field; equivalent experience considered -DoD 8570/8140 IAT Level II or III certification (Security+, CASP+, CISSP, or equivalent) ## Description Lead the design and deployment of Active Directory forest and domain architecture, including multi-domain and multi-forest environments -Architect and implement Active Directory Federation Services (ADFS) solutions to enable single sign-on (SSO) across classified and unclassified systems -Design and configure cross-domain and cross-forest trust relationships in complex, segmented network environments -Develop and enforce role-based access control (RBAC) frameworks, group policy objects (GPOs), and delegation models aligned with least-privilege principles -Align directory services architecture with DISA STIG requirements, NIST 800-53 controls, and program-specific security policies -Collaborate with cybersecurity teams to support ATO processes, RMF documentation, and identity-related continuous monitoring requirements -Serve as the subject matter expert for identity and directory services, providing technical leadership and mentorship to junior engineers -Troubleshoot and resolve complex Active Directory, ADFS, and identity federation issues across multi-domain environments -Evaluate emerging identity and access management technologies and recommend solutions aligned with program roadmaps and government requirements -Produce and maintain technical documentation including forest design diagrams, trust maps, RBAC matrices, and configuration baselines ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fake or News: LLMs Protect Each Other, Google Predicts Floods, and GitHub Copilot Loves COBOL - Niels Leenheer](https://www.wearedevelopers.com/videos/1860-fake-or-news-llms-protect-each-other-google-predicts-floods-and-github-copilot-loves-cobol-niels-leenheer) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Extending HTML with Web Components](https://www.wearedevelopers.com/videos/459-extending-html-with-web-components) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)