About the Role:

We are looking for an experienced and technically sharp Identity Infrastructure Engineer to join our client's Cybersecurity Operations team. This team oversees the design, implementation, and ongoing support of the organization's directory and identity management solutions, which is the foundational layer that underpins access, authentication, and security across the entire enterprise. This is a hands-on, senior-level role for someone who takes pride in keeping complex infrastructure running cleanly, communicates clearly with teams across the organization, and understands that identity is not just a technical function but a critical security control.

Role Description:

In this role, you will own the health, integrity, and security of the organization's identity infrastructure. That means administering Microsoft Active Directory and related directory services, managing PKI and certificate lifecycle operations, and ensuring that the identity backbone supporting thousands of users and systems is reliable, well-documented, and hardened against threats.

Day-to-day responsibilities include:

• Administering and maintaining Microsoft Active Directory, Active Directory Federation Services, and related directory services

• Designing, operating, and supporting the enterprise PKI environment and managing the full certificate lifecycle

• Configure and manage Okta Single Sign-On (SSO) and Multi-Factor Authentication (MFA)

• Performing daily system monitoring, reviewing system and application logs, and taking corrective action as needed

• Creating and maintaining system documentation covering installation, configuration, and troubleshooting procedures

• Supporting security continuous monitoring activities, including risk assessments and system patching, within the identity and access management space

• Collaborating with project and support teams across the organization on large, cross-functional identity initiatives

Required Qualifications & Education:

Active Directory & Directory Services

• 8-10 years of overall IT experience with a minimum of 5 years of experience administering Microsoft Active Directory and Active Directory Federation Services

• Experience designing and managing enterprise security solutions using Okta.

• Experience performing daily system monitoring, verifying the integrity and availability of hardware, server resources, systems, and key processes

• Proficiency in reviewing system and application logs and taking appropriate corrective action

• Ability to create and maintain thorough system documentation covering installation, configuration, and troubleshooting procedures

• Experience monitoring and analyzing architecture, communication, policies, and protocols from a cybersecurity perspective

PKI & Certificate Management

• Experience designing, implementing, and managing enterprise PKI environments, including certificate authority (CA) hierarchy management

• Proficiency in certificate lifecycle management — issuance, renewal, revocation, and auditing

• Understanding of cryptographic standards and their application within enterprise security policy

• Ability to troubleshoot certificate-related issues across large, complex environments

• Experience integrating PKI across Active Directory, web services, and endpoint devices

Identity & Access Management

• Experience with Microsoft Entra ID (formerly Azure Active Directory) and hybrid identity environments

• Familiarity with Single Sign-On (SSO), Multi-Factor Authentication (MFA), and enterprise identity governance platforms

• Ability to assist with security continuous monitoring, including risk assessments and system patching, within the identity and access management space

• Experience supporting large, cross-functional projects through collaboration with project and support teams

Education Requirements

• Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field preferred

• Relevant certifications such as MCSE, Microsoft Identity and Access Administrator (SC-300), or equivalent are strongly preferred

Desired Qualifications:

• Scripting and automation experience in PowerShell, Bash, Perl, or VBScript

• Experience with cloud management platforms such as Microsoft Azure or AWS

• Microsoft License Management experience

• Familiarity with enterprise mobility management and related Windows-based systems

• Experience with Microsoft 365 technologies and administration

• Knowledge of zero-trust security principles and how modern authentication fits within that framework

Clearance and Location Requirements:

• Candidates must be eligible to obtain and maintain a Public Trust security clearance.

• This is a hybrid position with on-site support requirements at the client location in the Washington, D.C and Manassas, VA; specific on-site and telework expectations will be confirmed at the time of hire.

Wasingt

Hybrid

Apply now

Need help? Lets talk.

We're ready to discuss your needs or dive in on your cyber defense journey. Let us know how we can help.

Contact us