Unknown Company

Directory Infrastructure Engineer

washington, dc • Posted 3 days ago
Hybrid Full Time General

Senior Directory Infrastructure EngineerThe Client Engineering and Security Team is looking for a senior level Directory Infrastructure Engineer for complex projects.The Client Security and Engineering Team manages a variety of functions including endpoint management, Active Directory, VPN, firewalls, and security incident response. The team is seeking experienced Directory Infrastructure Engineers with extensive expertise in enterprise identity infrastructure including Active Directory, Entra ID (formerly Azure AD), OKTA Universal Directory, and LDAP environments. The resource must have a proven track record of designing and managing complex directory services across multiple platforms with particular emphasis on the complete lifecycle management of AD domains.

The ideal candidates will bring expertise in modern identity approaches including Just-In-Time access, Privileged Identity Management, and continuous validation patterns that balance security with user experience.Key ResponsibilitiesDesign, implement, and maintain enterprise directory services infrastructureManage the complete lifecycle of AD domains including planning, deployment, maintenance, upgrades, and decommissioningLead domain consolidation, migration, and forest restructuring projectsDevelop domain health monitoring and proactive maintenance proceduresCreate and execute disaster recovery plans for directory servicesDevelop and maintain automation scripts using PowerShell for directory management tasksInterface with directory services using GraphAPI and REST API for custom integrationsImplement and maintain security best practices for directory servicesDesign and manage trust relationships between domains and forestsCreate and maintain documentation for directory architecture and operational proceduresProvide escalation support for critical directory service incidentsRequired Qualifications5+ years of hands-on experience with enterprise directory services (Active Directory, Entra ID, OKTA Universal Directory, LDAP)Demonstrated experience with AD domain lifecycle management including domain creation, upgrades, and decommissioningAdvanced PowerShell scripting skills with demonstrable experience automating directory management tasksProven experience with Microsoft GraphAPI and REST API integration for directory managementExperience with directory synchronization technologies (Azure AD Connect, OKTA integration agents, etc.)Strong understanding of identity security best practices and compliance requirementsExperience with multi-forest and hybrid identity environmentsAbility to design and implement complex directory architecture solutionsPreferred QualificationsRelevant certifications (Microsoft 365 Certified: Identity and Access Administrator, OKTA Professional, etc.)Experience with Terraform, Ansible, or similar IaC tools for directory infrastructureKnowledge of SAML, OAuth, OIDC, and other modern authentication protocolsExperience with Group Policy design and managementExpertise in domain controller sizing, placement, and performance optimizationExperience with domain functional level upgrades and cross-domain migrationsFamiliarity with CI/CD pipelines for infrastructure automationExperience with implementing Zero Trust architectureCompensation: $94.00 - $105.00 per hour

Back to Job Search