Active Directory Architect / Engineer
$150kLeidos
Description
Looking for an opportunity to make an impact?
At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers’ success.
We empower our teams, contribute to our communities, and operate sustainable. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.
Our Mission, Vision, and Values guide the way we do business.
If this sounds like the kind of environment where you can thrive, keep reading!
The Digital Modernization Sector brings together our digital transformation and IT programs, allowing us to better serve our customers through scale and repeatability.
(Group Profile/Link to Group page) -
Your Next Great Adventure Awaits!
Leidos is seeking a highly skilled Active Directory Architect / Engineer to review and re-architect ATR’s Microsoft Active Directory and hybrid identity environments. The candidate will be responsible for overseeing the implementation, optimization, and ongoing management of the updated architecture and will play a key role in maintaining integrity, availability, and security of identity and access management systems that support the entire ATR organization. This position focuses on both the on-premises Active Directory Domain Services (AD DS) and integration with Microsoft Entra ID (formerly Azure AD).
Please Note: This work is located onsite in the DC area.
Key Responsibilities:
Design, deploy, upgrade, and administer Active Directory Domain Services, including domain controllers, forests, domains, trusts, and replication topologies (i.e. Manage and optimize Group Policy Objects (GPOs), OU structures, and security baselines; including object management through bulk operations and automation, Troubleshoot and resolve complex AD-related issues, including authentication failures, replication problems, DNS issues, and Kerberos/NTLM problems, Plan and execute Active Directory migrations, consolidations, and upgrades (of both underlying server infrastructure and overall forest/domain functional levels), Develop and maintain disaster recovery, backup, and restore procedures for AD environments (including AD Recycle Bin and authoritative restores), Monitor AD health and performance using tools such as Microsoft System Center, Azure Monitor, or third-party solutions).
Implement and maintain Advanced Microsoft Entra ID (Azure AD), Okta, hybrid identity models, Privileged Access Management (PAM), and Public Key Infrastructure services in compliance with federal standards (e.g. NIST and DISA STIG).
Engineer and implement security best practices including: (i.e. Privileged Access Management (PAM), Just-In-Time (JIT) access, tiered administration, and Least Privilege principles, Zero Trust network access (ZTNA), secure enclave integration, and defense-in-depth methodologies, Compliance with security standards, regulatory requirements (SOC 2, ISO 27001, HIPAA, CMMC, etc.), and internal policies.
Collaborate with Security, Endpoint, Cloud, and Application teams on identity-related projects and incident response.
Automate repetitive tasks using PowerShell, Microsoft Graph, Python, and Infrastructure as Code (leveraging Ansible) where applicable.
Required Qualifications:
Bachelor’s degree in Computer Science, Information Technology, Engineering, OR in a related field and 12+ years of relevant experience OR Masters degree with 10+ years of relevant experience . Additional years of experience will be considered/accepted in lieu of a degree.
12+ years of hands-on experience as an Active Directory Architect, Engineer, OR Senior Administrator in complex enterprise environments.
Deep expertise in designing, deploying, upgrading, and administering Microsoft Active Directory Domain Services (AD DS), including domain controllers, multi-domain/forest architectures, trusts, replication topologies, Group Policy Objects (GPOs), OU design, and security baselines.
Strong experience with hybrid identity solutions, including synchronization and integration between on-premises AD DS and Microsoft Entra ID (formerly Azure AD).
Proven track record in troubleshooting and resolving complex AD issues (authentication failures, replication, DNS, Kerberos/NTLM, etc.).
Experience with Active Directory migrations, consolidations, forest/domain functional level upgrades, and infrastructure modernization.
Solid understanding of disaster recovery, backup/restore procedures for AD (including AD Recycle Bin and authoritative restores).
Experience implementing and managing Privileged Access Management (PAM), Just-In-Time (JIT) access, tiered administration models, and Least Privilege principles.
Working knowledge of Public Key Infrastructure (PKI), Zero Trust Network Access (ZTNA), secure enclaves, and defense-in-depth security strategies.
Familiarity with compliance frameworks and federal standards such as NIST, DISA STIGs, SOC 2, ISO 27001, HIPAA, and CMMC.
Proficiency in automation and scripting using PowerShell, Microsoft Graph, Python, and Infrastructure as Code tools (e.g., Ansible).
Experience collaborating with Security, Cloud, Endpoint, and Application teams on identity-related initiatives and incident response.
Strong communication skills and ability to work independently as a contractor in a dynamic environment.
U.S. Citizenship required.
Ability to obtain and maintain a Public Trust security clearance.
Preferred Qualifications:
Experience with Okta for identity management and federation.
Background supporting federal or regulated industries with strict compliance requirements.
Experience using monitoring tools such as Microsoft System Center, Azure Monitor, or third-party AD health solutions.
Knowledge of modern identity security practices and integration with cloud platforms.
Desired Certifications (one or more of the following):
Microsoft Certified: Identity and Access Administrator Associate (SC-300).
Microsoft Certified: Windows Server Hybrid Administrator Associate (AZ-800 + AZ-801).
Microsoft Certified: Azure Administrator Associate (AZ-104).
Microsoft Certified: Azure Security Engineer Associate (AZ-500).
CISSP (Certified Information Systems Security Professional).
CISM (Certified Information Security Manager).
Okta Certified Professional or Okta Certified Administrator.
Please Note: The program budget salary for this role could fall anywhere between mid $150,000 to low/mid $170,000 with a slight wiggle room (no guarantees) based on relevant experience and assessment. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Leidos is growing! Connect with us on LinkedIn and Facebook .
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:
June 18, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $131,300.00 - $237,350.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit .
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at .
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at View email address on apply.j-vers.com .
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission .
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
$150k
...(Group Profile/Link to Group page) - Your Next Great Adventure Awaits! Leidos is seeking a highly skilled Active Directory Architect / Engineer to review and re-architect ATR’s Microsoft Active Directory and hybrid identity environments. The candidate will be...SuggestedFor contractorsLocal areaImmediate start- ...As a Systems Engineer supporting the Government, you will be a part... ...digital identities, Virtual Directory, PKI, Access Control, and... ...Requirements ~ Active TS/SCI clearance and ability... ...service ~ Experience with architecting and engineering enterprise level...SuggestedTemporary workRelocation package
$103.7k - $140.3k
...A leading technology services provider in Washington, DC is seeking a Directory Services System Administrator to manage and troubleshoot Active Directory and provide support for identity access systems. The role requires a Bachelor’s degree in Computer Science or a related...SuggestedFlexible hours$122k - $184k
...accessible and affordable across the nation. Position Overview: Our rapidly evolving IT department is in search of an Active Directory Senior Engineer with excellent time management skills and a proven track record of setting and meeting results‑oriented goals. The role...SuggestedFull timeWork at office$71.2k - $158.2k
...Health Government Services is seeking a skilled Federal Senior Engineer/Architect (Principal Consultant) to join our mission-driven... ...this role, you will be responsible for leading engineering activities, projects and ensuring successful deployment of the Federal...SuggestedTemporary workFlexible hours$151k - $170k
...Job Title: Senior ITSM Engineer / Architect Location: Arlington, VA Duration: Full-Time Experience level: Mid-senior Experience... ...and drill-down capabilities to assist with troubleshooting activities. Conduct analysis of alternatives of commercial...Full timeFor contractorsRemote workRelocationRelocation package- ...Koniag Government Services is seeking a Cybersecurity Engineer for its Commercial Solutions for Classified (CSfC) initiative. The role requires an active TS/SCI clearance and the candidate must have at least 7 years of experience in cybersecurity, including expertise in...
$150k - $170k
...Job Openings 1802 - Identity & Access Management Engineer - Onsite - Active Secret Required Title 1802 - Identity & Access Management Engineer... ...Demonstrated experience and confidence with Azure Active Directory (Entra ID), both on-premises and cloud Knowledgeable in PKI...Temporary workLocal area$107k - $178k
...s degree with 8-12 years of experience, particularly in advanced GIS technologies and project leadership. The position requires an active Top Secret clearance and offers a competitive pay range of $107,000 - $178,000 annually, with a robust benefits package including 4...- ...challenges. You will lead a team as they engineer solutions to complex challenges for... ...using knowledge network engineering, Active Directory, and system administration. In this role... ...security upgrades Experience architecting and designing IP networks, including developing...Temporary workRelocation package
- ...Health Government Services is seeking a skilled Federal Senior Engineer/Architect (Principal Consultant) to join our mission-driven... ...this role, you will be responsible for leading engineering activities, projects and ensuring successful deployment of the Federal...
- Peraton is seeking a Computer Systems Engineer to manage the imaging and deployment lifecycle using MECM, Intune, and Autopilot. The ideal... ...experience migrating deployment processes and must possess an active Public Trust Clearance. This role requires hands-on support and...
- ...of the Professional Services team, AI Architects help position, sell, and support our platform... ...with Customer Success, Sales, Product, Engineering, and Marketing to help us bring our... ...response SLAs. Support pre-sales activities including architectural overviews, security...Work experience placementLocal area
- ...oriented Broadcom and VMware Principal Architect, to join our team. Clearance TS/SCI W/... ...architecture review boards, and governance activities. Identify technical risks, dependencies... ...strategies. Collaborate with engineers, administrators, security teams, program...Immediate startFlexible hours
- ...advocating for economic liberty and justice reform. Responsibilities include team organization, event logistics, and collaboration with the Senior Director of Activism. This position offers a hybrid work schedule and a comprehensive benefits package. #J-18808-Ljbffr...
$119k - $135k
...As a Sr. Directory Services Engineer I , work as part of a collaborative and high-performing team providing your expertise to deliver... ...Support the Senior Principal Directory Services Architect with expertise in active directory configuration and maintenance, and...Full timeWork experience placementLocal areaFlexible hours$170k - $230k
...you advance your career. Join GDIT as a Senior Principal Directory Services Architect you will build an impactful career in enterprise IT, collaborating... ...SUCCEED Bachelor’s degree in Computer Science, Computer Engineering, Information Technology, or related field. Experience may...Immediate startWorldwideFlexible hours- ...Systems Engineer (Microsoft Solutions) GOVERNMENT AGENCY: DOJ NSD – National Security Division POSITION INFORMATION: Full-Time... ...experience in lieu of a degree. ~ Expertise with/in: ~ Active Directory Design and Implementation ~ Dynamic Host Configuration Protocol...Full timeFor contractorsWork at officeFlexible hours
$122k - $184k
Freddie Mac is looking for an Active Directory Senior Engineer in McLean, Virginia. This role focuses on ensuring the stability and security of Active Directory systems, providing technical leadership, automation, and process engineering. The ideal candidate will have...$70 - $90 per hour
Apex Systems is seeking an Identity & Directory Services Engineer to design and manage access management infrastructure. This remote role involves... ...candidate will have strong experience with Microsoft Active Directory and will be responsible for deploying solutions...Remote jobHourly pay- ...automation. Perform as a technical mentor to the QA Automation Engineer role Branch Leadership ~ Contribute to evaluating and... ...is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required by this position...Full timeWork at office
- ...As a VDI Engineer supporting the Government, you will be trusted to engineer new and improved enhancements for existing and emerging virtual... ...Bachelor's degree and 6+ years of experience Must have an Active TS/SCI ; willing to obtain a CI Poly Experience performing...Temporary workRemote workRelocation package
$115k - $120k
...Voice/Video Engineer (S) SUVI Global Services is looking for a Voice/Video Engineer (S) to support IT across all DoD OIG networks.... ...and provide user training as needed. Qualifications Active Secret security clearance. Bachelor's degree from an accredited...Full timePart timeFor contractorsRemote work$115k - $120k
...SUVI Global Services is looking for a Voice/Video Engineer (S) to support IT across all DoD OIG networks. To join our team of outstanding... ...tools and provide user training as needed. Qualifications Active Secret security clearance. Bachelor’s degree from an accredited...Full timePart time- ...An innovative IT consulting firm in Maryland seeks a Systems Engineer to support the Government in engineering IDAM technologies. Responsibilities include overseeing technical projects and providing consultation on systems. Candidates must have 10 years of relevant experience...
- ...protection controls as a Trellix Endpoint Data Loss Prevention (DLP) Engineer. Serve as the technical owner for Trellix EDR/DLP components,... ...to interpret data movement patterns and policy outcomes Active TS/SCI clearance; willingness to take a polygraph exam Associate...Temporary workRelocation package
- ...subject matter to specialized solutions. Includes but not limited to; identity management, medical and legal transcription, scientific encoding, environmental, scientific, maintenance and repair processes, business processes, and logistical support activities....
- ...We are seeking an experienced PKI Engineer/IAM Engineer to support enterprise Identity and Access Management (IAM), PKI, and Zero... ...Bash scripting Configure and manage LDAP integrations and directory services related to PKI environments Define and maintain policies...Temporary workRelocation package
- Cylestio Inc. is seeking an early engineer with significant ownership in shaping the technical direction of our platform. You will work across the entire stack and collaborate with founders on product and technical strategy. The ideal candidate has 5+ years of full-stack...
- ...As a Storage Engineer supporting the Government, you will be trusted to work on Platform Engineering Services engineering solutions... ...on a Storage Engineer joining our team to support Government activities in Annapolis Junction, MD or Sterling, VA. As a Storage Engineer...Temporary workRelocation package
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Active Directory Architect / Engineer. Be the first to apply!


