AD / Entra Engineer Sr Tier 3 – Public Trust

Dunhill Solutions

United States

Remote

USD 120,000 - 139,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Dunhill Government Solutions is seeking a Senior Active Directory / Microsoft Entra Engineer to support a federal program delivering enterprise identity services. This is a full-time, fully remote role and the Tier 3 escalation authority for a hybrid identity platform spanning on-premises Active Directory, AD FS and Microsoft Entra ID.

Responsibilities include designing and maintaining AD infrastructure, integrating on-prem AD with Entra ID, and configuring Kerberos, LDAP, AD FS, DNS, GPOs, and

Qualifications

  • U.S. citizenship and ability to obtain Public Trust (Tier 1/NACI).
  • Bachelor’s degree in IT, CS, cybersecurity, engineering or related field, or equivalent experience.
  • At least 7 years of hands-on IT experience.
  • At least 3 years engineering, administering and supporting Active Directory and enterprise directory services.
  • Experience designing and supporting AD forests, domains, trusts and related infrastructure.
  • Experience supporting hybrid identity across AD, AD FS and Entra ID.
  • Advanced PowerShell scripting for automation, health checks, reporting and remediation.
  • Preferred: SC-300, AZ-800/AZ-801; familiarity with CA, MFA, SSO, PIM, Identity Protection.

Responsibilities

  • Design, implement and maintain Active Directory infrastructure (forests, domains, OU structures, DNS, replication, trusts).
  • Architect and support hybrid identity integrating on-premises AD with Microsoft Entra ID.
  • Configure and troubleshoot authentication and directory services (Kerberos, LDAP, NTLM, AD FS, DNS, certificates).
  • Design and maintain secure Group Policy architecture and hardening.
  • Provide Tier 3 incident response and root-cause analysis for replication and authentication issues.
  • Implement directory security controls and least-privilege administration.
  • Configure Entra ID capabilities including Conditional Access, MFA, SSO and Privileged Identity Management.
  • Develop PowerShell automation for health checks, lifecycle operations, diagnostics and remediation.
  • Produce architectures, runbooks, recovery procedures and knowledge articles.

Skills

PowerShell scripting
Active Directory
Microsoft Entra ID
Troubleshooting
Tier 3 incident response

Education

Bachelor's degree in IT, CS, cybersecurity, engineering or related discipline

Tools

Active Directory
Microsoft Entra ID
AD FS
Group Policy
PowerShell

Job description

AD / Entra Engineer Sr Tier 3 — Remote (U.S.)

Dunhill Government Solutions is hiring a Senior Active Directory / Microsoft Entra Engineer to support a newly awarded federal program delivering enterprise identity services. This is a full-time, fully remote role and the Tier 3 escalation authority for a hybrid identity platform spanning on-premises Active Directory, AD FS and Microsoft Entra ID.

Responsibilities:

  • Design, implement and maintain Active Directory infrastructure — forests, domains, OU structures, domain-controller placement, AD sites, DNS dependencies, replication topology and trusts.
  • Architect and support hybrid identity integrating on-premises Active Directory with Microsoft Entra ID, including Entra Connect or cloud sync, password hash synchronization, pass-through authentication, federation and synchronization failover.
  • Configure, administer and troubleshoot enterprise authentication and directory services: Kerberos, LDAP, NTLM, DNS service records, AD FS, certificate-dependent authentication and AD trusts.
  • Design and maintain secure Group Policy architecture — GPO inheritance, security filtering, baseline configuration, domain-controller hardening and policy-processing failure resolution.
  • Provide Tier 3 incident response and root-cause analysis for replication failures, lingering objects, authentication issues, broken trusts, synchronization errors, federation failures and privileged-access problems.
  • Implement directory security controls: least-privilege delegated administration, privileged-access boundaries, tiered administrative models, LDAP signing, legacy-protocol reduction and audit-ready configuration.
  • Configure and support Microsoft Entra ID capabilities including Conditional Access, multifactor authentication, single sign-on, application registrations, service principals, Identity Protection and Privileged Identity Management.
  • Develop PowerShell automation for directory health checks, account and group lifecycle operations, synchronization diagnostics, configuration validation, reporting and repeatable remediation.
  • Produce and maintain technical architectures, operational runbooks, recovery procedures, standards, change documentation and knowledge articles.

Requirements:

  • U.S. citizenship, and the ability to obtain and maintain a Public Trust (Tier 1 / NACI) background investigation.
  • Bachelor’s degree in information technology, computer science, cybersecurity, engineering or a related discipline, or equivalent relevant experience.
  • At least 7 years of hands-on information technology experience.
  • At least 3 years engineering, administering and supporting Active Directory and enterprise directory services.
  • Demonstrated experience designing and supporting AD forests, domains, domain controllers, sites, DNS integration, replication topology, Group Policy and trust relationships.
  • Demonstrated experience supporting hybrid identity across Active Directory, AD FS and Microsoft Entra ID.
  • Advanced PowerShell scripting, including automation of administration, health checks, reporting, diagnostics and remediation.
  • Preferred: Microsoft Certified Identity and Access Administrator Associate (SC-300); Windows Server Hybrid Administrator Associate (AZ-800 / AZ-801); hands-on Conditional Access, MFA, SSO, PIM and Identity Protection experience. Not holding a certification today does not stop you applying.
  • Fully remote, day shift. Travel is not required.

Compensation: $120,000 to $139,000 per year, full time, 40 hours per week.

Dunhill Government Solutions has placed cleared and public-trust professionals across the federal government for more than 25 years. AI-Powered. Human-Delivered.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Entra & Active Directory Engineer — Remote (Tier 3)
Senior Entra & Active Directory Engineer — Remote (Tier 3)

Dunhill Solutions • United States

Remote
USD 120,000 - 139,000
Senior Active Directory & Entra ID Engineer
Senior Active Directory & Entra ID Engineer

Noblesoft Solutions • Saint Petersburg (FL)

Hybrid
USD 90,000 - 140,000
Senior Automation Developer
Senior Automation Developer

XMS Solutions • Washington

On-site
USD 140,000 - 170,000
Entra ID Engineer
Entra ID Engineer

RedMatter Solutions LLC • Washington

On-site
USD 120,000 - 180,000
Senior Automation Developer
Senior Automation Developer

XMS Solutions, Inc. • Washington

On-site
USD 130,000 - 180,000
Sr Active Directory Engineer
Sr Active Directory Engineer

Revel IT • Houston (TX)

Hybrid
USD 120,000 - 170,000
Hybrid work model
Active Directory Architect
Active Directory Architect

Clark Davis Associates • Morristown (NJ)

On-site
USD 150,000 - 160,000
Medical insurance
401(k)
Identity and Access Management Technical Analyst
Identity and Access Management Technical Analyst

Staples • Framingham (MA)

On-site
USD 110,000 - 160,000
Inclusive culture
Flexible PTO
Company discounts & 401(k)
Windows/Active Directory Security Lead
Windows/Active Directory Security Lead

PRI Technology • New York (NY)

On-site
USD 286,541,000 - 315,195,000
Active Directory L3
Active Directory L3

Tata Consultancy Services • Salisbury (NC)

On-site
USD 100,000 - 115,000
Comprehensive Medical Coverage: Health
Dental & Vision
401K Plan
+3