Domain Services Engineer

General Dynamics Information Technology

Springfield (VA)

On-site

USD 110,000 - 160,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401K with company match
Comprehensive benefits and wellness
Paid time off
Wellness programs

Job summary

General Dynamics Information Technology is seeking a Domain Service Engineer to support planning, building, and operations of a large, globally accessed, hybrid cloud computing system. The role focuses on 802.1X NAC with Cisco ISE, Active Directory, DNS/DHCP/IPAM, and secure, scalable architectures across on‑prem and cloud environments.

The ideal candidate will own end-to-end domain services, design modern system architectures, and communicate effectively with teams across Network, Systems, and

Qualifications

  • 5+ years of experience in progressive roles from Active Directory Administrator to Sr. Engineer.
  • In-depth understanding of Active Directory or LDAP administration.
  • Advanced familiarity with Azure AD Connect, Cisco Directory Synchronization, or similar tools.
  • Expertise with Cisco ISE deployment, management, and NAC policies.

Responsibilities

  • Accountable for the management, uptime, and lifecycle of the organization’s 802.1x architecture.
  • Deliver and implement a secure, scalable, and resilient Active Directory design following best practices.
  • Provide SME-level support for DNS, DHCP, and AD including integration with Windows and non-Windows endpoints.
  • Own projects and systems, design for resiliency and security, and guide cross-team collaboration.
  • Configure Group Policy Objects based on requirements and troubleshoot related issues.
  • Monitor replication between domain controllers, DNS, and DHCP server configurations.
  • Manage PKI systems and certificates.

Skills

Active Directory administration
Networking and 802.1X
Scripting: PowerShell, Python, Bash, &

Tools

Cisco ISE
Azure AD Connect
PKI / Certificates
SIEM

Job description

GDIT IS YOUR PLACE
  • Growth: AI-powered career tool that identifies career steps and learning opportunities
  • Support: An internal mobility team focused on helping you achieve your career goals
  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
  • Community: Award-winning culture of innovation and a military-friendly workplace
OWN YOUR OPPORTUNITY

Explore an enterprise IT career at GDIT and you'll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward.

#RoverGSS

GDIT is seeking a Domain Service Engineer to support the planning, building, and operations of a large, globally accessed, hybrid cloud computing system. The Domain Services Engineer provides support, implementation, and design services for ISE and Microsoft Active Directory and Windows-based systems across the enterprise, including directory and identity management solutions.

We are looking for an individual who will serve as our internal Domain Services team a broad scale of technologies, working with 802.1X network access control using Cisco Identity Services Engine (ISE), while simultaneously taking ownership of our core DDI (DNS, DHCP, and IPAM) services. Beyond day-to-day administration and Tier 3 engineering, this individual will play a vital role in designing, modernizing, and documenting system-level architectures to ensure our hybrid on-premises and cloud infrastructures are highly available, secure, and scalable. The ideal candidate will be a motivated self-starter with excellent written and verbal communication skills, who exceeds as an individual, as well as excels among peers in a team environment.

Job Duties include but are not limited to:
  • Accountable for the management, uptime, and lifecycle of the organization’s 802.1x architecture.
  • Deliver and implement a secure, scalable, and resilient Active Directory design, following industry best practices while adhering to Information Security standards.
  • Provide SME level assistance and escalation support for all troubleshooting tasks related to DNS, DHCP, and AD, including but not limited to integration with Windows and non-Windows endpoints, authentication, role-based access controls, DNS, DHCP, etc.
  • Manage the environment proactively, anticipating risks and issues, designing and engineering for resiliency. Take technical ownership of projects and systems accordingly.
  • Facilitate the implementation of Group Policy Objects (GPO) based on stated requirements. Troubleshoot and resolve any GPO related issues that arise.
  • Monitor and identify replication interruptions between domain controllers, DNS and DHCP Server configurations.
  • Management of the Public Key Infrastructure (PKI) systems and certificates.
REQUIRED QUALIFICATIONS:

5+ years of experience in progressive roles from Active Directory Administrator to Sr. Engineer

Knowledge of at least scripting languages (e.g. Powershell, Python, Bash, or Perl).

In Depth understanding of Active Directory or LDAP authentication and administration.

Advanced familiarity with enterprise directory synchronization tools such as Azure Active Directory Connect, Cisco Directory Synchronization, or others.

  • Implement and Manage enterprise-wide architecture, deployment, and ongoing administration of Cisco ISE
  • Maintain advanced network access control (NAC) policies, utilizing 802.1X, MAC Authentication Bypass (MAB), and Web Authentication.
  • Act as a Tier 3 escalation point for complex 802.1X/RADIUS authentication issues, certificate mismatches, and supplicant-side issues across Windows, macOS, Linux, and IoT devices.
PREFERRED QUALIFICATIONS:

1. An analytic mindset with the ability to define complex infrastructure problems, correlate logs across multiple systems (ISE, AD, DNS, Network Switches), and execute systematic resolutions.

2. Someone who looks beyond immediate triage to design architectures that prevent future systemic failures.

3. A strong capability to translate highly technical concepts to non-technical business stakeholders, and collaborate across siloed Network, Systems, and Security teams.

4. Configure and optimize network device profiling, Cisco TrustSec (Security Group Tags), and Comply-to-Connect (C2C) architectures.

5. Integrate Cisco ISE with Active Directory, Azure AD/Entra ID, PKI/Certificate Authorities, and SIEM tools for automated threat containment and compliance reporting.

6. Evaluate existing infrastructure pipelines and propose architectural modernizations to leverage Zero Trust Network Architecture (ZTNA), automation, and hybrid-cloud capabilities.

7. Architect, document, and present system-level designs that integrate on-premises systems, virtualization platforms, and public/private cloud environments.

8. Experience working in a fast tempo government agency production IT environment.

9. Experience troubleshooting various Microsoft Windows Server platforms' roles and features.

Location: Customer Site / NGA Washington or NGA St. Louis

US Citizenship Required

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Domain Services Engineer
Domain Services Engineer

General Dynamics Information Technology • St. Louis (MO)

On-site
USD 126,000 - 170,000
Senior Domain Services Engineer – Hybrid Cloud & AD Expert
Senior Domain Services Engineer – Hybrid Cloud & AD Expert

General Dynamics Information Technology • St. Louis (MO)

On-site
USD 126,000 - 170,000
Directory Services Systems Administrator - Active Top Secret required
Directory Services Systems Administrator - Active Top Secret required

General Dynamics Information Technology • Washington

On-site
USD 104,000 - 140,000
Identity and Directory Services Engineer - TS/SCI with Polygraph
Identity and Directory Services Engineer - TS/SCI with Polygraph

General Dynamics - IT • Chantilly (VA)

On-site
USD 80,000 - 100,000
401K with company match
Comprehensive health packages
Professional growth opportunities
+1
Senior Active Directory Engineer - Active Top Secret required
Senior Active Directory Engineer - Active Top Secret required

General Dynamics Information Technology • Washington

Hybrid
USD 148,000 - 202,000
Network Engineer Senior
Network Engineer Senior

General Dynamics Corporation • Virginia (MN)

On-site
USD 102,000 - 138,000
IEC Systems Engineer - TS/SCI
IEC Systems Engineer - TS/SCI

General Dynamics Information Technology • Springfield (VA)

On-site
USD 143,000 - 170,000
Network Engineer Senior
Network Engineer Senior

General Dynamics Information Technology • McLean (VA)

On-site
USD 102,000 - 138,000
Health plan options
401(k) plan with company match
Paid time off
+2
Sr Network Engineer
Sr Network Engineer

General Dynamics Information Technology • Springfield (VA)

On-site
USD 143,000 - 170,000
401K with company match
Paid time off
Healthcare options
ICAM Systems Engineer & Manager
ICAM Systems Engineer & Manager

Socket.dev • Tampa (FL)

On-site
USD 113,000 - 132,000