ICAM/AD Solutions Architect

Leidos

Washington

On-site

USD 131,000 - 237,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Leidos seeks a Senior Technical Solutions Architect to deliver modern ICAM and Zero Trust Architectures across on‑premises and cloud environments. You will lead modernization, translate requirements into technical options, and perform hands‑on prototyping.

The role requires deep expertise in Active Directory, Entra ID, RBAC/PBAC, and policy-based security. Expect collaboration with security, network, and application teams to uphold Zero Trust standards.

Qualifications

  • BS degree and 12+ years of prior relevant experience; additional experience in lieu of degree
  • 8+ years of hands-on experience in a lead role
  • MCSE or MCSA certification in Windows Server / Directory Services is required
  • Proven experience/proficiency in enterprise‑level Windows Server administration and Directory Services management
  • Proven experience with Azure services: Azure Virtual Machines, Azure AD Domain Services, Azure Arc, and Microsoft Entra suite
  • Understanding of Attributes Based Access Control (ABAC) implementation, Role-Based Access Control (RBAC), and Policy-Based Access Control (PBAC)
  • Strong expertise in Azure AD / Entra ID, hybrid identity, and cloud migration projects
  • Deep knowledge of Windows Server operating systems (2016/2019/2022), AD DS, DNS, DHCP, PKI, and certificate services
  • PowerShell scripting proficiency for automation and reporting
  • Demonstrated experience with Digital Identity Management and Identity Governance / ICAM services

Responsibilities

  • Manage and prioritize tasks within the directory services team, ensuring timely delivery
  • Design, implement, and manage AD DS including forest/domain architecture, trusts, replication, high availability
  • Lead hybrid identity initiatives using Azure AD Connect, Entra ID, and cloud sync technologies
  • Develop ZT and ICAM solutions through COTS integration activities
  • Perform requirements decomposition and inform downstream feature development
  • Migrate and modernize legacy AD environments to Azure-native or hybrid solutions
  • Provide presentations to senior leaders describing solution options and tradeoffs
  • Champion the development, documentation, and execution of system policies
  • Influence project/team leaders regarding solution design, processes, and approaches
  • Collaborate with Security, Networking, and Application teams to enforce Zero Trust principles

Skills

PowerShell scripting
Azure AD Entra ID
Hybrid identity
AD DS management
RBAC / ABAC
MFA solutions
Identity Governance
Cloud migration
Communication

Education

BS degree
MCSE or MCSA certification

Tools

PowerShell
Terraform
Bicep
Lambda
Azure AD Connect
Entra ID

Job description

Leidos is seeking a Senior Technical Solutions Architect responsible for delivering modern Identity Access Credential Management (ICAM) solutions and Zero Trust Architectures (ZTA). Role responsibilities include technical leadership for modernization initiatives, translating business requirements into technical solutions alternatives, hands‑on implementation/prototyping of identified solutions, and IPT project management activities across multiple ICAM service capabilities. The ideal candidate will be a technical leader for designing, implementing, managing, troubleshooting, and optimizing enterprise‑grade Active Directory and Entra ID solutions. This role is critical in maintaining secure, scalable, and highly available identity infrastructure across on‑premises and cloud environments.

Key Responsibilities:

  • Manage and prioritize tasks within the team directory services team, ensuring timely delivery of projects and effective resource utilization.

  • Design, implement, and manage Active Directory Domain Services (AD DS), including forest/domain architecture, trusts, replication, and high availability.

  • Lead hybrid identity initiatives using Azure AD Connect, Entra ID, and cloud sync technologies.

  • Develop best‑of‑breed ZT and ICAM solutions through COTS integration activities

  • Perform technical triage, business to technical requirements decomposition, and solutioning as part of the requirements process that inform downstream feature development

  • Manage and optimize Group Policy Objects (GPOs), OU structures, and security baselines.

  • Implement and maintain identity governance, role‑based access control (RBAC), Privileged Identity Management (PIM), and Conditional Access policies in Azure.

  • Perform AD health monitoring, performance tuning, backup/recovery, and disaster recovery planning.

  • Migrate and modernize legacy AD environments to Azure‑native or hybrid solutions.

  • Perform hands‑on implementation / prototyping of solutions

  • Provide oral and written presentations to senior leaders describing solution options along with advantages and disadvantages of alternatives

  • Champions the development, documentation, and execution of system policies

  • Influence project/team leaders regarding solution design, process and/or approaches.

  • Requires expert knowledge of and ability to apply advanced technical principles, theories, and concepts.

  • Troubleshoot complex identity and authentication issues across Windows, Azure, and third‑party applications.

  • Collaborate with Security, Networking, and Application teams to enforce Zero Trust principles and compliance standards (e.g., NIST, CIS, SOC2, ISO27001).

Qualifications:

  • BS degree and 12+ years of prior relevant experience; additional experience in lieu of degree
  • 8+ years of hands‑on experience in a lead role
  • MCSE or MCSA certification in Windows Server / Directory Services is required
  • Proven experience/proficiency in enterprise‑level Windows Server administration and Directory Services management.
  • Proven experience with Azure services: Azure Virtual Machines, Azure AD Domain Services, Azure Arc, and Microsoft Entra suite.
  • Understanding of Attributes Based Access Control (ABAC) implementation, Role-Based Access Control (RBAC), and Policy-Based Access Control (PBAC)
  • Strong expertise in Azure AD / Entra ID, hybrid identity, and cloud migration projects.
  • Deep knowledge of Windows Server operating systems (2016/2019/2022), AD DS, DNS, DHCP, PKI, and certificate services.
  • Proven experience with Azure services: Azure Virtual Machines, Azure AD Domain Services, Azure Arc, and Microsoft Entra suite.
  • PowerShell scripting proficiency for automation and reporting.
  • Demonstrated experience with one of more of the following:
    • Digital Identity Management and Identity Governance
    • Authorization ICAM services
    • Data Security Architecture and Data Protection Services
    • Customer Identity Access Management (CIAM) solutioning
    • Authentication and Multi‑Factor Authentication (MFA) solutions
    • Cloud first and cloud native architectures (any or all of Amazon Web Services, Azure, Google Cloud)
    • Utilizing cloud services to build infrastructure as code in an automated fashion
  • Must have a solid understanding of IdAM / ICAM Services like Authentication, Authorization, Identity, and Data Protection through Digital Policy
  • Demonstrated experience for client support of large scale enterprise applications
  • Strong communication skills via documentation and verbally with senior management

Desirable Skills:

  • Certifications:
    • Microsoft Certified: Azure Administrator Associate (AZ‑104)
    • Microsoft Certified: Identity and Access Administrator Associate (AZ‑305 or SC‑300)
    • Microsoft Certified: Windows Server Hybrid Administrator Associate (preferred)
    • Familiarity with Power BI or other reporting tools
  • Experience with Azure Landing Zones, Governance (Azure Policy, Blueprints), and Bicep/Terraform.
  • Knowledge of modern authentication protocols (SAML, OAuth, OpenID Connect, Kerberos, NTLM).
  • Familiarity with security tools such as Microsoft Defender for Identity, Sentinel, and Privileged Access Workstation (PAW).
  • Experience with DevOps and automation: PowerShell, Lambda

If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 — and moving faster than anyone else dares.

Pay Range:

Pay Range $131,300.00 - $237,350.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ICAM/AD Solutions Architect
ICAM/AD Solutions Architect

COMFORT SYSTEMS • Washington

On-site
USD 131,000 - 238,000
ICAM/AD Solutions Architect
ICAM/AD Solutions Architect

Leidos • Washington

On-site
USD 131,000 - 238,000
Identity and Access Engineer (ICAM) Engineer
Identity and Access Engineer (ICAM) Engineer

Leidos Inc • Rockville (MD)

On-site
USD 87,000 - 157,000
Identity and Access Engineer (ICAM) Engineer
Identity and Access Engineer (ICAM) Engineer

Leidos • Rockville (MD)

On-site
USD 87,000 - 157,000
Lead Identity and Access Management (ICAM) Engineer
Lead Identity and Access Management (ICAM) Engineer

Leidos • Rockville (MD)

On-site
USD 131,000 - 237,000
ICAM/AD Solutions Architect in College Park
ICAM/AD Solutions Architect in College Park

Energy Jobline ZR • College Park (MD)

On-site
USD 140,000 - 170,000
Lead Identity and Access Management (ICAM) Engineer
Lead Identity and Access Management (ICAM) Engineer

Koitecc Solutions • Rockville (MD)

On-site
USD 131,000 - 237,000
Health and Wellness programs
Income Protection
Paid Leave and Retirement
Lead Identity and Access Management (ICAM) Engineer
Lead Identity and Access Management (ICAM) Engineer

Via Logic LLC • Rockville (MD)

On-site
USD 131,000 - 237,000
Competitive compensation
Health and Wellness programs
Income Protection
+1
ICAM & AD Solutions Architect — Zero Trust Leader
ICAM & AD Solutions Architect — Zero Trust Leader

Energy Jobline ZR • College Park (MD)

On-site
USD 140,000 - 170,000
Lead Identity and Access Management (ICAM) Engineer
Lead Identity and Access Management (ICAM) Engineer

Leidos Inc • Rockville (MD)

On-site
USD 131,000 - 237,000