Identity & Access Management Lead - TS/SCI with Polygraph

General Dynamics Information Technology

Chantilly (VA)

On-site

USD 213,000 - 288,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

General Dynamics Information Technology seeks an Identity & Access Management Lead to act as the lead engineer and technical authority for a complex PAM ecosystem, including password vaulting, just‑in‑time administration, and hardened identity operations.

The ideal candidate has extensive experience designing and securing Windows‑based identity platforms across large multi‑domain environments, with proven leadership to guide a small engineering team.

Qualifications

  • 5+ years of related experience required.

Responsibilities

  • Lead Identity Architecture for a privileged access management solution, including password vaulting, JIT access workflows, and Tier-0 protection aligned to Zero Trust principles.
  • Design, secure, and maintain Windows-based Active Directory forests and domains, including Group Policy, DNS, DHCP, PKI, MFA and hybrid identity integrations.
  • Develop automation and tooling using PowerShell to standardize operations, reduce manual effort, and improve reliability across identity services.
  • Oversee engineering lifecycle delivery—requirements refinement, architecture documentation, installation instructions, deployment plans, and O&M support.
  • Engineer solutions for geographically dispersed environments, hybrid cloud integrations, and automated deployment via configuration management platforms.
  • Harden identity infrastructure to meet STIG, SCAP, and enterprise security compliance requirements.
  • Perform advanced systems engineering, including modeling, simulation, analysis, and architectural enhancements.
  • Plan and direct OS upgrades, directory modernization efforts, and enterprise-wide identity improvements.
  • Develop technical documentation for new and existing systems, ensuring clarity, repeatability, and operational readiness.
  • Identify, analyze, and resolve complex system issues, including authentication failures, directory inconsistencies, and privileged access anomalies.
  • Provide training and technical guidance to engineers and operational support staff.
  • Serve as a client-facing liaison, ensuring requirements are met and technical solutions align with mission needs.
  • Maintain current knowledge of identity security, Windows infrastructure, and emerging directory technologies.
  • Manage and mentor a small engineering team, providing leadership, direction, and professional development.
  • Tier 0 & Cloud Identity plane governance: Serves as the primary authority for Tier 0 Access Plane Management across Azure and Microsoft Entra ID. Responsible for designing and enforcing strict identity boundary controls, privileged access management (PAM), and Directory-level security architectures, while overseeing secure application registration and single sign-on (SSO) integrations using SAML 2.0, OpenID Connect (OIDC), and OAuth.

Skills

Active Directory (AD)
Systems Engineering
Zero Trust Architecture
Automation

Tools

PowerShell
Windows Server
SCCM/MCM
SCOM
Splunk
Dynatrace
Azure
AWS
VMware ESX
Citrix Xen Desktop/App

Job description

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

Top Secret SCI + Polygraph

Clearance Level Must Be Able to Obtain:

Top Secret SCI + Polygraph

Public Trust/Other Required:

None

Job Family:

IT Infrastructure and Operations

Job Qualifications:

Skills:

Active Directory (AD), Systems Engineering, Zero Trust Architecture

Certifications:

None

Experience:

5 + years of related experience

US Citizenship Required:

Yes

Job Description:

The Identity & Access Management Lead serves as the lead engineer and technical authority for a complex privileged access management ecosystem supporting password vaulting, just‑in‑time administration, and hardened identity operations. This role requires deep expertise in Active Directory engineering, enterprise identity security, and automation, combined with strong leadership capabilities to guide a small team of engineers delivering mission‑critical authentication and access services.

The ideal candidate brings extensive experience designing, securing, and modernizing Windows‑based identity platforms across large, multi‑domain environments. They demonstrate exceptional problem‑solving skills, clear communication, and a proven ability to operate independently or collaboratively within cross‑functional teams.

Core Responsibilities:
  • Lead Identity Architecture for a privileged access management solution, including password vaulting, JIT access workflows, and Tier‑0 protection aligned to Zero Trust principles.
  • Design, secure, and maintain Windows‑based Active Directory forests and domains, including Group Policy, DNS, DHCP, PKI, MFA and hybrid identity integrations
  • Develop automation and tooling using PowerShell to standardize operations, reduce manual effort, and improve reliability across identity services.
  • Oversee engineering lifecycle delivery—requirements refinement, architecture documentation, installation instructions, deployment plans, and O&M support.
  • Engineer solutions for geographically dispersed environments, hybrid cloud integrations, and automated deployment via configuration management platforms.
  • Harden identity infrastructure to meet STIG, SCAP, and enterprise security compliance requirements.
  • Perform advanced systems engineering, including modeling, simulation, analysis, and architectural enhancements.
  • Plan and direct OS upgrades, directory modernization efforts, and enterprise‑wide identity improvements.
  • Develop technical documentation for new and existing systems, ensuring clarity, repeatability, and operational readiness.
  • Identify, analyze, and resolve complex system issues, including authentication failures, directory inconsistencies, and privileged access anomalies.
  • Provide training and technical guidance to engineers and operational support staff.
  • Serve as a client‑facing liaison, ensuring requirements are met and technical solutions align with mission needs.
  • Maintain current knowledge of identity security, Windows infrastructure, and emerging directory technologies.
  • Manage and mentor a small engineering team, providing leadership, direction, and professional development.
  • Tier 0 & Cloud Identity plane governance: Serves as the primary authority for Tier 0 Access Plane Management across Azure and Microsoft Entra ID. Responsible for designing and enforcing strict identity boundary controls, privileged access management (PAM), and Directory-level security architectures, while overseeing secure application registration and single sign-on (SSO) integrations using SAML 2.0, OpenID Connect (OIDC), and OAuth.
Preferred Experience & Technical Strengths
  • Directory Services: Active Directory, Group Policy, LDAP, DNS, ADCS, OCSP, DHCP, DFS, ADFS, Entra ID, hybrid identity
  • Security & Identity: PKI, MFA, privileged access controls, STIG compliance, ACAS, vulnerability mitigation
  • Automation & Systems: PowerShell, Windows Server, SCCM/MCM, SCOM, Splunk, Dynatrace
  • Cloud & Virtualization: Azure, AWS, VMware ESX, Citrix Xen Desktop/App
  • Leadership: Technical leadership, identity operations management, cross‑functional coordination

GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.

  • Growth: AI-powered career tool that identifies career steps and learning opportunities
  • Support: An internal mobility team focused on helping you achieve your career goals
  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
  • Community: Award-winning culture of innovation and a military-friendly workplace

OWN YOUR OPPORTUNITY
Explore an enterprise IT career at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward.

The likely salary range for this position is $212,500 - $287,500. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

None

Telecommuting Options:

Onsite

Work Location:

USA VA Chantilly

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work:

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Enterprise IT Systems Architect - TS
Lead Enterprise IT Systems Architect - TS

General Dynamics Information Technology • Chantilly (VA)

On-site
USD 173,000 - 233,000
401K with company match
Comprehensive health and wellness
Internal mobility team
+2
Senior Active Directory Engineer - Active Top Secret required
Senior Active Directory Engineer - Active Top Secret required

General Dynamics Information Technology • Washington

Hybrid
USD 148,000 - 202,000
ICAM Identity Provider (IdP) Engineer - Enterprise Authentication Services
ICAM Identity Provider (IdP) Engineer - Enterprise Authentication Services

General Dynamics Corporation • Falls Church (VA), Northern (KY)

Hybrid
USD 170,000 - 230,000
Technical Architect - Active Top Secret required
Technical Architect - Active Top Secret required

General Dynamics Information Technology • Washington

On-site
USD 135,000 - 224,000
Systems Administrator - TS/SCI with Polygraph
Systems Administrator - TS/SCI with Polygraph

General Dynamics Corporation • McLean (VA)

Hybrid
USD 99,000 - 133,000
401K with company match
Health and wellness packages
Internal mobility team
+3
Systems Administrator Sr - TS/SCI w/Polygraph
Systems Administrator Sr - TS/SCI w/Polygraph

General Dynamics Information Technology • Herndon (VA)

On-site
USD 115,000 - 155,000
401K with company match
Health and wellness packages
Internal mobility team
+3
Sr. Cybersecurity Architect - Active Top Secret
Sr. Cybersecurity Architect - Active Top Secret

General Dynamics Corporation • Washington, Northern (KY)

Hybrid
USD 179,000 - 242,000
Windows Systems Engineer
Windows Systems Engineer

General Dynamics Information Technology • McLean (VA)

On-site
USD 157,000 - 213,000
Directory Services Systems Administrator - Active Top Secret required
Directory Services Systems Administrator - Active Top Secret required

General Dynamics Information Technology • Washington

On-site
USD 104,000 - 140,000
ICAM Systems Engineer & Manager
ICAM Systems Engineer & Manager

General Dynamics Corporation • Town of Florida (NY), Northern (KY)

Hybrid
USD 113,000 - 132,000