The Identity & Access Management Lead serves as the lead engineer and technical authority for a complex privileged access management ecosystem supporting password vaulting, just-in-time administration, and hardened identity operations. This role requires deep expertise in Active Directory engineering, enterprise identity security, and automation, combined with strong leadership capabilities to guide a small team of engineers delivering mission-critical authentication and access services.
The ideal candidate brings extensive experience designing, securing, and modernizing Windows-based identity platforms across large, multi-domain environments. They demonstrate exceptional problem-solving skills, clear communication, and a proven ability to operate independently or collaboratively within cross-functional teams.
Core Responsibilities:
- Lead Identity Architecture for a privileged access management solution, including password vaulting, JIT access workflows, and Tier-0 protection aligned to Zero Trust principles.
- Design, secure, and maintain Windows-based Active Directory forests and domains, including Group Policy, DNS, DHCP, PKI, MFA and hybrid identity integrations
- Develop automation and tooling using PowerShell to standardize operations, reduce manual effort, and improve reliability across identity services.
- Oversee engineering lifecycle delivery - requirements refinement, architecture documentation, installation instructions, deployment plans, and O&M support.
- Engineer solutions for geographically dispersed environments, hybrid cloud integrations, and automated deployment via configuration management platforms.
- Harden identity infrastructure to meet STIG, SCAP, and enterprise security compliance requirements.
- Perform advanced systems engineering, including modeling, simulation, analysis, and architectural enhancements.
- Plan and direct OS upgrades, directory modernization efforts, and enterprise-wide identity improvements.
- Develop technical documentation for new and existing systems, ensuring clarity, repeatability, and operational readiness.
- Identify, analyze, and resolve complex system issues, including authentication failures, directory inconsistencies, and privileged access anomalies.
- Provide training and technical guidance to engineers and operational support staff.
- Serve as a client-facing liaison, ensuring requirements are met and technical solutions align with mission needs.
- Maintain current knowledge of identity security, Windows infrastructure, and emerging directory technologies.
- Manage and mentor a small engineering team, providing leadership, direction, and professional development.
- Tier 0 & Cloud Identity plane governance: Serves as the primary authority for Tier 0 Access Plane Management across Azure and Microsoft Entra ID. Responsible for designing and enforcing strict identity boundary controls, privileged access management (PAM), and Directory-level security architectures, while overseeing secure application registration and single sign-on (SSO) integrations using SAML 2.0, OpenID Connect (OIDC), and OAuth.
Preferred Experience & Technical Strengths
- Directory Services: Active Directory, Group Policy, LDAP, DNS, ADCS, OCSP, DHCP, DFS, ADFS, Entra ID, hybrid identity
- Security & Identity: PKI, MFA, privileged access controls, STIG compliance, ACAS, vulnerability mitigation
- Automation & Systems: PowerShell, Windows Server, SCCM/MCM, SCOM, Splunk, Dynatrace
- Cloud & Virtualization: Azure, AWS, VMware ESX, Citrix Xen Desktop/App
- Leadership: Technical leadership, identity operations management, cross-functional coordination
GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
- Growth: AI-powered career tool that identifies career steps and learning opportunities
- Support: An internal mobility team focused on helping you achieve your career goals
- Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
- Community: Award-winning culture of innovation and a military-friendly workplace
OWN YOUR OPPORTUNITY
Explore an enterprise IT career at GDIT and you'll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward.