Identity & Access Management Lead - TS/SCI with Polygraph

General Dynamics IT

Chantilly (VA)

On-site

USD 213,000 - 288,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

General Dynamics Information Technology (GDIT) seeks an Identity & Access Management Lead to serve as the technical authority for a complex PAM ecosystem supporting password vaulting, JIT access, and Tier-0 protection. The role requires deep AD engineering expertise and the ability to guide a small team delivering mission-critical authentication services.

The ideal candidate brings extensive experience in securing Windows-based identity platforms, is capable of cross-domain design, and excels in

Qualifications

  • 5+ years of related experience
  • US Citizenship Required: Yes
  • Experience designing and securing Windows-based identity platforms

Responsibilities

  • Lead Identity Architecture for a PAM solution, including password vaulting and JIT access.
  • Design, secure, and maintain Windows AD forests and domains, including GPO, DNS, DHCP, PKI, MFA, and hybrid identity integrations.
  • Develop automation with PowerShell to standardize operations and improve reliability.
  • Oversee engineering lifecycle, documentation, deployment plans, and O&M support.
  • Engineer solutions for hybrid cloud integrations and automated deployment via CM tools.
  • Harden identity infrastructure to meet STIG/SCAP and security compliance.
  • Perform advanced systems engineering: modeling, analysis, and architectural enhancements.
  • Plan OS upgrades and directory modernization across enterprise.
  • Create technical documentation for systems and ensure operational readiness.
  • Identify and resolve authentication failures, directory inconsistencies, and PAM anomalies.
  • Provide training and guidance to engineers and staff.
  • Serve as client-facing liaison to align solutions with mission needs.
  • Maintain current knowledge of identity security and directory technologies.
  • Mentor a small engineering team and direct professional development.
  • Govern Tier 0 & Cloud Identity plane across Azure and Entra ID, enforcing strict PAM and SSO integrations.

Skills

Active Directory
Systems Engineering
Zero Trust Architecture

Tools

PowerShell
Windows Server
SCCM/MCM
SCOM
Splunk
Dynatrace
Azure
AWS
VMware ESX
Citrix Xen Desktop/App

Job description

Type of Requisition

Regular

Clearance Level Must Currently Possess

Top Secret SCI + Polygraph

Clearance Level Must Be Able to Obtain

Top Secret SCI + Polygraph

Public Trust/Other Required

None

Job Family

IT Infrastructure and Operations

Job Qualifications
  • Skills: Active Directory (AD), Systems Engineering, Zero Trust Architecture
  • Certifications: None
  • Experience: 5 + years of related experience
  • US Citizenship Required: Yes
Job Description

The Identity & Access Management Lead serves as the lead engineer and technical authority for a complex privileged access management ecosystem supporting password vaulting, just‑in‑time administration, and hardened identity operations. This role requires deep expertise in Active Directory engineering, enterprise identity security, and automation, combined with strong leadership capabilities to guide a small team of engineers delivering mission‑critical authentication and access services.

The ideal candidate brings extensive experience designing, securing, and modernizing Windows‑based identity platforms across large, multi‑domain environments. They demonstrate exceptional problem‑solving skills, clear communication, and a proven ability to operate independently or collaboratively within cross‑functional teams.

Core Responsibilities
  • Lead Identity Architecture for a privileged access management solution, including password vaulting, JIT access workflows, and Tier‑0 protection aligned to Zero Trust principles.
  • Design, secure, and maintain Windows‑based Active Directory forests and domains, including Group Policy, DNS, DHCP, PKI, MFA and hybrid identity integrations
  • Develop automation and tooling using PowerShell to standardize operations, reduce manual effort, and improve reliability across identity services.
  • Oversee engineering lifecycle delivery-requirements refinement, architecture documentation, installation instructions, deployment plans, and O&M support.
  • Engineer solutions for geographically dispersed environments, hybrid cloud integrations, and automated deployment via configuration management platforms.
  • Harden identity infrastructure to meet STIG, SCAP, and enterprise security compliance requirements.
  • Perform advanced systems engineering, including modeling, simulation, analysis, and architectural enhancements.
  • Plan and direct OS upgrades, directory modernization efforts, and enterprise‑wide identity improvements.
  • Develop technical documentation for new and existing systems, ensuring clarity, repeatability, and operational readiness.
  • Identify, analyze, and resolve complex system issues, including authentication failures, directory inconsistencies, and privileged access anomalies.
  • Provide training and technical guidance to engineers and operational support staff.
  • Serve as a client‑facing liaison, ensuring requirements are met and technical solutions align with mission needs.
  • Maintain current knowledge of identity security, Windows infrastructure, and emerging directory technologies.
  • Manage and mentor a small engineering team, providing leadership, direction, and professional development.
  • Tier 0 & Cloud Identity plane governance: Serves as the primary authority for Tier 0 Access Plane Management across Azure and Microsoft Entra ID. Responsible for designing and enforcing strict identity boundary controls, privileged access management (PAM), and Directory‑level security architectures, while overseeing secure application registration and single sign‑on (SSO) integrations using SAML 2.0, OpenID Connect (OIDC), and OAuth.
Preferred Experience & Technical Strengths
  • Directory Services: Active Directory, Group Policy, LDAP, DNS, ADCS, OCSP, DHCP, DFS, ADFS, Entra ID, hybrid identity
  • Security & Identity: PKI, MFA, privileged access controls, STIG compliance, ACAS, vulnerability mitigation
  • Automation & Systems: PowerShell, Windows Server, SCCM/MCM, SCOM, Splunk, Dynatrace
  • Cloud & Virtualization: Azure, AWS, VMware ESX, Citrix Xen Desktop/App
  • Leadership: Technical leadership, identity operations management, cross‑functional coordination
GDIT IS YOUR PLACE

At GDIT, the mission is our purpose, and our people are at the center of everything we do.

Growth: AI-powered career tool that identifies career steps and learning opportunities

Support: An internal mobility team focused on helping you achieve your career goals

Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off

Community: Award-winning culture of innovation and a military-friendly workplace

OWN YOUR OPPORTUNITY

Explore an enterprise IT career at GDIT and you'll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward.

Salary Information

The likely salary range for this position is $212,500 - $287,500. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled W

Scheduled W

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Identity & Access Management Lead - TS/SCI with Polygraph
Identity & Access Management Lead - TS/SCI with Polygraph

General Dynamics Information Technology • Chantilly (VA)

On-site
USD 140,000 - 190,000
401K with company match
Paid time off
Comprehensive benefits
Senior Active Directory Engineer - Active Top Secret required
Senior Active Directory Engineer - Active Top Secret required

General Dynamics Information Technology • Washington

Hybrid
USD 148,000 - 202,000
Lead Enterprise IT Systems Architect - TS
Lead Enterprise IT Systems Architect - TS

General Dynamics Information Technology • Chantilly (VA)

On-site
USD 173,000 - 233,000
401K with company match
Comprehensive health and wellness
Internal mobility team
+2
ICAM Systems Engineer & Manager
ICAM Systems Engineer & Manager

General Dynamics Corporation • Town of Florida (NY), Northern (KY)

Hybrid
USD 113,000 - 132,000
Domain Services Engineer
Domain Services Engineer

General Dynamics Information Technology • St. Louis (MO)

On-site
USD 126,000 - 170,000
Identity Access Management (IAM) Architect
Identity Access Management (IAM) Architect

General Dynamics Information Technology • Washington

On-site
USD 150,000 - 190,000
Identity and Directory Services Engineer - TS/SCI with Polygraph
Identity and Directory Services Engineer - TS/SCI with Polygraph

General Dynamics Information Technology • Chantilly (VA)

On-site
USD 90,000 - 130,000
401K with company match
Health and wellness packages
Internal Mobility team
+3
Windows Systems Engineer
Windows Systems Engineer

General Dynamics Information Technology • McLean (VA)

On-site
USD 157,000 - 213,000
Systems Administrator - TS/SCI with Polygraph
Systems Administrator - TS/SCI with Polygraph

General Dynamics Corporation • McLean (VA)

Hybrid
USD 99,000 - 133,000
401K with company match
Health and wellness packages
Internal mobility team
+3
Directory Services Systems Administrator - Active Top Secret required
Directory Services Systems Administrator - Active Top Secret required

General Dynamics Information Technology • Washington

On-site
USD 104,000 - 140,000