Empower AI

Account / Access Management Specialist

Empower AI • $82K — $128K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree with 3 years of related experience (or equivalent experience in lieu of degree).
  • U.S. Citizenship required.
  • Active Top Secret Clearance needed to start; must be a Privileged User.
  • Willing to obtain TS/SCI eligibility post-start if required.
  • Current DoD 8570/8140 IAT Level II certification (e.g., CompTIA Security+ CE).
  • 3+ years administering Active Directory and identity/access management services in enterprise settings.
  • Strong knowledge of Active Directory, Group Policy, Kerberos/NTLM authentication, and Windows Server.

Responsibilities

  • Administer Active Directory domains and related identity services across various security enclaves.
  • Manage lifecycle of user, service, and privileged accounts including provisioning, modification, and periodic access reviews.
  • Support and enhance Active Directory orchestration with ServiceNow for self-service functionalities.
  • Act as Tier III escalation point for complex authentication and authorization issues from Tier I/II support.
  • Automate identity management tasks using PowerShell and workflow tools to reduce manual effort.
  • Apply DISA STIGs and remediate vulnerabilities according to policy timelines.
  • Coordinate with cybersecurity initiatives and maintain identity/access documentation.

Benefits

  • Full-time salary position with FLSA-exempt status.
  • Onsite role with low travel requirements (up to 10%).
  • Work in a supportive environment focused on cybersecurity posture.
  • Opportunity to engage in Zero Trust and ICAM initiatives.
  • Potential career growth through involvement in advanced projects and technologies.
Full Job Description
Overview

Empower AI is seeking a Systems Administrator (Identity and Access Management) to administer directory services, account lifecycle, and access management capabilities for a Department of War agency supported by an enterprise IT Customer Support Services program. The administrator manages Active Directory and related identity services across multiple security enclaves, supports the Active Directory orchestration and ServiceNow AI Ops automation that delivers Tier 0 self-service password resets and account unlocks, and serves as the Tier III escalation point for complex account, permission, and authentication issues. As a privileged user, this role is central to both the customer experience objective of the program (resolve at the lowest tier) and its cybersecurity posture (least privilege, auditable access). This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers. 

 

THIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED. 

 

JOB DUTIES: 

  • Administer Active Directory domains, organizational units, groups, Group Policy, DNS/DHCP as applicable, and related identity services (e.g., Entra ID/Azure AD synchronization, ADFS, certificate-based authentication) across NIPRNet, SIPRNet, and JWICS enclaves. 
  • Manage the user, service, and privileged account lifecycle: provisioning, modification, deprovisioning, group membership, permissions, and periodic access reviews, in accordance with approved processes and least-privilege principles. 
  • Support, maintain, and enhance the Active Directory orchestration and ServiceNow AI Ops/Virtual Agent integrations that enable Tier 0 self-service password resets, account unlocks, and status checks, and measure their contribution to ticket deflection. 
  • Serve as the Tier III escalation point for complex authentication, authorization, CAC/PKI logon, group policy, and account issues escalated from Tier I/II, resolving PL1-PL4 tickets within PRS timeframes and following the Customer-Confirmed Ticket Closure process. 
  • Automate identity and access management tasks with PowerShell and workflow tools, develop request fulfillment workflows with the ITSM platform team, and reduce manual account administration effort. 
  • Apply DISA STIGs to directory and identity systems, remediate vulnerabilities within policy timeframes, support audit log review and privileged access monitoring, and provide control evidence and POA&M inputs for RMF packages in eMASS. 
  • Support ICAM and Zero Trust initiatives, including attribute-based access, conditional access, and identity governance improvements, and coordinate with cybersecurity, endpoint, and collaboration platform administrators. 
  • Maintain identity and access documentation, SOPs, knowledge articles, and Tier I enablement content, and provide account and access performance data for the Customer Support Metrics Dashboard. 
Qualifications

REQUIREMENTS: 

  • Bachelor's degree and a minimum of 3 years of related experience (an additional 4 years of related experience may be substituted for the degree). 
  • Must be a U.S. Citizen. 
  • Must have an Active Top Secret Clearance (favorably adjudicated T5/T5R) to start; this is a Privileged User position. 
  • Must be willing and able to obtain TS/SCI eligibility after start, if required by mission needs. 
  • Must be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting. 
  • Must possess and maintain a current DoD 8570/8140 IAT Level II baseline certification (e.g., CompTIA Security+ CE, CySA+, GSEC, SSCP, or CCNA-Security). 
  • Demonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision. 
  • Minimum of 3 years of experience administering Active Directory and identity and access management services in an enterprise environment. 
  • Strong knowledge of Active Directory architecture, Group Policy, DNS, Kerberos/NTLM authentication, PKI/CAC-based logon, and Windows Server. 
  • Proficiency in PowerShell scripting for account administration and automation. 
  • Experience with identity governance concepts: least privilege, role-based access, privileged account management, and access reviews. 
  • Experience applying DISA STIGs and remediating vulnerabilities on Windows Server and directory services. 
  • Experience executing changes through formal Change Management; ability to participate in an after-hours on-call rotation and Saturday maintenance windows. 
  • Strong analytical, documentation, and customer communication skills. 

 

DESIRED SKILLS: 

  • Microsoft Certified: Identity and Access Administrator Associate or Windows Server Hybrid Administrator; CompTIA Security+ CE or CySA+. 
  • Experience with ServiceNow AI Ops, Virtual Agent, or Active Directory orchestration for self-service password reset and account unlock. 
  • Experience with Entra ID (Azure AD), conditional access, ADFS, and Microsoft 365 GCC High identity integration. 
  • Experience supporting Department of War (DoW), DoD, or Intelligence Community environments across multiple enclaves. 
  • Familiarity with DoD ICAM Strategy, Zero Trust Reference Architecture, and privileged access management tools. 
  • Familiarity with eMASS, ACAS, and RMF control evidence for identity systems. 
  • Experience using ServiceNow (incident, request, knowledge, CMDB, Service Catalog, Virtual Agent) or a comparable enterprise ITSM platform. 

 

 

PHYSICAL REQUIREMENTS:

 

This position requires the ability to perform the below essential functions:

 

  • Sitting for long periods
  • Standing for long periods
  • Ambulate throughout an office
  • Ambulate between several buildings

 

Pay Band MinUSD $82,980.00/Yr. Pay Band MaxUSD $128,440.00/Yr.

About Empower AI

Empower AI is a privately held company that develops artificial intelligence software for the healthcare industry. The company was founded in 2017 and is headquartered in Cambridge, Massachusetts. Empower AI's software uses machine learning algorithms to analyze medical data and provide insights to healthcare providers. The company's software is designed to improve patient outcomes and reduce healthcare costs. Empower AI has approximately 50 employees and operates in the United States.
Learn more about Empower AI
Size
50 employees
Industry
Founded
1989

Similar Jobs

More Jobs at Empower AI

More Aerospace & Defense Jobs

Find similar Account / Access Management Specialist jobs: