Full Job Description
We have an opening for an experienced Active Directory Administrator to help design, automate, secure, and support enterprise-wide Active Directory services in a highly regulated environment. This role is ideal for someone who enjoys combining hands-on operations, platform engineering, and security compliance to support mission-critical computing services. This position is in the Information Technology Solutions (ITSD) Division within the Computing Directorate.
This position requires full-time on-site presence due to the nature of the work.
This position will be filled at either level based on knowledge and related experience as assessed by the hiring team. Additional job responsibilities (outlined below) will be assigned if hired at the higher level.
You will
• Perform day-to-day operational support functions, including complex problem isolation and remediation, while exercising sound judgment and a moderate degree of independence.
• Contribute to the development, implementation, testing, and validation of security benchmarks (DISA STIG), including implementing monthly patching and vulnerability remediation.
• Troubleshoot, configure, and maintain Group policies in support of secure enterprise Active Directory operations.
• Integrate applications and services with Entra ID.
• Develop scripting and automation for solutions to common problems and reduce operational overhead.
• Develop and maintain clear technical documentation to support system administration, integration, operations and knowledge sharing.
• Collaborate with engineers, security teams, and other stakeholders.
• Support critical systems off-hours as needed and part of a regular 24/7 on-call rotation.
• Perform other duties as assigned.
Additional job responsibilities, at the 393.2 level
• Manage multiple complex parallel tasks and priorities of customers and stakeholders, ensuring deadlines are met, while leveraging team member skills.
• Leverage tools and develop procedures to improve windows configuration management services and automate various complex tasks.
Qualifications
• Ability to secure and maintain a U.S. DOE Q-level security clearance which requires U.S. citizenship.
• Bachelor's degree in computer science, Computer Engineering or related field, or the equivalent combination of education and related experience.
• Broad experience operating and supporting Microsoft Active Directory in an enterprise setting including the use of PowerShell
• Broad experience administering Windows server environments including deployment, patching, monitoring, backup or repairing.
• Ability to work in a dynamic, technical team environment with competing priorities, tight deadlines and high pressure associated with operating a critical, complex system.
• Broad experience with Azure, Entra ID and cloud security
• Proficient written and verbal communication and strong interpersonal skills, ability to interact with all levels of management and staff as well as outside vendors, contractors, service providers and consultants.
• Ability to work off-hours and On-Call and to respond to service alerts from various monitoring systems (intermittently, either as-needed or as part of a rotation).
Additional qualifications at the 393.2 level
• Highly advanced experience architecting and administering highly redundant and fault tolerant enterprise Windows server environments including deployment, patching, monitoring, backup and repairing.
• Substantial experience with Entra ID operations including identity management and authentication integrations
• Expert knowledge and experience with standard authentication protocols such as SAML, OAuth, or OIDC.
Qualifications We Desire
• Broad experience with monitoring platforms such as SCOM or Splunk.
• Broad experience with MS SQL or other relational databases.
• Experience with applying DISA STIG requirements.
Pay Range
$125,310 - $185,640 annually
$125,310 - $153,444 annually for 393.1
$151,620 - $185,640 annually for 393.2
This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting; pay will not be below any applicable local minimum wage. An employee's position within the salary range will be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, and business or organizational needs.
Additional Information
#LI-Onsite
Position Information
This is a Career Indefinite position, open to Lab employees and external candidates.