Manage and prioritize tasks within the team directory services team, ensuring timely delivery of projects and effective resource utilization.
Design, implement, and manage Active Directory Domain Services (AD DS), including forest/domain architecture, trusts, replication, and high availability.
Lead hybrid identity initiatives using Azure AD Connect, Entra ID, and cloud sync technologies.
Develop best-of-breed ZT and ICAM solutions through COTS integration activities
Perform technical triage, business to technical requirements decomposition, and solutioning as part of the requirements process that inform downstream feature development
Manage and optimize Group Policy Objects (GPOs), OU structures, and security baselines.
Implement and maintain identity governance, role-based access control (RBAC), Privileged Identity Management (PIM), and Conditional Access policies in Azure.
Perform AD health monitoring, performance tuning, backup/recovery, and disaster recovery planning.
Migrate and modernize legacy AD environments to Azure-native or hybrid solutions.
Perform hands-on implementation / prototyping of solutions
Provide oral and written presentations to senior leaders describing solution options along with advantages and disadvantages of alternatives
Champions the development, documentation, and execution of system policies
Influence project/team leaders regarding solution design, process and/or approaches.
Requires expert knowledge of and ability to apply advanced technical principles, theories, and concepts.
Troubleshoot complex identity and authentication issues across Windows, Azure, and third-party applications.
Collaborate with Security, Networking, and Application teams to enforce Zero Trust principles and compliance standards (e.g., NIST, CIS, SOC2, ISO27001).
BS degree and 12+ years of prior relevant experience; additional experience in lieu of degree
8+ years of hands-on experience in a lead role
MCSE or MCSA certification in Windows Server / Directory Services is required
Proven experience/proficiency in enterprise-level Windows Server administration and Directory Services management.
Proven experience with Azure services: Azure Virtual Machines, Azure AD Domain Services, Azure Arc, and Microsoft Entra suite.
Understanding of Attributes Based Access Control (ABAC) implementation, Role-Based Access Control (RBAC), and Policy-Based Access Control (PBAC)
Strong expertise in Azure AD / Entra ID, hybrid identity, and cloud migration projects.
Deep knowledge of Windows Server operating systems (2016/2019/2022), AD DS, DNS, DHCP, PKI, and certificate services.
Proven experience with Azure services: Azure Virtual Machines, Azure AD Domain Services, Azure Arc, and Microsoft Entra suite.
PowerShell scripting proficiency for automation and reporting.
Demonstrated experience with one of more of the following:
Digital Identity Management and Identity Governance
Authorization ICAM services
Data Security Architecture and Data Protection Services
Customer Identity Access Management (CIAM) solutioning
Authentication and Multi-Factor Authentication (MFA) solutions
Cloud first and cloud native architectures (any or all of Amazon Web Services, Azure, Google Cloud)
Utilizing cloud services to build infrastructure as code in an automated fashion
Must have a solid understanding of IdAM / ICAM Services like Authentication, Authorization, Identity, and Data Protection through Digital Policy
Demonstrated experience for client support of large scale enterprise applications
Strong communication skills via documentation and verbally with senior management
US Citizenship
Ability to obtain and maintain Public Trust.