Mediabistro logo
job logo

Senior Directory Infrastructure engineer

3B Staffing LLC, Washington, District of Columbia, United States


Senior Directory Infrastructure Engineer for Remote Assignment in Washington, DC

The ideal candidate is a DMV resident with over 5 years of hands-on experience with enterprise directory services, such as Active Directory, Entra ID, OKTA Universal Directory, and LDAP. They should also have advanced PowerShell scripting skills and experience with Microsoft Graph API and REST API integration for directory management.

Senior Directory Infrastructure Engineer to support the Client for a remote role in Washington, DC.

Position Description: The Office of the Chief Technology Officer's Security and Engineering Team manages a variety of functions, including endpoint management, Active Directory, VPN, firewalls, and security incident response. The team is seeking experienced Directory Infrastructure Engineers with extensive expertise in enterprise identity infrastructure, including Active Directory, Entra ID (formerly Azure AD), OKTA Universal Directory, and LDAP environments. The resource must have a proven track record of designing and managing complex directory services across multiple platforms with particular emphasis on the complete lifecycle management of AD domains. The ideal candidates will bring expertise in modern identity approaches, including Just-In-Time access, Privileged Identity Management, and continuous validation patterns that balance security with user experience.

Position Responsibilities:

Design, implement, and maintain enterprise directory services infrastructure

Manage the complete lifecycle of AD domains, including planning, deployment, maintenance, upgrades, and decommissioning

Lead domain consolidation, migration, and forest restructuring projects

Develop domain health monitoring and proactive maintenance procedures

Create and execute disaster recovery plans for directory services

Develop and maintain automation scripts using PowerShell for directory management tasks

Interface with directory services using Graph API and REST API for custom integrations

Implement and maintain security best practices for directory services

Design and manage trust relationships between domains and forests

Create and maintain documentation for directory architecture and operational procedures

Provide escalation support for critical directory service incidents

General skills Must have

Experience with enterprise directory services (Active Directory, Entra ID, OKTA Universal Directory, LDAP)- 6 year(s) of experience

Experience with AD domain lifecycle management including domain creation, upgrades, and decommissioning- 5 year(s) of experience

Advanced PowerShell scripting skills with demonstrable experience automating directory management tasks-5 year(s) of experience

Proven experience with Microsoft Graph API and REST API integration for directory management- 5 year(s) of experience

Strong understanding of identity security best practices and compliance requirements-5 year(s) of experience

Experience with directory synchronization technologies (Azure AD Connect, OKTA integration agents, etc.)- 5 year(s) of experience

Experience with multi-forest and hybrid identity environments- 5 year(s) of experience

Ability to design and implement complex directory architecture solutions- 5 year(s) of experience

Bachelor's degree in IT or related field or equivalent experience

Required Qualifications:

5+ years of hands-on experience with enterprise directory services (Active Directory, Entra ID, OKTA Universal Directory, LDAP)

Demonstrated experience with AD domain lifecycle management, including domain creation, upgrades, and decommissioning

Advanced PowerShell scripting skills with demonstrable experience automating directory management tasks

Proven experience with Microsoft Graph API and REST API integration for directory management

Experience with directory synchronization technologies (Azure AD Connect, OKTA integration agents, etc.)

Strong understanding of identity security best practices and compliance requirements

Experience with multi-forest and hybrid identity environments

Ability to design and implement complex directory architecture solutions

Preferred Qualifications:

Relevant certifications (Microsoft 365 Certified: Identity and Access Administrator, OKTA Professional, etc.

Experience with Terraform, Ansible, or similar IaC tools for directory infrastructure

Knowledge of SAML, OAuth, OIDC, and other modern authentication protocols

Experience with Group Policy design and management

Expertise in domain controller sizing, placement, and performance optimization

Experience with domain functional level upgrades and cross-domain migrations

Familiarity with CI/CD pipelines for infrastructure automation

Experience with implementing Zero Trust architecture

Minimum Education/ Certification Requirements:

Bachelor's degree in information technology or related field, or equivalent experience

Skills Matrix:

Experience with enterprise directory services (Active Directory, Entra ID, OKTA Universal Directory, LDAP) | Required | 6

Experience with AD domain lifecycle management, including domain creation, upgrades, and decommissioning | Required | 5

Advanced PowerShell scripting skills with demonstrable experience automating directory management tasks | Required | 5

Proven experience with Microsoft Graph API and REST API integration for directory management | Required | 5

Strong understanding of identity security best practices and compliance requirements | Required | 5

Experience with directory synchronization technologies (Azure AD Connect, OKTA integration agents, etc.) | Required | 5

Experience with multi-forest and hybrid identity environments | Required | 5

Ability to design and implement complex directory architecture solutions | Required | 5

Bachelor's degree in IT or related field or equivalent experience | Required