Mediabistro logo
job logo

ICAM/AD Solutions Architect

Comfort Systems USA · Washington, DC, USA ·

Pay:
$131,300-$237,350/yr
Job type:
Full Time

Description
Leidos is seeking a Senior Technical Solutions Architect responsible for delivering modern Identity Access Credential Management (ICAM) solutions and Zero Trust Architectures (ZTA). Role responsibilities include technical leadership for modernization initiatives, translating business requirements into technical solutions alternatives, hands‑on implementation/prototyping of identified solutions, and IPT project management activities across multiple ICAM service capabilities. The ideal candidate will be a technical leader for designing, implementing, managing, troubleshooting, and optimizing enterprise‑grade Active Directory and Entra ID solutions. This role is critical in maintaining secure, scalable, and highly available identity infrastructure across on‑premises and cloud environments.

Key Responsibilities

Manage and prioritize tasks within the team directory services team, ensuring timely delivery of projects and effective resource utilization.

Design, implement, and manage Active Directory Domain Services (AD DS), including forest/domain architecture, trusts, replication, and high availability.

Lead hybrid identity initiatives using Azure AD Connect, Entra ID, and cloud sync technologies.

Develop best‑of‑breed ZT and ICAM solutions through COTS integration activities

Perform technical triage, business to technical requirements decomposition, and solutioning as part of the requirements process that inform downstream feature development

Manage and optimize Group Policy Objects (GPOs), OU structures, and security baselines.

Implement and maintain identity governance, role‑based access control (RBAC), Privileged Identity Management (PIM), and Conditional Access policies in Azure.

Perform AD health monitoring, performance tuning, backup/recovery, and disaster recovery planning.

Migrate and modernize legacy AD environments to Azure‑native or hybrid solutions.

Perform hands‑on implementation / prototyping of solutions

Provide oral and written presentations to senior leaders describing solution options along with advantages and disadvantages of alternatives

Champions the development, documentation, and execution of system policies

Influence project/team leaders regarding solution design, process and/or approaches.

Requires expert knowledge of and ability to apply advanced technical principles, theories, and concepts.

Troubleshoot complex identity and authentication issues across Windows, Azure, and third‑party applications.

Collaborate with Security, Networking, and Application teams to enforce Zero Trust principles and compliance standards (e.g., NIST, CIS, SOC2, ISO27001).

Qualifications

BS degree and 12+ years of prior relevant experience; additional experience in lieu of degree

8+ years of hands‑on experience in a lead role

MCSE or MCSA certification in Windows Server / Directory Services is required

Proven experience/proficiency in enterprise‑level Windows Server administration and Directory Services management.

Proven experience with Azure services: Azure Virtual Machines, Azure AD Domain Services, Azure Arc, and Microsoft Entra suite.

Understanding of Attributes Based Access Control (ABAC) implementation, Role‑Based Access Control (RBAC), and Policy‑Based Access Control (PBAC)

Strong expertise in Azure AD / Entra ID, hybrid identity, and cloud migration projects.

Deep knowledge of Windows Server operating systems (2016/2019/2022), AD DS, DNS, DHCP, PKI, and certificate services.

Proven experience with Azure services: Azure Virtual Machines, Azure AD Domain Services, Azure Arc, and Microsoft Entra suite.

PowerShell scripting proficiency for automation and reporting.

Demonstrated experience with one of more of the following:

Digital Identity Management and Identity Governance

Authorization ICAM services

Data Security Architecture and Data Protection Services

Customer Identity Access Management (CIAM) solutioning

Authentication and Multi‑Factor Authentication (MFA) solutions

Cloud first and cloud native architectures (any or all of Amazon Web Services, Azure, Google Cloud)

Utilizing cloud services to build infrastructure as code in an automated fashion

Must have a solid understanding of IdAM / ICAM Services like Authentication, Authorization, Identity, and Data Protection through Digital Policy

Demonstrated experience for client support of large scale enterprise applications

Strong communication skills via documentation and verbally with senior management

Desirable Skills

Certifications:

Microsoft Certified: Azure Administrator Associate (AZ‑104)

Microsoft Certified: Identity and Access Administrator Associate (AZ‑305 or SC‑300)

Microsoft Certified: Windows Server Hybrid Administrator Associate (preferred)

Familiarity with Power BI or other reporting tools

Experience with Azure Landing Zones, Governance (Azure Policy, Blueprints), and Bicep/Terraform.

Knowledge of modern authentication protocols (SAML, OAuth, OpenID Connect, Kerberos, NTLM).

Familiarity with security tools such as Microsoft Defender for Identity, Sentinel, and Privileged Access Workstation (PAW).

Experience with DevOps and automation: PowerShell, Lambda

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Pay Range
Pay Range $131,300.00 - $237,350.00

About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .

Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers.

Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement.

More details are available at www.leidos.com/careers/pay-benefits .

Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law.

Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.

Leidos will consider qualified applicants with criminal histories for employment in accordance with relevant Laws.

Leidos is an equal opportunity employer/disability/vet.

#J-18808-Ljbffr