Point your AI agent at freehire and let it find you a job.

Get the CLI →

jobgether

NewBe an early applicant

Identity & Directory Services Architect

Discussion

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Identity & Directory Services Architect based in the United States.

The Identity & Directory Services Architect will provide senior-level leadership for complex hybrid identity and directory services supporting large-scale enterprise collaboration environments.
You’ll architect and integrate Identity and Access Management capabilities spanning multiple domains and cloud environments.
Your work will enable secure, seamless authentication and access for large user populations across modern connectivity models and devices.
The role combines enterprise architecture, cloud infrastructure, directory services, cybersecurity, and technical engineering.
You’ll support the design, implementation, modernization, and sustainment of critical identity services while ensuring alignment with federal and Department of Defense requirements.
Working with technical teams and senior stakeholders, you’ll help introduce emerging technologies while maintaining secure and resilient enterprise services.
This is a remote opportunity for an experienced identity professional who can provide technical leadership in complex, highly regulated environments.

Accountabilities

  • Design, implement, integrate, modify, and sustain enterprise-wide Identity and Access Management and directory services across hybrid and multi-domain environments.
  • Architect secure authentication and identity solutions capable of supporting large-scale user populations and modern connectivity methods, including mobile devices.
  • Ensure directory and authentication services align with applicable Department of Defense instructions, security requirements, and technical guidance.
  • Provide comprehensive engineering support for enterprise identity projects and operational activities from initial design through deployment and sustainment.
  • Apply expertise across traditional IT infrastructure and cloud computing to incorporate new and emerging technologies into established service environments.
  • Support program management and customer stakeholders with identity, directory, authentication, and infrastructure engineering expertise.
  • Develop highly secure, scalable, and resilient IdAM solutions for multi-tenant and hybrid cloud infrastructures.
  • Design and support Microsoft identity technologies, including Active Directory, Azure Active Directory, and Group Policy.
  • Support identity federation using technologies such as AD FS, Attribute-Based Access Control, and Department of Defense Public Key Infrastructure models.
  • Provide technical expertise across networking technologies including TCP/IP, DNS, DHCP, VoIP, SSL, VPNs, network topology, and firewalls.
  • Support Office 365 management and configuration across Exchange, OneDrive, SharePoint, Office applications, and Azure identity services.
  • Develop, maintain, and contribute to technical, architectural, and process documentation.
  • Provide technical guidance on cloud service delivery models and secure integration patterns.
  • Support DoD cloud security requirements and architectures, including CC-SRG and SCCA environments and Cloud Access Point architectures.
  • Collaborate with technical leadership and senior stakeholders, including executive-level audiences, to communicate architecture, risks, and recommendations.
  • Motivate and guide technical teams to maintain high performance through complex and challenging initiatives.
  • Requirements

    • 15+ years of enterprise engineering and directory services experience.
    • Bachelor’s degree in a related field; equivalent experience may be considered where applicable.
    • Active DoD Secret clearance is required, with the ability to maintain or obtain the required clearance.
    • DoD 8570 IAT Level II certification, such as CompTIA Security+ CE or an equivalent certification.
    • Microsoft Certified Solutions Expert (MCSE) certification or relevant enterprise IT and directory services certification.
    • Demonstrated experience with identity and access management technologies such as SailPoint, Okta, CyberArk, Ping Identity, Radiant Logic, and/or ForgeRock.
    • Deep expertise designing and delivering secure IdAM solutions across multi-tenant and hybrid cloud infrastructures.
    • Strong experience with Microsoft identity technologies, including Active Directory, Azure Active Directory, and Group Policy.
    • Expertise in identity federation, including AD FS, Attribute-Based Access Control, and DoD PKI infrastructure models.
    • Experience with Windows Server environments, particularly versions 2008 through 2016.
    • Strong networking knowledge spanning TCP/IP, DNS, DHCP, VoIP, SSL, VPN, network topology, and firewall technologies.
    • Experience managing and configuring Office 365 services, including Exchange, OneDrive, SharePoint, Office applications, and Azure identity services.
    • Strong technical documentation and communication skills, with the ability to translate complex architecture concepts for technical and non-technical audiences.
    • Ability to lead, motivate, and collaborate with technical teams over long-term and challenging initiatives.
    • Prior experience as an IAM or ICAM consultant, specialist, or engineer is preferred.
    • Experience with cloud service delivery models and federal or DoD cloud security architectures is advantageous.
    • Familiarity with DoD Cloud Computing Security Requirements Guide (CC-SRG), SCCA architectures, and Cloud Access Point (CAP) architectures is preferred.
    • Comfortable presenting technical concepts and recommendations to senior technical leaders and C-suite executives.
    • U.S. citizenship is required.
    • Benefits

      • $174,250–$235,750 estimated annual salary range, with actual compensation determined by experience, geographic location, and potentially contractual requirements.
      • Fully remote work arrangement.
      • 40-hour standard workweek.
      • No travel required.
      • 401(k) plan with company match.
      • Comprehensive health and wellness benefits.
      • Medical plan options, including plans with Health Savings Accounts.
      • Dental and vision coverage.
      • Paid vacation, sick, personal, and holiday leave.
      • Paid parental, military, bereavement, and jury-duty leave.
      • Typically 15 days of paid leave per calendar year for new employees, plus 10 paid holidays, subject to applicable policies and prorating.
      • Up to 160 hours of paid family leave over a rolling 12-month period for eligible employees.
      • Short- and long-term disability benefits.
      • Life, accidental death and dismemberment, personal accident, critical illness, and business travel and accident insurance options.
      • Flexible work arrangements and full-flex work weeks where applicable.
      • Professional development opportunities, including paid education and certifications.
      • Internal mobility support focused on career development and advancement.
      • Exposure to cutting-edge identity, cloud, cybersecurity, and enterprise infrastructure technologies.
      • Opportunity to contribute to complex mission-focused technology programs.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

Skills

See also

Architecture jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available