Job Requirements
Washington, DC
Public Trust Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Systems Administrator - Active Directory
& Entra ID
About the role
We're hiring a Systems Administrator to support our hybrid identity environment across on-premises Active Directory and Microsoft Entra ID. The role requires the ability to produce the identity and access evidence that supports our FISMA compliance and NIST SP 800-53 control assessments.
This role reports to the ICAM Team Lead and works closely with the service desk, the Information System Security Officer (ISSO)
Key responsibilities
Active Directory
Microsoft Entra ID
FISMA and NIST SP 800-53 compliance
Hybrid identity and security operations
Support and collaboration
Required qualifications
Preferred qualifications
Compensation and work environment
& Entra ID
About the role
We're hiring a Systems Administrator to support our hybrid identity environment across on-premises Active Directory and Microsoft Entra ID. The role requires the ability to produce the identity and access evidence that supports our FISMA compliance and NIST SP 800-53 control assessments.
This role reports to the ICAM Team Lead and works closely with the service desk, the Information System Security Officer (ISSO)
Key responsibilities
Active Directory
- Administer users, groups, computers, and OUs across one or more AD domains.
- Manage Group Policy, DNS, and DHCP, and keep domain controllers healthy, patched, and replicating.
- Delegate permissions using least privilege and review AD ACLs and privileged group membership.
- Plan and perform AD backups, recovery testing, and domain controller upgrades.
Microsoft Entra ID
- Manage cloud users, groups, licensing, and administrative units in Entra ID.
- Configure and maintain Conditional Access, MFA, self-service password reset, and authentication methods.
- Administer directory roles and Privileged Identity Management (PIM), including access reviews.
- Register and govern enterprise applications, SSO (SAML/OIDC), and API permission consents.
FISMA and NIST SP 800-53 compliance
- Implement and maintain identity controls mapped to NIST SP 800-53, especially the Access Control (AC), Identification and Authentication (IA), and Audit and Accountability (AU) families.
- Produce recurring compliance reports, such as privileged account inventories, inactive account reviews, MFA coverage, and role assignment exports.
- Gather and organize evidence for annual FISMA assessments, Authority to Operate (ATO) packages, and continuous monitoring.
- Contribute identity sections to the System Security Plan (SSP) and keep control implementation statements current.
- Track identity-related findings in Plans of Action and Milestones (POA&Ms) and drive them to closure.
- Support auditors and assessors with walkthroughs, screenshots, and log evidence.
Hybrid identity and security operations
- Operate and troubleshoot Entra Connect (or Cloud Sync) for directory synchronization.
- Monitor sign-in and audit logs, respond to identity-related alerts, and support incident investigations.
- Maintain identity documentation, runbooks, and onboarding/offboarding procedures.
Support and collaboration
- Serve as escalation point for account, access, and authentication issues from the service desk.
- Partner with security and application teams on new projects, migrations, and access designs.
- Participate in a shared on-call rotation for critical identity services.
Required qualifications
- 4+ years of systems administration experience in a Windows enterprise environment.
- Strong hands-on experience administering Active Directory, including Group Policy, DNS, and delegation.
- 2+ years administering Microsoft Entra ID (formerly Azure AD), including Conditional Access and MFA.
- Experience supporting a hybrid identity setup with Entra Connect or Cloud Sync.
- Working knowledge of FISMA requirements and NIST SP 800-53 controls, with experience producing compliance reports or audit evidence.
- Working knowledge of Microsoft 365 administration and licensing.
- Solid understanding of authentication protocols such as Kerberos, NTLM, SAML, and OAuth/OIDC.
- Clear written communication for documentation, control statements, and working with non-technical staff.
- Bachelor's degree in IT or a related field, or equivalent work experience.
- Ability to obtain and maintain [Public Trust / Secret] clearance, if required.
Preferred qualifications
- PowerShell scripting to automate AD and Entra ID tasks and
compliance reports, including the Active Directory module and Microsoft
Graph PowerShell SDK. - Experience with the NIST Risk Management Framework (RMF), SSPs,
POA&Ms, and ATO processes. - Familiarity with FedRAMP, Microsoft GCC/GCC High, or other
government cloud environments. - Experience applying DISA STIGs or CIS Benchmarks to Windows
servers and domain controllers. - Experience with Privileged Identity Management, access reviews,
and identity governance. - Exposure to Azure RBAC, Microsoft Intune, Microsoft Defender
for Identity, or Entra ID Protection. - Certifications such as Microsoft SC-300 (Identity and Access
Administrator), Security+, or CAP/CGRC.
Compensation and work environment
- Salary: [80,000]-[90,000] USD per
year, based on experience, clearance, and location. - Location: [Remote, Hybrid], [Washington
DC]. - Schedule: Full-time, with
occasional after-hours maintenance windows and a shared on-call rotation. - Benefits: [Health, dental, and
vision insurance; 401(k) ; paid time off
group id: 10290999