Domain Services Engineer
General Dynamics Information Technology · Springfield, VA · 5 days ago
Engineering$126k–$170k/yrFull-time
GDIT is seeking a Domain Service Engineer to support the planning, building, and operations of a large, globally accessed, hybrid cloud computing system. The role involves providing support, implementation, and design services for ISE and Microsoft Active Directory and Windows-based systems across the enterprise, including directory and identity management solutions.
Responsibilities
- Accountable for the management, uptime, and lifecycle of the organization’s 802.1x architecture.
- Deliver and implement a secure, scalable, and resilient Active Directory design, following industry best practices while adhering to Information Security standards.
- Provide SME-level assistance and escalation support for all troubleshooting tasks related to DNS, DHCP, and AD, including integration with Windows and non-Windows endpoints, authentication, role-based access controls, DNS, DHCP, etc.
- Manage the environment proactively, anticipating risks and issues, designing and engineering for resiliency. Take technical ownership of projects and systems.
- Facilitate the implementation of Group Policy Objects (GPO) based on stated requirements. Troubleshoot and resolve any GPO-related issues.
- Monitor and identify replication interruptions between domain controllers, DNS, and DHCP Server configurations.
- Manage Public Key Infrastructure (PKI) systems and certificates.
- Maintain advanced network access control (NAC) policies, utilizing 802.1X, MAC Authentication Bypass (MAB), and Web Authentication.
- Act as a Tier 3 escalation point for complex 802.1X/RADIUS authentication issues, certificate mismatches, and supplicant-side issues across Windows, macOS, Linux, and IoT devices.
- Configure and optimize network device profiling, Cisco TrustSec (Security Group Tags), and Comply-to-Connect (C2C) architectures.
- Integrate Cisco ISE with Active Directory, Azure AD/Entra ID, PKI/Certificate Authorities, and SIEM tools for automated threat containment and compliance reporting.
- Evaluate existing infrastructure pipelines and propose architectural modernizations to leverage Zero Trust Network Architecture (ZTNA), automation, and hybrid-cloud capabilities.
- Architect, document, and present system-level designs that integrate on-premises systems, virtualization platforms, and public/private cloud environments.
Requirements
- 5+ years of experience in progressive roles from Active Directory Administrator to Sr. Engineer.
- Knowledge of scripting languages (e.g., PowerShell, Python, Bash, or Perl).
- In-depth understanding of Active Directory or LDAP authentication and administration.
- Advanced familiarity with enterprise directory synchronization tools such as Azure Active Directory Connect, Cisco Directory Synchronization, or others.
- Implement and manage enterprise-wide architecture, deployment, and ongoing administration of Cisco ISE.
- US Citizenship required.
Preferred Qualifications
- Analytic mindset with the ability to define complex infrastructure problems, correlate logs across multiple systems (ISE, AD, DNS, Network Switches), and execute systematic resolutions.
- Strong capability to translate highly technical concepts to non-technical business stakeholders and collaborate across siloed Network, Systems, and Security teams.
- Experience troubleshooting various Microsoft Windows Server platforms' roles and features.
- Experience working in a fast-paced government agency production IT environment.
Benefits
- Comprehensive benefits and wellness packages.
- 401(k) plan with company match and the ability to contribute both pre- and post-tax dollars up to IRS annual limits.
- Paid time off plans, including vacation, sick and personal time, holidays, parental, military, bereavement, and jury duty leave.
- Short- and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness, and business travel and accident insurance.
- Full flex work weeks where possible to encourage work/life balance.
- AI-powered career tool for identifying career steps and learning opportunities.
- Internal mobility team focused on helping achieve career goals.
Pay
The likely salary range for this position is $125,800 - $170,200. Salary will be set based on experience, geographic location, and possibly contractual requirements.
Schedule
- Scheduled Weekly Hours: 40
- Telecommuting Options: Onsite
Work Location: USA VA Springfield or USA MO St. Louis (Customer Site / NGA Washington or NGA St. Louis).