Senior Active Directory & Microsoft Entra Identity Engineer (Tier 3 Escalation) - Remote (U.S.)
Lead enterprise identity services for a federal program by designing, implementing, and maintaining hybrid identity platforms combining on-premises Active Directory, AD FS, and Microsoft Entra ID. Provide Tier 3 escalation support for authentication, directory services, and security controls while automating administrative tasks via PowerShell. Requires 7+ years of IT experience, 3+ years in Active Directory, and U.S. citizenship with Public Trust clearance eligibility.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Nice to Have
Job Description
AD / Entra Engineer Sr Tier 3 — Remote (U.S.)
Dunhill Government Solutions is hiring a Senior Active Directory / Microsoft Entra Engineer to support a newly awarded federal program delivering enterprise identity services. This is a full-time, fully remote role and the Tier 3 escalation authority for a hybrid identity platform spanning on-premises Active Directory, AD FS and Microsoft Entra ID.
Responsibilities:
- Design, implement and maintain Active Directory infrastructure — forests, domains, OU structures, domain-controller placement, AD sites, DNS dependencies, replication topology and trusts.
- Architect and support hybrid identity integrating on-premises Active Directory with Microsoft Entra ID, including Entra Connect or cloud sync, password hash synchronization, pass-through authentication, federation and synchronization failover.
- Configure, administer and troubleshoot enterprise authentication and directory services: Kerberos, LDAP, NTLM, DNS service records, AD FS, certificate-dependent authentication and AD trusts.
- Design and maintain secure Group Policy architecture — GPO inheritance, security filtering, baseline configuration, domain-controller hardening and policy-processing failure resolution.
- Provide Tier 3 incident response and root-cause analysis for replication failures, lingering objects, authentication issues, broken trusts, synchronization errors, federation failures and privileged-access problems.
- Implement directory security controls: least-privilege delegated administration, privileged-access boundaries, tiered administrative models, LDAP signing, legacy-protocol reduction and audit-ready configuration.
- Configure and support Microsoft Entra ID capabilities including Conditional Access, multifactor authentication, single sign-on, application registrations, service principals, Identity Protection and Privileged Identity Management.
- Develop PowerShell automation for directory health checks, account and group lifecycle operations, synchronization diagnostics, configuration validation, reporting and repeatable remediation.
- Produce and maintain technical architectures, operational runbooks, recovery procedures, standards, change documentation and knowledge articles.
Interested in remote work opportunities in IT & Network Engineering? Discover IT & Network Engineering Remote Jobs featuring exclusive positions from top companies that offer flexible work arrangements.
Requirements:
- U.S. citizenship, and the ability to obtain and maintain a Public Trust (Tier 1 / NACI) background investigation.
- Bachelor’s degree in information technology, computer science, cybersecurity, engineering or a related discipline, or equivalent relevant experience.
- At least 7 years of hands-on information technology experience.
- At least 3 years engineering, administering and supporting Active Directory and enterprise directory services.
- Demonstrated experience designing and supporting AD forests, domains, domain controllers, sites, DNS integration, replication topology, Group Policy and trust relationships.
- Demonstrated experience supporting hybrid identity across Active Directory, AD FS and Microsoft Entra ID.
- Advanced PowerShell scripting, including automation of administration, health checks, reporting, diagnostics and remediation.
- Preferred: Microsoft Certified Identity and Access Administrator Associate (SC-300); Windows Server Hybrid Administrator Associate (AZ-800 / AZ-801); hands-on Conditional Access, MFA, SSO, PIM and Identity Protection experience. Not holding a certification today does not stop you applying.
- Fully remote, day shift. Travel is not required.
Browse our curated collection of remote jobs across all categories and industries, featuring positions from top companies worldwide.
Compensation: $120,000 to $139,000 per year, full time, 40 hours per week.
Dunhill Government Solutions has placed cleared and public-trust professionals across the federal government for more than 25 years. AI-Powered. Human-Delivered.™
#cjpost
Similar Jobs
Explore other opportunities that match your interests