Posted 3 days ago
Cloud Engineer
AI Summary
Supports and maintains enterprise identity and messaging services across on-premises and Microsoft cloud environments in a federal setting, administering Active Directory, Entra ID, Exchange Server, and hybrid services.
About this role
The Senior Identity and Messaging Engineer is responsible for supporting, maintaining, securing, and enhancing enterprise identity and messaging services across on-premises and Microsoft cloud environments. This hands-on role administers and engineers Microsoft Active Directory, Microsoft Entra ID, Exchange Server, Exchange Online, and the hybrid services that connect them in a complex federal environment.
- Must have existing Top Secret and/or DOE Q Clearance
Responsibilities
Active Directory Administration & Engineering
Exchange Administration & Engineering
Identity & Access Management
- Implement and support Microsoft Entra ID (Azure Active Directory).
- Deploy, configure, maintain, and troubleshoot Microsoft Entra Connect and Entra Cloud Sync, including scoping and filtering, attribute flow, source anchor decisions, synchronization monitoring, and error remediation.
- Configure and troubleshoot hybrid authentication using Password Hash Synchronization, Pass-through Authentication, and Active Directory Federation Services, and support migrations away from federation where appropriate. Implement Single Sign-On, Conditional Access, Multi-Factor Authentication, Privileged Identity Management, and phishing-resistant authentication using PIV/CAC and certificate-based authentication.
- Participate in identity governance and role-based access control initiatives.
- Collaborate with security teams to enforce Zero Trust architecture principles.
- Work within segmented, multi-enclave federal networks to maintain Active Directory replication, authentication, directory synchronization, and mail flow across firewalls, VLANs, proxies, and security zones.
- Identify and document required ports, protocols, Microsoft 365 endpoints, and GCC High or DoD-specific allow-list requirements.
- Troubleshoot connectivity with Wireshark, netsh, pktmon, port testing, packet captures, and log analysis to isolate identity, application, and network failures.
- Configure and troubleshoot split-brain and conditional DNS, forwarders, load balancers, VPN, SD-WAN, ExpressRoute, TIC 3.0 paths, DMZ services, and disconnected or cross-domain environments as applicable.
- Ensure systems comply with DOE requirements, NIST Special Publication 800-53, FISMA, FedRAMP, DISA Security Technical Implementation Guides, and applicable CISA Secure Cloud Business Applications baselines. Support Authority to Operate activities, security control assessments, audit evidence requests, vulnerability remediation, and compliance reporting.
- Perform vulnerability remediation, security hardening, and patch management.
- Support audits, security assessments, and compliance reporting activities.
- Implement security baselines and monitor for unauthorized changes or suspicious activity.
- Assist with incident response and forensic investigations involving identity and messaging systems.
- Develop and maintain PowerShell and Microsoft Graph automation for administration, reporting, monitoring, user lifecycle management, mailbox provisioning, group management, and repeatable operational tasks.
- Automate user lifecycle management, mailbox provisioning, and group management processes.
- Produce solution designs, operational runbooks, standard operating procedures, as-built documentation, port and protocol matrices, and technical diagrams that meet federal documentation and audit standards.
- Support enterprise modernization initiatives involving Microsoft 365 and cloud migrations.
- Provide Tier III escalation support for identity and messaging-related issues.
- Participate in on-call support rotations as required.
- Troubleshoot complex authentication, replication, Exchange, and directory synchronization issues.
- Coordinate maintenance activities and planned outages.
Network and Infrastructure
Cybersecurity & Compliance
Automation & Engineering
Operations Support
Qualification
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or related field with 7 or more years of experience administering Active Directory in enterprise environments, including multi-domain or multi-forest architectures.
- 5 or more years of experience administering Exchange Server, including hands-on responsibility for at least one Exchange hybrid deployment, and three or more years supporting Microsoft 365, Microsoft Entra ID, and Exchange Online.
- Experience supporting enterprise environments with 5,000+ users preferred.
- Senior-level experience supporting federal government customers onsite, with a demonstrated record of working effectively with government program managers, CIO staff, security officers, and contractors in professional, multi-vendor environments.
- Demonstrated knowledge of TCP/IP, routing, subnetting, Network Address Translation, VLANs, firewalls, DNS, PKI and certificates, SMTP, Kerberos, and LDAP. Proven ability to diagnose network-related authentication, directory synchronization, and mail flow failures using packet capture, port testing, and log analysis in environments with strict change control.
- PowerShell scripting and automation
- Microsoft 365 Administration
- Identity and Access Management (IAM)
- Certificate Services (PKI)
- Active Directory Federation Services (ADFS)
- Windows Server Administration
- Experience implementing Exchange Hybrid environments.
- Experience with Microsoft Defender, Microsoft Purview, and Microsoft Sentinel.
- Experience with CyberArk, Beyond Trust, or other Privileged Access Management (PAM) solutions.
- Experience supporting Zero Trust initiatives.
- Familiarity with virtualization technologies such as VMware or Hyper-V.
- Experience administering Microsoft 365 in GCC, GCC High, or DoD tenants, including government-specific endpoints, security controls, service limitations, and hybrid connectivity requirements.
- Experience with PIV/CAC authentication, federal Identity, Credential, and Access Management requirements, administrative forest or ESAE/Red Forest architectures, one-way trusts, shadow principals, bastion forests, or Microsoft Identity Manager Privileged Access Management.
- Familiarity with Active Directory consolidation, domain migrations, tenant-to-tenant migrations, Azure networking, TIC 3.0, Zero Trust network architecture, and cross-domain solutions.
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft 365 Certified: Administrator Expert (MS-102)
- Microsoft 365 Certified: Messaging Administrator Associate (MS-203 legacy)
- CompTIA Security+ or another DoD 8140-qualifying certification
- CCNA, Network+, or equivalent networking certification
- CISSP
- GIAC Certifications
- ITIL Foundation
Infrastructure: Windows Server (2003-2025), Active Directory / GPO, Hyper-V & VMware, DHCP / DNS / NPS
Security & Compliance: DISA STIGs, Trellix EPO / HIPS, Vulnerability Scanners, (ACAS / Nessus)
Systems Management: MECM / SCCM, Exchange Server (2003-2019), Microsoft Active Directory, Entra ID and Azure AD Connect, Domain Services (AD DS), Red Hat / Linux+, Orchestrator / PowerShell
Preferred Qualifications
Certifications (Preferred)
Skills
Explore related jobs
More jobs at Planet Technologies
Similar Active Directory jobs
Jobs in Denver
- P
Senior Electrical EngineerProject Canary · Denver Headquarters - YJourneyman ElectricianYellowstone Local · Denver, Colorado
- 5Licensed Clinical Social Worker (LCSW)5280 High School · Denver, Colorado
- TDirector, Clinical Programs (Clinical Enterprise)TRC Total Renal Care Inc · 05555 - Casa del Mundo Office (Denver HQ)
- GAssociate MerchantGoldBug · Denver, Colorado
- DTransportation SupervisorDomino's · Denver, CO
Browse these categories
Market data for this role
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.