AS

Enterprise Active Directory & Email Services Lead

Hiring from
United States
Work type
Remote
Posted
Sep 30, 2026
Is this job info correct?

The Enterprise Active Directory & Email Services Lead will lead the team responsible for enterprise identity, directory, authentication, and messaging services across a large hybrid environment. This role provides hands-on senior technical leadership, people management, and day-to-day delivery accountability for Active Directory, Microsoft Entra ID, identity synchronization, ADFS/federation, MFA, Conditional Access, hybrid Exchange, Exchange Online, Microsoft 365 messaging, mail flow, email security, and related DNS/certificate dependencies. The Lead will directly manage approximately 12 engineers and administrators — including staffing, performance, coaching, and workload management — ensure service reliability and compliance, drive modernization and automation, and act as the senior escalation point for complex identity and messaging issues.

The successful candidate will be accountable for team leadership and staff development, operational excellence, L2/L3 engineering support, incident and problem management, change quality, security hardening, service monitoring, audit readiness, documentation, stakeholder communication, and continuous improvement.

Key Responsibilities

Team Leadership & People Management

  • Directly supervise a team of ~12 AD, identity, Exchange, M365, and messaging engineers/administrators, including hiring, onboarding, and offboarding support.
  • Set individual and team goals; conduct regular 1:1s, performance reviews, and career development/coaching conversations.
  • Manage team schedules, on-call/rotation coverage, workload balancing, and staffing/backfill needs.
  • Approve timesheets, PTO, and other administrative HR actions per company policy.
  • Identify skill gaps and drive training, upskilling, and certification plans across the team.
  • Foster a positive, accountable team culture; handle performance issues, conflict resolution, and disciplinary actions in partnership with HR as needed.
  • Run regular team meetings, tech syncs, and knowledge-sharing sessions to build bench strength.
  • Mentor engineers on technical growth paths and support internal mobility/promotion readiness.

Technical & Service Leadership

  • Own enterprise service health, reliability, security posture, and L2/L3 support for AD, Entra ID, ADFS, identity synchronization, hybrid Exchange, Exchange Online, and email security platforms.
  • Govern AD forest/domain design, sites/services, domains/trusts, GPO, delegation, DNS, replication, SYSVOL, and functional-level standards.
  • Govern Entra ID, Conditional Access, MFA, SSO, authentication methods, application integrations, modern authentication, and legacy protocol reduction.
  • Own hybrid Exchange and Exchange Online service health, mail routing, connectors, SMTP relays, transport rules, mail traces, certificates, and Exchange hybrid optimization.
  • Drive SPF, DKIM, DMARC, anti-phishing controls, email security gateway tuning, retention-related controls, and messaging compliance readiness.
  • Lead high-severity incident response, root-cause analysis, corrective-action planning, and problem management.
  • Define and monitor service KPIs/SLOs for directory, authentication, synchronization, mail flow, and email security.
  • Review and approve complex architectural and operational changes, ensuring risk assessment, rollback planning, and documentation.
  • Drive modernization, automation, technical debt reduction, configuration baselines, and runbook maturity.
  • Partner with cybersecurity, cloud, VMware, platform, network, application, and compliance teams.
  • Lead client/service governance forums and communicate priorities, risks, incidents, and service health in business terms.

Required Qualifications

  • Secret clearance required, or as specified by the account/client.
  • 10+ years of experience in enterprise infrastructure, identity, directory, messaging, or Microsoft platform operations/engineering.
  • 5+ years of experience with Active Directory and Microsoft identity services in large hybrid enterprise environments.
  • 5+ years of experience with Exchange, Exchange Online, Microsoft 365 messaging, SMTP/mail flow, and email security operations.
  • 3+ years directly leading, supervising, or managing technical teams (preferably 10+ personnel), including performance management, staffing, and coaching.
  • Demonstrated experience with ITSM, incident/problem/change management, service metrics, documentation, and client/stakeholder governance.

Preferred Qualifications

  • Experience with Microsoft Defender for Office 365, Proofpoint, Mimecast, Cisco email security, CyberArk, SailPoint, Infoblox, VMware, Azure, and ServiceNow.
  • Experience with PowerShell automation, configuration-as-code, infrastructure-as-code, and operational dashboarding.
  • Experience in regulated, public sector, defense, or other secured environments requiring audit evidence, privileged access controls, and formal change governance.
  • Experience leading identity and messaging modernization programs (ADFS reduction, Conditional Access rollout, Exchange Online migration, on-prem decommissioning, DMARC enforcement).
  • Experience with formal people-management training, performance management frameworks, or supervisory/leadership certifications.

Job Specific Skills

  • Active Directory & Entra ID administration
  • Hybrid Exchange / Exchange Online engineering
  • Identity federation (ADFS), MFA, Conditional Access
  • Email security (SPF/DKIM/DMARC, gateway tuning)
  • Incident, problem, and change management (ITSM)
  • People management and team leadership (~12 FTEs)
  • PowerShell automation
  • Stakeholder/client governance communication

Compensation Ranges

Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.

EEO Requirements

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.

Physical Requirements

The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.

Disclaimer

The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.

Similar jobs

Apply for this job