IT Services and IT Consulting👥 201 employees📍 Gaithersburg, MD, USEst. 1997
Planet Technologies was built around investing in and developing long term relationships with our customers and corporate partners. We work hard to keep our staff trained on the latest technologies, …
📋 Job Overview
Planet Technologies, the Nation’s leading Microsoft services provider to the public sector, is looking for a highly motivated individual to join our growing team as Cloud Infrastructure Engineer. In this role, you will be supporting impactful projects that make a difference for our country.
🏢 About [Company]
Planet Technologies is the Nation’s leading Microsoft services provider to the public sector, supporting impactful projects that make a difference for our country.
🎯 The Role
The Senior Identity and Messaging Engineer is responsible for supporting, maintaining, securing, and enhancing enterprise identity and messaging services across on-premises and Microsoft cloud environments. This hands-on role administers and engineers Microsoft Active Directory, Microsoft Entra ID, Exchange Server, Exchange Online, and the hybrid services that connect them in a complex federal environment.
✅ Key Responsibilities
Design, implement, configure, and maintain multi-domain and multi-forest Microsoft Active Directory Domain Services infrastructure, including trusts, Flexible Single Master Operations roles, domain controller lifecycle management, schema changes, functional-level upgrades, and disaster recovery.
Manage Domain Controllers, Group Policy Objects (GPOs), DNS, DHCP, Sites and Services, and Active Directory replication.
Perform schema modifications, forest and domain functional level upgrades, and disaster recovery planning.
Harden Active Directory using tiered administration, Local Administrator Password Solution, privileged access workstations, Microsoft Defender for Identity, and findings from tools such as PingCastle and Purple Knight. Design, maintain, or support administrative forest and tiered administration architectures, and advise customers on transitioning from legacy ESAE or Red Forest models to Microsoft's Enterprise Access Model where appropriate.
Monitor and optimize AD performance, health, and security.
Administer and support Exchange Server 2016, Exchange Server 2019, Exchange Server Subscription Edition, and Exchange Online, including Database Availability Groups, transport services, certificates, cumulative updates, security updates, and high-availability configurations.
Build, maintain, and troubleshoot Exchange hybrid deployments using the Hybrid Configuration Wizard, organization relationships, free/busy services, mail flow connectors, and centralized mail transport. Plan and execute remote-move, cutover, and cross-tenant mailbox migrations with minimal disruption to users.
Manage Exchange Online Protection and Microsoft Defender for Office 365, including SPF, DKIM, DMARC, transport rules, anti-spam, anti-phishing, and email encryption controls. Support retention, eDiscovery, litigation hold, journaling, and Microsoft Purview compliance workloads.
Support email continuity, backup, recovery, and high-availability configurations.
Implement and support Microsoft Entra ID (Azure Active Directory).
Deploy, configure, maintain, and troubleshoot Microsoft Entra Connect and Entra Cloud Sync, including scoping and filtering, attribute flow, source anchor decisions, synchronization monitoring, and error remediation.
Configure and troubleshoot hybrid authentication using Password Hash Synchronization, Pass-through Authentication, and Active Directory Federation Services, and support migrations away from federation where appropriate. Implement Single Sign-On, Conditional Access, Multi-Factor Authentication, Privileged Identity Management, and phishing-resistant authentication using PIV/CAC and certificate-based authentication.
Participate in identity governance and role-based access control initiatives.
Collaborate with security teams to enforce Zero Trust architecture principles.
Work within segmented, multi-enclave federal networks to maintain Active Directory replication, authentication, directory synchronization, and mail flow across firewalls, VLANs, proxies, and security zones.
Identify and document required ports, protocols, Microsoft 365 endpoints, and GCC High or DoD-specific allow-list requirements.
Troubleshoot connectivity with Wireshark, netsh, pktmon, port testing, packet captures, and log analysis to isolate identity, application, and network failures.
Configure and troubleshoot split-brain and conditional DNS, forwarders, load balancers, VPN, SD-WAN, ExpressRoute, TIC 3.0 paths, DMZ services, and disconnected or cross-domain environments as applicable.
Ensure systems comply with DOE requirements, NIST Special Publication 800-53, FISMA, FedRAMP, DISA Security Technical Implementation Guides, and applicable CISA Secure Cloud Business Applications baselines. Support Authority to Operate activities, security control assessments, audit evidence requests, vulnerability remediation, and compliance reporting.
Perform vulnerability remediation, security hardening, and patch management.
Support audits, security assessments, and compliance reporting activities.
Implement security baselines and monitor for unauthorized changes or suspicious activity.
Assist with incident response and forensic investigations involving identity and messaging systems.
Develop and maintain PowerShell and Microsoft Graph
🛂 Visa & Eligibility
Must have existing Top Secret and/or DOE Q Clearance
Please let Planet Technologies know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.