1,053,222open jobs
61,880companies
171,336added this week
Browse all
Salary
≈ $101k – $197k per year (Estimated)
Location
In office (Denver)
Seniority
Senior · 7+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 1, 2026. First seen by Alion on Sep 29, 2026. Planet Technologies scores B on the Alion truth index.

Overview
Company
Impact
Profile match
Planet Technologies is a leading provider of Microsoft professional services aimed at optimizing government operations and solving business challenges using Microsoft tools and technology. Specializing in the public sector, Planet Technologies is recognized as a trusted advisor with 27 Microsoft Partner of the Year awards. They focus on utilizing existing Microsoft investments to drive efficiency and impact, particularly for government agencies and community colleges.

Planet Technologies, the Nation’s leading Microsoft services provider to the public sector, is looking for a highly motivated individual to join our growing team as Cloud Infrastructure Engineer. In this role, you will be supporting impactful projects that make a difference for our country.

The Senior Identity and Messaging Engineer is responsible for supporting, maintaining, securing, and enhancing enterprise identity and messaging services across on-premises and Microsoft cloud environments. This hands-on role administers and engineers Microsoft Active Directory, Microsoft Entra ID, Exchange Server, Exchange Online, and the hybrid services that connect them in a complex federal environment.

  • Must have existing Top Secret and/or DOE Q Clearance

Responsibilities

    Active Directory Administration & Engineering

  • Design, implement, configure, and maintain multi-domain and multi-forest Microsoft Active Directory Domain Services infrastructure, including trusts, Flexible Single Master Operations roles, domain controller lifecycle management, schema changes, functional-level upgrades, and disaster recovery.
  • Manage Domain Controllers, Group Policy Objects (GPOs), DNS, DHCP, Sites and Services, and Active Directory replication.
  • Perform schema modifications, forest and domain functional level upgrades, and disaster recovery planning.
  • Harden Active Directory using tiered administration, Local Administrator Password Solution, privileged access workstations, Microsoft Defender for Identity, and findings from tools such as PingCastle and Purple Knight. Design, maintain, or support administrative forest and tiered administration architectures, and advise customers on transitioning from legacy ESAE or Red Forest models to Microsoft's Enterprise Access Model where appropriate.
  • Monitor and optimize AD performance, health, and security.
  • Exchange Administration & Engineering

  • Administer and support Exchange Server 2016, Exchange Server 2019, Exchange Server Subscription Edition, and Exchange Online, including Database Availability Groups, transport services, certificates, cumulative updates, security updates, and high-availability configurations.
  • Manage mailbox provisioning, migrations, retention policies, archive solutions, and email routing.
  • Build, maintain, and troubleshoot Exchange hybrid deployments using the Hybrid Configuration Wizard, organization relationships, free/busy services, mail flow connectors, and centralized mail transport. Plan and execute remote-move, cutover, and cross-tenant mailbox migrations with minimal disruption to users.
  • Manage Exchange Online Protection and Microsoft Defender for Office 365, including SPF, DKIM, DMARC, transport rules, anti-spam, anti-phishing, and email encryption controls. Support retention, eDiscovery, litigation hold, journaling, and Microsoft Purview compliance workloads.
  • Support email continuity, backup, recovery, and high-availability configurations.
  • Identity & Access Management

    • Implement and support Microsoft Entra ID (Azure Active Directory).
    • Deploy, configure, maintain, and troubleshoot Microsoft Entra Connect and Entra Cloud Sync, including scoping and filtering, attribute flow, source anchor decisions, synchronization monitoring, and error remediation.
    • Configure and troubleshoot hybrid authentication using Password Hash Synchronization, Pass-through Authentication, and Active Directory Federation Services, and support migrations away from federation where appropriate. Implement Single Sign-On, Conditional Access, Multi-Factor Authentication, Privileged Identity Management, and phishing-resistant authentication using PIV/CAC and certificate-based authentication.
    • Participate in identity governance and role-based access control initiatives.
    • Collaborate with security teams to enforce Zero Trust architecture principles.
    • Network and Infrastructure

    • Work within segmented, multi-enclave federal networks to maintain Active Directory replication, authentication, directory synchronization, and mail flow across firewalls, VLANs, proxies, and security zones.
    • Identify and document required ports, protocols, Microsoft 365 endpoints, and GCC High or DoD-specific allow-list requirements.
    • Troubleshoot connectivity with Wireshark, netsh, pktmon, port testing, packet captures, and log analysis to isolate identity, application, and network failures.
    • Configure and troubleshoot split-brain and conditional DNS, forwarders, load balancers, VPN, SD-WAN, ExpressRoute, TIC 3.0 paths, DMZ services, and disconnected or cross-domain environments as applicable.
    • Cybersecurity & Compliance

    • Ensure systems comply with DOE requirements, NIST Special Publication 800-53, FISMA, FedRAMP, DISA Security Technical Implementation Guides, and applicable CISA Secure Cloud Business Applications baselines. Support Authority to Operate activities, security control assessments, audit evidence requests, vulnerability remediation, and compliance reporting.
    • Perform vulnerability remediation, security hardening, and patch management.
    • Support audits, security assessments, and compliance reporting activities.
    • Implement security baselines and monitor for unauthorized changes or suspicious activity.
    • Assist with incident response and forensic investigations involving identity and messaging systems.
    • Automation & Engineering

    • Develop and maintain PowerShell and Microsoft Graph automation for administration, reporting, monitoring, user lifecycle management, mailbox provisioning, group management, and repeatable operational tasks.
    • Automate user lifecycle management, mailbox provisioning, and group management processes.
    • Produce solution designs, operational runbooks, standard operating procedures, as-built documentation, port and protocol matrices, and technical diagrams that meet federal documentation and audit standards.
    • Support enterprise modernization initiatives involving Microsoft 365 and cloud migrations.
    • Operations Support

      • Provide Tier III escalation support for identity and messaging-related issues.
      • Participate in on-call support rotations as required.
      • Troubleshoot complex authentication, replication, Exchange, and directory synchronization issues.
      • Coordinate maintenance activities and planned outages.

Qualification

    • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or related field with 7 or more years of experience administering Active Directory in enterprise environments, including multi-domain or multi-forest architectures.
    • 5 or more years of experience administering Exchange Server, including hands-on responsibility for at least one Exchange hybrid deployment, and three or more years supporting Microsoft 365, Microsoft Entra ID, and Exchange Online.
    • Experience supporting enterprise environments with 5,000+ users preferred.
    • Senior-level experience supporting federal government customers onsite, with a demonstrated record of working effectively with government program managers, CIO staff, security officers, and contractors in professional, multi-vendor environments.
    • Demonstrated knowledge of TCP/IP, routing, subnetting, Network Address Translation, VLANs, firewalls, DNS, PKI and certificates, SMTP, Kerberos, and LDAP. Proven ability to diagnose network-related authentication, directory synchronization, and mail flow failures using packet capture, port testing, and log analysis in environments with strict change control.
    • PowerShell scripting and automation
    • Microsoft 365 Administration
    • Identity and Access Management (IAM)
    • Certificate Services (PKI)
    • Active Directory Federation Services (ADFS)
    • Windows Server Administration
    • Infrastructure: Windows Server (2003-2025), Active Directory / GPO, Hyper-V & VMware, DHCP / DNS / NPS

      Security & Compliance: DISA STIGs, Trellix EPO / HIPS, Vulnerability Scanners, (ACAS / Nessus)

      Systems Management: MECM / SCCM, Exchange Server (2003-2019), Microsoft Active Directory, Entra ID and Azure AD Connect, Domain Services (AD DS), Red Hat / Linux+, Orchestrator / PowerShell

      Preferred Qualifications

      • Experience implementing Exchange Hybrid environments.
      • Experience with Microsoft Defender, Microsoft Purview, and Microsoft Sentinel.
      • Experience with CyberArk, Beyond Trust, or other Privileged Access Management (PAM) solutions.
      • Experience supporting Zero Trust initiatives.
      • Familiarity with virtualization technologies such as VMware or Hyper-V.
      • Experience administering Microsoft 365 in GCC, GCC High, or DoD tenants, including government-specific endpoints, security controls, service limitations, and hybrid connectivity requirements.
      • Experience with PIV/CAC authentication, federal Identity, Credential, and Access Management requirements, administrative forest or ESAE/Red Forest architectures, one-way trusts, shadow principals, bastion forests, or Microsoft Identity Manager Privileged Access Management.
      • Familiarity with Active Directory consolidation, domain migrations, tenant-to-tenant migrations, Azure networking, TIC 3.0, Zero Trust network architecture, and cross-domain solutions.
      • Certifications (Preferred)

      • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
      • Microsoft 365 Certified: Administrator Expert (MS-102)
      • Microsoft 365 Certified: Messaging Administrator Associate (MS-203 legacy)
      • CompTIA Security+ or another DoD 8140-qualifying certification
      • CCNA, Network+, or equivalent networking certification
      • CISSP
      • GIAC Certifications
      • ITIL Foundation
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,053,222 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

DevOps
Similar stack
Same company
Denver
$103k – $193k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • Oak Brook
Python
PowerShell
Bash
DevOps
Terraform
New Relic
Datadog
Prometheus
GitOps
ArgoCD
AWS
Kubernetes
Grafana
Windows
Cybersecurity
ISO 27001
Active Directory
SIEM
Management
Agile
Scrum
Apply
$134k – $228k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Oak Brook
DevOps
Terraform
GCP
CloudFormation
Azure
CI/CD
AWS
Kubernetes
Bicep
FinOps
Windows
Cybersecurity
ISO 27001
Active Directory
Management
Agile
Scrum
Apply
Senior DevOps Engineer 7 months ago
$155k – $185k per year • In office • Full-Time • 5+ years exp • Chatsworth
Python
JavaScript
DevOps
Terraform
Azure DevOps
GitHub Actions
Consul
Datadog
Prometheus
Azure
CI/CD
Docker
Kubernetes
Grafana
Linux
Cryptography
Vault
Apply
$127k – $170k per year • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • San Francisco
Apply
$70k – $116k per year • In office • Public Trust • Full-Time • 4+ years exp • Bachelor's Degree • San Antonio • Houston • Charlotte • Huntsville • Atlanta
AI/ML
Claude
Claude Code
Model Context Protocol
Embeddings
Function Calling
AI Agents
LLM
RAG
Anthropic
Human-in-the-Loop
Structured Outputs
Agentic Workflows
Tool Use
DevOps
GCP
Azure
AWS
Apply
In office • Full-Time • 3+ years exp • Bengaluru
Python
Go
Databases
Amazon Aurora
DevOps
Rest API
Ansible
GitHub Actions
VMWare
CloudFormation
Debian
Azure
CI/CD
Jenkins
AWS
Docker
AWS Fargate
Amazon EC2
Hyper-V
eBPF
Amazon S3
IAM
Amazon ECS
Amazon CloudWatch
Linux
DHCP
Cybersecurity
Nmap
Suricata
QA
Pytest
Apply
Engineer 2 11 hours ago
$88k – $130k per year • Hybrid • 5+ years exp • Bachelor's Degree • Dallas
Python
SQL
PowerShell
C#
C#
.NET
Databases
MS SQL
Apache Kafka
AI/ML
PyTorch
Ignite
DevOps
Rest API
Azure
CI/CD
Git
Incident Management
Management
Agile
Scrum
Kanban
Apply
DevOps Engineer (KORM) 11 hours ago
≈ $16k – $40k per year (Estimated) • Hybrid • Moscow
Python
PowerShell
Bash
DevOps
Helm
Azure DevOps
Prometheus
VictoriaMetrics
Yandex Cloud
Azure
CI/CD
Kubernetes
Linux
Windows
Cybersecurity
Kaspersky
Apply
Quality Engineer 11 hours ago
≈ $18k – $36k per year (Estimated) • In office • Full-Time • 3+ years exp • Bengaluru
Python
Databases
Amazon Aurora
AI/ML
Copilot
Claude
Model Context Protocol
DevOps
GCP
Azure
CI/CD
AWS
Management
Agile
QA
JMeter
Playwright
Gatling
k6
Locust
Apply
Senior Developer 11 hours ago
≈ $20k – $44k per year (Estimated) • In office • Full-Time • 5+ years exp • Bengaluru
Python
Go
Rust
SQL
Databases
PostgreSQL
Amazon Aurora
DevOps
Ansible
Azure
AWS
Docker
Kubernetes
SaltStack
Configuration Management
Cybersecurity
Metasploit
Nmap
Nessus
Prisma Cloud
Qualys Cloud Platform
OpenVAS
MITRE ATT&CK
CIS Benchmarks
OWASP Top 10
Apply
≈ $84k – $170k per year (Estimated) • Hybrid • Public Trust • Full-Time • 3+ years exp • Bachelor's Degree
DevOps
Azure DevOps
Azure
Windows
Cybersecurity
Microsoft Defender
CIS Benchmarks
FedRAMP
Least Privilege
Microsoft Defender for Cloud
Active Directory
Management
Scrum
Apply
≈ $102k – $227k per year (Estimated) • Remote (United States) • Full-Time
DevOps
Red Hat
VMWare
Azure
CI/CD
AWS
Kubernetes
Ubuntu
Azure AKS
IAM
Linux
Apply
Cloud Engineer 5 months ago
≈ $104k – $203k per year (Estimated) • Hybrid • Top Secret • Full-Time • 5+ years exp • Bachelor's Degree • Huntsville
Python
Java
DevOps
Terraform
Ansible
GCP
CloudFormation
Azure
CI/CD
Jenkins
AWS
Docker
Kubernetes
Configuration Management
GitLab
IAM
Cybersecurity
ISO 27001
NIST 800-53
FedRAMP
Zero Trust
Apply
≈ $96k – $189k per year (Estimated) • In office • Top Secret • Full-Time • 5+ years exp • Bachelor's Degree • Albuquerque
SQL
PowerShell
Databases
MS SQL
DevOps
VMWare
Azure
Windows Server
Hyper-V
Windows
DNS
DHCP
Cybersecurity
Active Directory
Management
ITIL
Apply
Data Scientist 22 days ago
≈ $111k – $219k per year (Estimated) • In office • Top Secret • Full-Time • 5+ years exp • Washington
Python
SQL
MATLAB
SPSS
AI/ML
NumPy
Machine Learning
Analytics
Power BI
ETL/ELT
Management
SharePoint
Apply
$154k – $208k per year • Equity • In office • Full-Time • 7+ years exp • Bachelor's Degree • Denver
DevOps
AWS
Management
Agile
Apply
$97k – $161k per year • Remote (United States) • Full-Time • 5+ years exp • Bachelor's Degree • Chattanooga • Scottsdale • Denver • Saint Louis
Python
SQL
SAS
Analytics
Tableau
Apply
$80k – $132k per year • In office • Full-Time • Denver
Apply
≈ $40k – $79k per year (Estimated) • In office • Full-Time • 3+ years exp • High School Diploma • Denver
Apply
$115k – $135k per year • Equity • Remote (United States) • Full-Time • 10+ years exp • Denver
Mobile
Braze
Marketing
Iterable
Apply
See all jobs
This is one of many
1,053,222 more open roles from verified company boards, updated every day.