I found the following code on the internets that appears to do what I want it to, namely grant read and execute access on a folder and all subfolders and files to various AD groups.
Project path is the top-level folder for the groups in the $Domains\$
Project path is the top-level folder for the groups in the $Domains\$