DevOps Engineer (IDP/Keycloak SME)

Tetra Tech

United States

Remote

USD 130,000 - 150,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

LS Technologies, a Tetra Tech Company, seeks a System Engineer SME for Identity Provider (IDP) and IAM with Keycloak and Login.gov integrations.

You will design, deploy, secure, automate, and maintain identity services across cloud-hosted apps, and support federation with LDAP/AD, OpenShift/Kubernetes, and CI/CD pipelines.

Requirements include 6–10 years in tech support or DevOps, Linux/Unix and Windows administration, and hands-on Keycloak, OAuth 2.0, OIDC, SAML, JWT, and RBAC experience.

Qualifications

  • 6-10 years of experience in technology support, DevOps, or system administration roles.
  • Proficiency in Linux/Unix and Windows server administration.
  • Hands-on experience administering, engineering, and troubleshooting Keycloak or comparable enterprise IdP/IAM platforms.
  • Strong understanding of OAuth 2.0, OIDC, SAML, JWT, authentication, authorization, and identity federation.
  • Experience integrating identity services with enterprise applications and APIs.
  • Experience troubleshooting complex authentication and application integration issues.
  • Understanding of cybersecurity principles, secure configuration, vulnerability remediation, and access control.
  • Hands-on experience integrating applications with Login.gov.

Responsibilities

  • Serve as a technical SME for Keycloak, IdP, IAM, and Login.gov solutions across FAA cloud applications.
  • Design, deploy, configure, upgrade, and maintain Keycloak environments in multiple stages.
  • Configure and manage Keycloak realms, clients, roles, groups, users, service accounts, identity providers, authentication flows, and policies.
  • Implement and support OAuth 2.0, OIDC, SAML 2.0, and JWT-based authentication.
  • Design secure integrations between FAA apps and Login.gov for authentication and identity verification.
  • Support applications integrating with Login.gov using OpenID Connect/OAuth 2.0 patterns.
  • Configure and troubleshoot Login.gov identity provider integrations, including client registration and redirects.
  • Support federation between Login.gov, Keycloak, and FAA applications as needed.
  • Troubleshoot authentication issues involving Login.gov, Keycloak, tokens, and federation.
  • Apply Login.gov integration/security requirements to onboarding and deployment activities.
  • Support testing and validation of Login.gov integrations across environments.
  • Coordinate with application teams to resolve Login.gov integration issues and ensure proper authentication flows.
  • Implement and support SSO across cloud applications and services.
  • Support federation with LDAP/AD and other identity sources.
  • Configure/manage identity federation, identity brokering, token exchange, and policy mappings.
  • Develop secure authentication/authorization patterns for FAA cloud environments.
  • Implement RBAC and least-privilege access patterns.
  • Develop automated Keycloak provisioning/configuration/deployment/lifecycle processes.
  • Use Terraform and IaC to automate cloud infra and identity configurations.
  • Integrate Keycloak deployments into CI/CD and DevSecOps workflows.
  • Support containerized deployments using Red Hat OpenShift/Kubernetes.

Skills

Keycloak
Identity Provider (IdP)
IAM
OAuth 2.0
OIDC
SAML 2.0
JWT
Login.gov
Linux/Unix
Windows Server

Education

Bachelor’s degree in Information Technology/Computer Science/Engineering

Tools

Terraform
OpenShift
Kubernetes
CI/CD

Job description

Job Description

The Federal Aviation Administration (FAA) is seeking a highly skilled System Engineer to serve as an Identity Provider (IDP) Subject Matter Expert (SME) by providing advanced engineering, implementation, integration, and operational support for enterprise identity and access management (IAM) services. The engineer will serve as a subject matter expert for Keycloak, IDP technologies, and Login.gov integrations, helping design, deploy, secure, automate, and maintain identity services supporting cloud-hosted applications and platforms.


Salary is based on relative years of experience:

$130,000 - $150,000


Job Duties & Responsibilities

Essential Job Functions may include (but are not limited to) the following:
The following duties are considered essential to the role. Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions



  • Serve as a technical SME for Keycloak, Identity Provider (IdP), IAM, and Login.gov solutions supporting FAA cloud applications and services.

  • Design, deploy, configure, upgrade, and maintain Keycloak environments across development, test, staging, and production environments.

  • Configure and manage Keycloak realms, clients, roles, groups, users, service accounts, identity providers, authentication flows, and authorization policies.

  • Implement and support OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, and JWT-based authentication.

  • Design and implement secure integrations between FAA applications and Login.gov for authentication and identity verification use cases.

  • Support applications integrating with Login.gov using OpenID Connect/OAuth 2.0 patterns.

  • Configure and troubleshoot Login.gov identity provider integrations, including client registration, redirect/return URLs, scopes, claims, authentication flows, and token handling.

  • Support integration between Login.gov, Keycloak, and FAA applications where federated identity or identity brokering is required.

  • Troubleshoot authentication issues involving Login.gov, Keycloak, application clients, tokens, claims, certificates, redirects, and federation.

  • Apply Login.gov integration and security requirements to application onboarding and deployment activities.

  • Support testing and validation of Login.gov integrations across development, test, staging, and production environments.

  • Coordinate with application teams and identity/security stakeholders to resolve Login.gov integration issues and ensure proper authentication flows.

  • Implement and support Single Sign-On (SSO) capabilities across cloud applications and enterprise services.

  • Support federation with enterprise directories and identity services, including LDAP/Active Directory and other authoritative identity sources.

  • Configure and manage identity federation, identity brokering, token exchange, identity mapping, claims, scopes, and protocol mappers.

  • Develop and maintain secure authentication and authorization patterns for applications operating within FAA cloud environments.

  • Implement role-based access control (RBAC) and least privilege access patterns.

  • Develop automated processes for Keycloak provisioning, configuration, deployment, and lifecycle management.

  • Use Terraform and Infrastructure as Code (IaC) to automate cloud infrastructure and identity platform configurations.

  • Integrate Keycloak and identity-related deployments into CI/CD pipelines and DevSecOps workflows.

  • Support containerized Keycloak deployments using Red Hat OpenShift/Kubernetes and cloud-native technologies.

  • Configure Keycloak for high availability, scalability, resilience, backup/recovery, and disaster recovery requirements.

  • Monitor identity platform performance, authentication activity, availability, logs, and system health.

  • Support certificate and key management associated with TLS, signing certificates, encryption, SAML, OIDC, SSL, and JWT-based integrations.

  • Implement security hardening for Keycloak and supporting identity infrastructure in accordance with FAA cybersecurity requirements and applicable federal security standards.

  • Support vulnerability remediation, patching, configuration management, and security assessments of identity services.

  • Integrate identity services with cloud security, logging, monitoring, and SIEM platforms.

  • Support cybersecurity teams with audit evidence, security assessments, compliance documentation, and remediation activities.

  • Participate in incident response and root-cause analysis for identity and authentication-related incidents.

  • Support change management activities, including technical analysis, implementation planning, testing, deployment, and validation.

  • Develop and maintain architecture documentation, configuration standards, deployment procedures, and troubleshooting guides.


Provide technical mentorship and guidance to junior engineers on IAM, Keycloak, Login.gov, authentication, authorization, and DevSecOps practices.


Required Qualifications

A successful candidate will have



  • 6-10 years of experience in technology support, DevOps, or system administration roles.

  • Proficiency in Linux/Unix and Windows server administration.

  • Hands-on experience administering, engineering, and troubleshooting Keycloak or comparable enterprise IdP/IAM platforms.

  • Strong understanding of OAuth 2.0, OIDC, SAML, JWT, authentication, authorization, and identity federation.

  • Experience integrating identity services with enterprise applications and APIs.

  • Experience troubleshooting complex authentication and application integration issues.

  • Understanding of cybersecurity principles, secure configuration, vulnerability remediation, and access control.


Hands-on experience integrating applications with Login.gov.


Education


  • Bachelor’s degree in Information Technology, Computer Science, Engineering, or related field (or equivalent experience).


Work Requirements and Additional Information


  • Work Location: Remote

  • Position is: Remote

  • Work Hours: 40

  • Travel: 0%

  • Background check: Must have the ability to obtain and maintain a public trust clearance, which requires U.S. citizenship.


Physical Requirements

Extended Computer Use: Regular and prolonged periods of working at a computer terminal.



  • Mobility: Ability to move around the office environment to access computer hardware, networking equipment, and server rooms.

  • Dexterity: Manual dexterity and visual acuity to operate computer equipment, troubleshoot issues, and perform tasks requiring precision.

  • Sitting/Standing: Both prolonged sitting and occasional standing may be required for troubleshooting and attending to system issues.


Primarily computer-based work; meetings or collaboration may be required.


About LS Technologies

At LS Technologies, a Tetra Tech Company, we're enhancing our nation’s critical infrastructure by providing engineering, technical, and professional services to Federal Government agencies. The quality of our work, deep technical expertise, and genuine passion for public service sets us apart. As a growing organization we are expanding our benefits and communication with our employees, offering add-ons that speak to our growing employees’ needs. Join us in delivering high-quality solutions and shaping the future of safety and innovation for our government partners. In 2024 we joined Tetra Tech, enabling us to combine our expertise with the reach and resources of a prestigious global organization.


EEO Commitment

LS Technologies, a Tetra Tech Company, is proud to be an Equal Opportunity Employer. All qualified candidates will be considered without regard to race, color, religion, national origin, age, disability, sex, marital or familial status, status as a protected veteran, or any other characteristic protected by law. Tetra Tech is a VEVRAA federal contractor, and we request priority referral of veterans. We invite applications from all interested parties.


Requesting an Accommodation

LS Technologies is committed to providing equal employment opportunities for persons with disabilities or religious observances, including reasonable accommodation when needed. If you are hired by LS Technologies and require accommodation to perform the essential functions of your role, you will be asked to participate in our reasonable accommodation process. Accommodations made to facilitate the recruiting process are not a guarantee of future or continued accommodations once hired. If you would like to be considered for employment opportunities with LS Technologies and have accommodation needs for a disability or religious observance, please send us an email hr@lstechllc.com or speak with your recruiter.


Compensation (Pay Bands)

Salary at LST is determined by a wide array of factors, such as (but not limited to) education, certifications, knowledge, skills, competencies, and experience, location, and clearance level, as well as contract-specific affordability and organizational requirements and applicable employment laws. Please note that the salary information is a general guideline only. The projected compensation range for this position is provided within the posting and is based on full-time, 40 hour/week status. Part-time staff receive compensation at an hourly rate. The estimated minimum and maximum displayed represents the broadest range for this position (inclusive of high geographic and high clearance requirements) and is just one component of LSTs total compensation package for employees. ** In compliance with local laws, LS Technologies presents this reasonable compensation range as a guideline for roles in California, Colorado, New York, or Washington D.C.


Benefits offered to all employees who work 30+ hours per week: Medical, Dental, Vision, Life Insurance, Short-Term Disability, Long-Term Disability, 401(k) match, Flexible Spending Accounts, EAP, Education Assistance, Parental Leave, Annual Leave, and Holidays.



  • The perks of working at Tetra Tech include:

  • Comprehensive and market-competitive benefits.

  • Merit-based financial rewards.

  • Flexibility and company-wide commitment to work/life balance.

  • Collaborative team atmosphere that values the contributions of all employees.

  • Learning and development opportunities for ongoing professional growth.


About Tetra Tech:

Tetra Tech is the leader in water, environment, and sustainable infrastructure, providing high-end consulting and engineering services for projects worldwide. With 30,000 employees working together, Tetra Tech provides clear solutions to complex problems by Leading with Science® to address the entire water cycle, protect and restore the environment, design sustainable and resilient infrastructure, and support the clean energy transition.


Explore our open positions at https://www.tetratech.com/careers. Follow us on social media to learn more about our people, culture, and opportunities:LinkedIn: TetraTechCareers; X (Twitter): @TetraTechJobs

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Full Stack Developer - Federal Aviation Administration
Full Stack Developer - Federal Aviation Administration

Tetra Tech • Atlantic City (NJ)

On-site
USD 100,000 - 110,000
Competitive benefits
Merit-based rewards
Work-life balance
+2
Junior Data Scientist
Junior Data Scientist

230 LST • Warrenton (VA)

Hybrid
USD 60,000 - 70,000
Medical Insurance
Dental Insurance
Vision Insurance
+4
FAA Systems Engineers
FAA Systems Engineers

230 LST • Atlantic City (NJ)

On-site
USD 100,000 - 120,000
Senior Cloud & Virtualization Engineer
Senior Cloud & Virtualization Engineer

230 LST • Washington

On-site
USD 140,000 - 190,000
Medical
Dental
Vision
+3
Electrical Engineer (Communication Systems)
Electrical Engineer (Communication Systems)

230 LST • Atlantic City (NJ)

On-site
USD 90,000 - 120,000
Medical benefits
Dental benefits
Vision benefits
+2
Junior Data Scientist
Junior Data Scientist

Tetra Tech • Warrenton (VA)

On-site
USD 60,000 - 70,000
Benefits package
Merit-based rewards
Work/life balance
+2
Cloud Security Tech Support
Cloud Security Tech Support

Tetra Tech • Washington

On-site
USD 80,000 - 120,000
Comprehensive benefits
Merit-based financial rewards
Learning and development opportunities
+1
Cloud Security Engineer
Cloud Security Engineer

Tetra Tech • Town of Egg Harbor (WI)

On-site
USD 140,000 - 190,000
Voice Engineer
Voice Engineer

Tetra Tech • Atlantic City (NJ)

On-site
USD 120,000 - 180,000
Market-competitive benefits
Merit-based rewards
Work-life balance
+2
Electronics Technician (PR)
Electronics Technician (PR)

Tetra Tech • Puerto Rico

Remote
USD 65,000 - 85,000