ICAM Architect

SAIC

Springfield (VA)

On-site

USD 120,001 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SAIC seeks a skilled ICAM Architect to design, implement, and optimize identity, credential, and access management solutions for a mission-critical enterprise IT environment in Springfield, VA. You will lead ICAM efforts across on-premises, hybrid, and cloud environments, enforcing Zero Trust and FICAM standards while aligning with MAJESTIC JPO priorities.

The role requires 10–15 years of enterprise IT experience, deep expertise in SAML, OAuth, OpenID Connect, LDAP, PKI, SSO/MFA, and scripting.

Qualifications

  • 10–15 years of enterprise IT experience.
  • ICAM architecture experience with Zero Trust and FICAM.
  • Experience integrating on-premises, hybrid, and cloud identity solutions.

Responsibilities

  • Design ICAM architectures aligned with mission needs and Zero Trust.
  • Develop identity lifecycle workflows (provisioning/deprovisioning/credentialing).
  • Integrate on-premises, hybrid and cloud identity solutions (SAML/OAuth/OpenID).
  • Deploy and manage SSO, MFA, PAM.
  • Design RBAC/ABAC models and automate workflows (Ansible/Terraform/PowerShell).
  • Monitor identity systems using SIEM tools (Splunk).
  • Provide technical briefings and maintain documentation.

Skills

SAML/OAuth/OIDC
RBAC/ABAC
PKI/Credentialing
SSO/MFA
PowerShell-Bash-Terraform
Identity analytics/SIEM

Education

High School Diploma/GED
Bachelor's Degree in Cybersecurity/CS

Tools

Active Directory/Azure AD
LDAP
Okta/DIDO/Ping Identity

Job description

Minimum Clearance Required TS.SCI

Job ID 2614889

Location Springfield, VA, US

Date Posted 2026-07-23

Category Information Technology

Subcategory Network Engineer

Schedule Full-Time

Shift Day Job

Travel Yes - 10% of the time

Minimum Clearance Required TS.SCI

Clearance Level Must Be Able to Obtain TS/SCI with Poly

Potential for Remote Work ORA_ON_SITE

Description

SAIC is seeking a highly skilled and motivated ICAM Architect to design, implement, and optimize advanced Identity, Credential, and Access Management (ICAM) solutions for a mission-critical enterprise IT environment. This position will support our MAJESTIC Joint Program Office (JPO) Team and requires an experienced professional with in-depth knowledge of ICAM architecture and compliance with federal identity and access management standards, such as FICAM and Zero Trust Architecture principles. As the ICAM Architect, you will lead efforts to develop secure, scalable, and interoperable identity systems. The role requires expertise in integrating identity and access control solutions across on-premises, hybrid, and cloud environments. The ICAM Architect will collaborate with cross-functional teams to enforce proper access controls, enhance system security, and align with mission priorities, ensuring only properly credentialed individuals have access to critical resources. All work must be performed on-site in Springfield, VA.

Key Responsibilities
  • Design and implement ICAM architectures that align with mission needs, Zero Trust principles, and compliance with FICAM.
  • Develop workflows for identity lifecycle management, including provisioning, deprovisioning, and secure credentialing (e.g., PKI, PIV, CAC).
  • Integrate on-premises, hybrid, and cloud identity solutions, leveraging technologies like SAML, OAuth, OpenID Connect, and LDAP.
  • Deploy and manage SSO, MFA, and Privileged Access Management (PAM) solutions to enhance authentication and access security.
  • Optimize secure access to applications and resources by designing RBAC/ABAC models and automating workflows with tools like Ansible, Terraform, or PowerShell.
  • Monitor identity systems using tools like Splunk or other SIEM platforms to detect and respond to threats and anomalies.
  • Collaborate with cross-functional teams to ensure seamless integration of ICAM systems into broader IT environments.
  • Provide technical briefings, metrics, and status updates for leadership while maintaining comprehensive technical documentation.
Qualifications
Education
  • High School Diploma/GED
Certifications (CWF Requirements)
  • Candidates must satisfy Cybersecurity Workforce Framework (CWF)ID 443 (Network Analyst – Intermediate Level)requirements, as outlined byNavy COOL.

This requirement can be met by possessing one or more of the following qualifying certifications

  • CompTIA Cloud+
  • CompTIA Security+
  • GIAC Global Industrial Cyber Security Professional (GICSP)
  • GIAC Security Essentials Certification (GSEC)
  • Systems Security Certified Practitioner (SSCP)

OR This requirement can be met through

  • ABachelor’s Degreein Cybersecurity, Computer Science, IT, or a related field.
Experience
  • 10-15 years of professional experience managing and supporting enterprise-levelIT environments.
Technical Skills
  • Deep expertise in identity federation, authentication, and authorization protocols (e.g., SAML, OAuth, OpenID Connect, Kerberos).
  • Hands-on experience with Active Directory, Azure Active Directory, LDAP, and PKI-based systems.
  • Proficient in designing and implementing Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) models for secure enterprise systems.
  • Skilled in deploying and managing Single Sign-On (SSO) and Multi-Factor Authentication (MFA) using tools like Okta, Duo, or Ping Identity.
  • Experienced with monitoring and detecting anomalies using identity analytics tools and SIEM platforms like Splunk.
  • Strong background in scripting and workflow automation using tools such as PowerShell, Bash, or Terraform to enhance ICAM processes.
Preferred Certifications (In Addition To CWF Requirements)
  • Certified Information Systems Security Professional (CISSP) or equivalent.
  • Microsoft Certified Security, Compliance, and Identity Fundamentals.
  • Vendor-specific certifications for identity tools such as ForgeRock, Okta, Ping Identity, or SailPoint.
  • Experience establishing ICAM within a Zero Trust Architecture (ZTA) framework.
Clearance Requirement
  • ActiveTS/SCI clearance with the ability to obtain and maintain aTS/SCI with Poly.
Work Environment and Notes
  • On-Site WorkAll work must be conductedon-sitein Springfield, VA.
  • Program ScopeSupports on-premises enterprise IT environments, including virtualized Windows servers, MS SQL Server databases, and networking layers.
  • Subcontractor RoleResponsibilities and compensation vary based on the subcontract agreement, with a competitive salary aligned to market rates and role-specific requirements.

Target salary range $120,001 - $160,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ICAM Architect – Zero Trust & PKI Expert (TS/SCI)
ICAM Architect – Zero Trust & PKI Expert (TS/SCI)

SAIC • Springfield (VA)

On-site
USD 120,000 - 160,000
Senior ICAM Solutions Architect
Senior ICAM Solutions Architect

Peraton • Reston (VA)

On-site
USD 135,000 - 216,000
Senior ICAM Engineer
Senior ICAM Engineer

Leidos • United States

On-site
USD 131,000 - 238,000
ICAM Architect (Top Secret/SCI with agreement to obtain CI Poly Clearance Required)
ICAM Architect (Top Secret/SCI with agreement to obtain CI Poly Clearance Required)

North Point Technology • Herndon (VA)

On-site
USD 150,000 - 190,000
ICAM Architect (Top Secret/SCI with agreement to obtain CI Poly with Security Clearance
ICAM Architect (Top Secret/SCI with agreement to obtain CI Poly with Security Clearance

North Point Technology • Reston (VA)

On-site
USD 150,000 - 210,000
Identity & Access Management Support Engineer (ICAM) Hanover, MD, US
Identity & Access Management Support Engineer (ICAM) Hanover, MD, US

CACI International Inc. • Northern (KY)

Hybrid
USD 113,000 - 238,000
Identity & Access Management (ICAM) Architect (TS/SCI Clearance Required)
Identity & Access Management (ICAM) Architect (TS/SCI Clearance Required)

North Point Technology • Chantilly (VA)

On-site
USD 140,000 - 190,000
Senior ICAM Identity Governance and Provisioning Engineer
Senior ICAM Identity Governance and Provisioning Engineer

Leidos • United States

On-site
USD 131,000 - 238,000
Identity, Credential, and Access Management (ICAM) Analyst
Identity, Credential, and Access Management (ICAM) Analyst

Jobless • Arlington (TX), Northern (KY)

Hybrid
USD 170,000 - 250,000
Identity & Access Management (ICAM) Engineer (TS/SCI Clearance Required)
Identity & Access Management (ICAM) Engineer (TS/SCI Clearance Required)

North Point Technology • Chantilly (VA)

On-site
USD 120,000 - 160,000