ICAM Engineer

ECS Corporate Services

Fort Meade (MD)

On-site

USD 170,000 - 190,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Everforth ECS seeks an ICAM Engineer to support IL5/IL6 programs in DoD environments at Ft. Meade, MD. This onsite role requires advanced ICAM expertise, including PingFederate, Ping Directory, SAML/OIDC, LDAP, and PKI, with a strong emphasis on security policy alignment.

Responsibilities include serving as ICAM SME for Azure-based DoD environments, implementing and managing enterprise IAM systems, planning automation, and producing technical documentation and executive summaries.

Qualifications

  • 10+ years of ICAM architecture experience.
  • Experience in DoD IL5/IL6 environments.
  • Active Secret clearance or higher.
  • Onsite work in Ft. Meade, MD 5 days/week.
  • Strong communication and stakeholder skills.
  • Experience with PKI, LDAP, SAML/OIDC.
  • Ability to document architectures and guidance.

Responsibilities

  • Serve as ICAM SME for Azure-based DoD environments.
  • Implement, maintain, and optimize enterprise systems.
  • Monitor and manage installed systems, directory services.
  • Configure, test, and maintain OS, apps, and tools.
  • Guide IT support teams on ICAM-related tasks.
  • Lead integration of customized software/hardware solutions.
  • Plan automation to improve operations.
  • Design secure controls and ensure high availability.
  • Maintain inventories and provide rapid issue response.
  • Develop and enhance Enterprise Directory and LDAP schemas.
  • Create directory integration solutions across systems.
  • Configure IAM systems with RBAC, workflows, reviews.
  • Review ICAM integration requirements per policy.
  • Collaborate with business and technical stakeholders.
  • Produce technical standards and design guidance.
  • Prepare briefs on ICAM architecture and policy.
  • Support security assessments and ATO activities.
  • Other duties as assigned.

Skills

ICAM
Azure
PingFederate
Ping Directory
SAML/OIDC
LDAP
PowerShell
PKI
DoD
Security

Education

Bachelor's degree

Tools

Azure AD
Entra ID
Okta
SailPointIIQ

Job description

Everforth ECS is seeking an Identity Credential and Access Management (ICAM) Engineer to work in our Ft. Meade, MD office in an onsite capacity. Everforth ECS is seeking an ICAM Engineer to support robust Impact Level (IL) 5 and IL6 programs in an operational DoW environment that houses multiple U.S. Coalition Mission Partner Environments (MPE). The ICAM Engineer will serve as the Ping Identity SME displaying expertise with PingFederate and Ping Directory. You will help clients understand emerging technical solutions relative to client policies and operational requirements and apply analytical and innovative strategies to develop solutions to address client needs. The candidate will contribute to technical artifacts and thought leadership for IAM tools relating to Credential Management, Public Key Infrastructure, Alternate Credentials, Directory Services, Authentication solutions, and ICAM integrations. This position is a demanding, high-energy role that requires innovative ideas to manage identities, credentials, and access across Mission Partner Environments (MPE). The ideal candidate has advanced technical acumen; essential soft skills, including analytical thinking, problem-solving, communication, and proven leadership abilities; and intellectual curiosity critical for analyzing ICAM needs and developing solutions to address them. The ICAM SME/Engineer reports to the Senior Cyber Security Engineer and collaborates closely with the Engineering team.

Responsibilities
  • Serve as the ICAM SME for Azure based DOD environments.
  • Implement, maintain, and optimize enterprise systems in alignment with organizational standards and SOPs.
  • Monitor and manage all installed systems, infrastructure, and directory services.
  • Configure, test, and maintain operating systems, application software, and system management tools.
  • Evaluate existing systems and provide technical guidance to IT support teams.
  • Lead the development and integration of customized software and hardware solutions.
  • Plan and implement automation to improve operational efficiency.
  • Design and maintain security controls to ensure data integrity and system protection.
  • Ensure high availability of technical resources and maintain accurate system inventories.
  • Provide timely reporting and rapid response to system issues or outages.
  • Support the development and enhancement of the client's Enterprise Directory, including LDAP schema design, object classes, attributes, queries, and group structures.
  • Develop directory integration solutions across directory and database systems.
  • Configure and support enterprise Identity Management systems, including role based access, segregation of duties, workflow automation, and periodic access reviews.
  • Review and implement ICAM integration requirements with adherence to an organization's mission, goals, and standards.
  • Experience working in client services environments and engaging with both business and technical stakeholders.
  • Prepare technical standards, provide technical advice and guidance, and collaborate with other programmers to conceptualize and develop design.
  • Demonstrated ability to write technical documentation, including product analysis, as-is/to-be architectures, and network and infrastructure diagrams.
  • Demonstrated experience in migration of ICAM technologies, including transitioning legacy applications to innovative and best of breed solutions.
  • Experience developing and briefing materials and executive summaries on ICAM architecture, implementation, and policy.
  • Support security assessments, audits, and ATO activities, including documentation and control evidence related to ICAM.
  • Other duties, as assigned.

Salay Range: 170,000-190,000

General Description of Benefits

U.S. Citizen. Active Secret security clearance. Bachelor's degree in Cybersecurity, Information Security, Computer Science, or related STEM (Science, Technology, Engineering and Mathematics) discipline. 10+ years of technical experience developing ICAM architectures and strategies with a wide array of products (e.g., Intercede MyID, SailPointIIQ, Okta, CyberArk, PKI). Minimum DoD 8140 IAT Level II certification (e.g., CompTIA Security+, CySA+, GSEC, SSCP). Ability to work 5 days/week onsite at 6910 Cooper Ave, Ft. Meade, MD. Experience with the following: Configuring and troubleshooting SAML/OIDC federation, OAuth/SCIM provisioning, LDAP integrations, attribute mappings, and partner identity connections. Supporting multi-partner ICAM integrations, SSO, directory synchronization, access policies, and end-to-end identity flow troubleshooting across secure enterprise environments Strong PowerShell scripting experience. Knowledge of: ADFS, Azure App Proxy, WPAD, and MFA technologies, especially Certificate Based Authentication (CBA). Deep knowledge of Active Directory, including: Domain controller maintenance and upgrades GPO management DNS and core AD infrastructure Experience with Entra ID (Azure AD), including: Application registrations and SSO onboarding Intune policy management DNS and core AD infrastructure Understanding of PKI technologies (LDAP directories, HSMs, OCSP) and security best practices. Experience working within large federal IT infrastructures. Recent experience with deployment of identity and credential management solutions; knowledge of federal cybersecurity and zero trust policies, requirements and standards. Strong understanding stakeholder requirements and expectations, system architecture, infrastructure build and documentation, configuration and deployment, as well as existing and emerging federal policy including HSPD-12 and NIST documents. Exceptional analytical, problem-solving, and communication skills. Strong decision-making ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution. Proven ability to remain calm, decisive, and methodical under pressure. Advanced proficiency with Microsoft Office tools and O365, including Word, Excel, PowerPoint, Teams, Outlook, and SharePoint. Experience designing, implementing, and supporting ICAM solutions in Microsoft Azure cloud environments.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Identity, Credential, and Access Management (ICAM) Security Engineer
Senior Identity, Credential, and Access Management (ICAM) Security Engineer

Ampcus, Inc • Washington

On-site
USD 100,000 - 130,000
Senior ICAM Engineer
Senior ICAM Engineer

Easy Dynamics Corp. • United States

On-site
USD 160,000 - 200,000
Senior ICAM Engineer
Senior ICAM Engineer

Leidos • United States

On-site
USD 131,300 - 237,350
Senior ICAM Engineer, Remote, United States
Senior ICAM Engineer, Remote, United States

Technologist, Inc. • Northern (KY)

Remote
USD 120,000 - 160,000
Health Care Plan
401k with employer match
Paid Time Off
+2
ICAM Engineer: Azure & Ping Identity (Onsite Ft. Meade)
ICAM Engineer: Azure & Ping Identity (Onsite Ft. Meade)

ECS Corporate Services • Fort Meade (MD)

On-site
USD 170,000 - 190,000
Lead Specialist, Federal ICAM (Identity, Credential, and Access Management) Engineer
Lead Specialist, Federal ICAM (Identity, Credential, and Access Management) Engineer

KPMG LLP • McLean (VA)

On-site
USD 140,000 - 180,000
Azure Cloud Engineer – ICAM
Azure Cloud Engineer – ICAM

EdgeByte Solutions, LLC • Northern (KY)

On-site
USD 75,000 - 150,000
Specialist Director, Federal Identity (ICAM) Architect
Specialist Director, Federal Identity (ICAM) Architect

KPMG LLP • McLean (VA)

On-site
USD 140,000 - 210,000
Sr ICAM Engineer
Sr ICAM Engineer

Easy Dynamics Corp • McLean (VA)

On-site
USD 144,000 - 176,000
ICAM Engineer – Identity, Credential, and Access Management
ICAM Engineer – Identity, Credential, and Access Management

RMantra Solutions • Alexandria (VA), Northern (KY)

On-site
USD 140,000 - 190,000