ICAM Engineer, Senior

Booz Allen Hamilton

Illinois

Hybrid

USD 87,000 - 198,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Booz Allen Hamilton is seeking an Identity and Access Management (IAM) Senior Engineer to design, deploy, and support enterprise IAM systems. You will work on SSO, access controls, and identity federation across on-premises, hybrid, and cloud platforms.

The role emphasizes protecting assets, collaborating with stakeholders, and implementing robust authentication methods in a multi-cloud environment. A Secret clearance is mentioned in the posting.

Qualifications

  • Experience with Ping Federate, Entra ID, Okta, or ADFS.
  • Experience with SAML 2.0, OAuth 2.0, or OpenID Connect (OIDC).
  • Experience with Identity Federation and Single Sign-On (SSO).
  • Experience with access control models such as RBAC or ABAC.
  • Experience integrating IdPs with directory services such as Active Directory (AD) and LDAP, including synchronization and authentication workflows.
  • Knowledge of Zero Trust architectures and implementation of password-less authentication or multifactor authentication (MFA) within the IdP environment.
  • Ability to resolve complex identity and federation issues, including token validation errors, assertion mismatches, and connectivity problems.
  • Ability to design and operate IdP solutions across on-premises, hybrid, and cloud infrastructures, including AWS, Azure, or Google Cloud, and multiple Impact Levels.
  • HS diploma or GED.

Responsibilities

  • Design, deploy, and support IAM systems that verify user privileges and manage credentials.
  • Implement enterprise-class SSO and privileged access solutions to stop adversaries.
  • Analyze identity lifecycles and articulate access requirements for enterprise records.
  • Collaborate with stakeholders and engineering teams to detail processes and user roles.

Skills

IAM expertise
Zero Trust
SSO
AD/LDAP
Token issues

Education

HS diploma or GED

Tools

Jira
Confluence
Okta Workflows
Python
PowerShell
Bash
Azure AD
AWS IAM
Google Cloud Identity

Job description

Join a culture of empowerment and connectivity.

Develop your craft

Learn the skills you need to accelerate your career.

Discover benefits that support your life and work.

Innovate with intention

Build mission-ready tech that protects the nation.

You know that the user is the last frontier for cybersecurity. It’s where the peri met er is drawn, and securing identities is pivotal in the fight against cybercriminals. As an Identity and Access Management ( IAM ) spe cia list, you have the skills and experience to keep hackers from taking data and breaking processes. We’re looking for someone like you to help our clients meet their missions without disruption.

As a Ping Identity Engineer at Booz Allen, you’ll play a critical role in the world of IAM and Zero T rus t. You’ll interface with stakeholders and engineering teams to delve into the details and dependencies of critical processes and users’ roles within them.

You’ll analyze the identity lifecycle, articulating access requirements and defining enterprise identity records. You’ll use your experience in IAM to design, deploy, and support systems that verify appropriate user privileges and manage credentials for accessing our clients’ most valuable assets. From single sign-on to privileged access systems, you’ll have the chance to implement enterprise-class solutions and stop adversaries in their tracks.

Join us. The world can’t wait.

You Have

Experience with Ping Federate, Entra ID, Okta, or ADFS

Experience with SAML 2.0, OAuth 2.0, or OpenID Connect ( OIDC )

Experience with Identity Federation and Single Sign-On ( SSO )

Experience with access control models such as RBAC or ABAC

Experience integrating IdPs with directory services such as Active Directory ( AD ) and LDAP, including synchronization and authentication workflows

Knowledge of Zero T rus t architectures and implementation of password-less authentication or multifactor authentication ( MFA ) within the IdP environment

Ability to resolve complex identity and federation issues, including token validation errors, assertion mismatches, and connectivity problems

Ability to design and operate IdP solutions across on-premises, hybrid , and cloud infrastructures, including AWS, Azure, or Google Cloud, and multiple Impact Levels

HS diploma or GED

Nice If You Have

Experience with agile development solutions such as Jira or Confluence

Experience with advanced platform features such as Okta Workflows, Ping Identity Suite advanced policy scripting, adaptive authentication, and the development of custom login pages

Experience with scripting languages such as Python, PowerShell, or Bash to automate IdP configuration, monitoring, and remediation tasks

Knowledge of cloud-native IAM services, including Azure Active Directory, AWS IAM, or Google Cloud Identity

DoW 8140 Certification

Clearance

Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information ; Secret clearance is required.

Compensation

At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $86,800.00 to $198,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.

ICAM Engineer, Senior
The Opportunity

You know that the user is the last frontier for cybersecurity. It’s where the peri met er is drawn, and securing identities is pivotal in the fight against cybercriminals. As an Identity and Access Management ( IAM ) spe cia list, you have the skills and experience to keep hackers from taking data and breaking processes. We’re looking for someone like you to help our clients meet their missions without disruption.

As a Ping Identity Engineer at Booz Allen, you’ll play a critical role in the world of IAM and Zero T rus t. You’ll interface with stakeholders and engineering teams to delve into the details and dependencies of critical processes and users’ roles within them.

You’ll analyze the identity lifecycle, articulating access requirements and defining enterprise identity records. You’ll use your experience in IAM to design, deploy, and support systems that verify appropriate user privileges and manage credentials for accessing our clients’ most valuable assets. From single sign-on to privileged access systems, you’ll have the chance to implement enterprise-class solutions and stop adversaries in their tracks.

Join us. The world can’t wait.

You Have
  • Experience with Ping Federate, Entra ID, Okta, or ADFS

  • Experience with SAML 2.0, OAuth 2.0, or OpenID Connect ( OIDC )

  • Experience with Identity Federation and Single Sign-On ( SSO )

  • Experience with access control models such as RBAC or ABAC

  • Experience integrating IdPs with directory services such as Active Directory ( AD ) and LDAP, including synchronization and authentication workflows

  • Knowledge of Zero T rus t architectures and implementation of password-less authentication or multifactor authentication ( MFA ) within the IdP environment

  • Ability to resolve complex identity and federation issues, including token validation errors, assertion mismatches, and connectivity problems

  • Ability to design and operate IdP solutions across on-premises, hybrid , and cloud infrastructures, including AWS, Azure, or Google Cloud, and multiple Impact Levels

  • Secret clearance

  • HS diploma or GED

Nice If You Have
  • Experience with agile development solutions such as Jira or Confluence

  • Experience with advanced platform features such as Okta Workflows, Ping Identity Suite advanced policy scripting, adaptive authentication, and the development of custom login pages

  • Experience with scripting languages such as Python, PowerShell, or Bash to automate IdP configuration, monitoring, and remediation tasks

  • Knowledge of cloud-native IAM services, including Azure Active Directory, AWS IAM, or Google Cloud Identity

  • DoW 8140 Certification

Clearance

Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information ; Secret clearance is required.

Compensation

At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $86,800.00 to $198,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.

Identity Statement

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Candidate AI Usage Policy

AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided.

Work Model

Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.

  • Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.

  • Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.

  • Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Ping Identity Engineer
Ping Identity Engineer

Booz Allen Hamilton • United States

Hybrid
USD 87,000 - 198,000
Identity Provider Operations Engineer
Identity Provider Operations Engineer

Booz Allen Hamilton • Reston (VA)

On-site
USD 87,000 - 198,000
Public Key Infrastructure Engineer
Public Key Infrastructure Engineer

Booz Allen Hamilton • Washington

On-site
USD 87,000 - 198,000
Identity Provider Operations Engineer
Identity Provider Operations Engineer

Booz Allen Hamilton • St. Augustine South (FL)

On-site
USD 87,000 - 198,000
ICAM Engineer, Senior
ICAM Engineer, Senior

Phase2 Technology • Norfolk (VA)

On-site
USD 87,000 - 198,000
Identity Provider Operations Engineer
Identity Provider Operations Engineer

Booz Allen Hamilton • Riverdale Park (MD)

On-site
USD 87,000 - 198,000
ICAM Engineer
ICAM Engineer

Phase2 Technology • Shiloh (IL)

On-site
USD 62,000 - 141,000
ICAM Engineer
ICAM Engineer

Phase2 Technology • Norfolk (VA)

On-site
USD 61,000 - 141,000
Identity and Access Management Specialist
Identity and Access Management Specialist

Booz Allen Hamilton • Washington

On-site
USD 87,000 - 198,000
Identity Provider Operations Engineer
Identity Provider Operations Engineer

Phase2 Technology • Reston (VA)

On-site
USD 120,000 - 198,000