ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services

General Dynamics - IT

Virginia (IL)

Hybrid

USD 180,000 - 250,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

General Dynamics - IT seeks a Principal ICAM Architect and IdP Engineer to lead enterprise-scale authentication and federation strategies across the DoD. This remote role oversees ADFS and modern IdP platforms for millions of identities, guiding architecture and engineering teams toward Zero Trust and ICAM modernization.

You will define enterprise standards, enforce security controls, and provide authoritative guidance across cybersecurity, infrastructure, and applications.

Qualifications

  • Active Secret Clearance at minimum; interim clearances not allowed.
  • 15+ years in enterprise identity architecture, ICAM engineering, and authentication platforms.
  • Experience designing large-scale IdP and federation solutions for DoD or similarly regulated environments.

Responsibilities

  • Define enterprise ICAM architecture standards and Zero Trust-aligned identity strategy.
  • Architect, deploy, and secure large-scale IdP platforms (ADFS, SAML, OIDC) for millions of identities.
  • Lead engineering teams, guide Agile cycles, and provide governance across authentication ecosystems.

Skills

Identity architecture
ICAM engineering
authentication platforms
federation technologies
SAML
OIDC
JWT
PKI
MFA
Active Directory

Education

Bachelor's Degree in a related technical discipline
DoD 8570/8140 IAT Level II certification (Security+ CE or higher)

Tools

PingFederate
PingDirectory
Keycloak
Okta
Azure AD / Microsoft Entra ID
AD CS
Windows
Linux
PowerShell

Job description

ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services

GDIT is seeking a highly experienced Principal ICAM Architect and Identity Provider Engineer to lead enterprise-scale authentication and federation strategy across the Department of Defense. This role serves as a senior technical authority responsible for defining architecture, guiding engineering teams, and delivering resilient Identity Provider (IdP) services that support secure authentication for more than 4 million DoD enterprise identities. This position is fully remote.

MEANINGFUL WORK AND PERSONAL IMPACT

The ideal candidate brings 15+ years of deep experience in identity architecture, enterprise authentication platforms, federation engineering, and strategic ICAM modernization. As a Principal Engineer, you will define enterprise standards, drive Zero Trust–aligned identity strategies, and provide authoritative guidance across mission-critical authentication ecosystems. You will serve as a senior technical leader partnering with cybersecurity, infrastructure, and application teams to evolve enterprise identity capabilities. Serve as the enterprise technical lead and architect for Identity Provider services across DoD, driving long-term ICAM strategy, modernization, and architectural governance.

Architect, build, and evolve large-scale ADFS and modern IdP platforms to deliver secure, resilient authentication and federation for millions of identities. Define enterprise trust architectures, federation models, and cross-boundary identity integration patterns with internal DoD components, mission partners, and external organizations. Lead design and architecture of authentication solutions leveraging SAML, OAuth, OpenID Connect (OIDC), WS-Federation, JWT, and certificate-based technologies. Set technical direction for onboarding applications, APIs, and enterprise services into the authentication ecosystem, ensuring alignment with Zero Trust and DoD ICAM standards.

Develop enterprise-wide policies, claims rule frameworks, token issuance patterns, identity assurance levels, and authorization logic. Provide principal-level oversight for MFA, phishing-resistant authentication, Conditional Access, and passwordless identity technologies. Act as the senior escalation point for the most complex trust, certificate, federation, and token issues impacting mission-critical workloads. Architect highly available, fault-tolerant authentication platforms incorporating advanced load balancing, multi-region resiliency, failover, and operational continuity strategies. Produce authoritative technical documentation including architecture roadmaps, engineering standards, reference architectures, integration guides, and operational frameworks.

Lead and mentor engineering teams, provide guidance during Agile development cycles, and champion continuous improvement across authentication services. Identify enterprise risks, drive mitigation strategies, and advise senior leadership on authentication posture, ICAM modernization plans, and Zero Trust progress.

Basic Qualifications

Active Secret Clearance at minimum. Interim Secret Clearances are not allowed. Bachelor’s Degree in a related technical discipline, or the equivalent combination of education, technical certifications or training, or work experience. DoD 8570/8140 IAT Level II certification (Security+ CE or higher).

Required Skills/Knowledge

15+ years of experience in enterprise identity architecture, ICAM engineering, authentication platforms, or federation technologies. Deep expertise designing and leading enterprise-scale ADFS and IdP solutions. Proven leadership architecting identity systems for large regulated environments supporting millions of users. Advanced understanding of authentication, authorization, identity assurance, federation protocols, and Zero Trust identity pillars. Strong experience with SAML, OAuth, OIDC, WS-Federation, JWT, PKI, smart card authentication, and MFA architectures. Architecture-level experience integrating mission applications and APIs with enterprise IdP and federation platforms. Expert-level proficiency with Active Directory, LDAP directories, identity repositories, and claims-based identity systems. Hands‑on experience designing enterprise token rules, claims mappings, federation workflows, and trust policies. Expertise with Windows and Linux server platforms in identity contexts. Experience deploying identity COTS products in secure environments. Excellent communication skills, with ability to provide guidance to engineers and influence leadership. Proven success driving large‑scale identity initiatives from architecture to implementation.

Desired Skills/Knowledge

Experience designing and supporting highly available ADFS farms with Web Application Proxy (WAP), load balancing, and disaster recovery architectures. Experience with Microsoft Entra ID (Azure AD), PingFederate, PingAccess, PingDirectory, Okta, Keycloak, or similar enterprise authentication platforms. Experience supporting DoD Enterprise ICAM, Federation Hub, or mission partner federation initiatives. Experience implementing federation solutions for coalition, partner, or cross-organizational environments. Experience supporting NIST 800-63 Identity Assurance Levels (IAL), Authenticator Assurance Levels (AAL), and Federation Assurance Levels (FAL). Experience implementing phishing-resistant authentication technologies and passwordless authentication solutions. Experience supporting Zero Trust Architecture and identity-centric security initiatives. Familiarity with PowerShell scripting and automation for ADFS administration. Experience supporting enterprise monitoring, performance tuning, and capacity planning for authentication services supporting millions of identities. Experience with Active Directory Certificate Services (AD CS) and enterprise PKI. Familiarity with container technologies such as Docker and Kubernetes. Familiarity with DoD PKI, CAC authentication, derived credentials, and certificate lifecycle management. Experience supporting highly available, mission-critical enterprise authentication environments.

GDIT IS YOUR PLACE
  • Growth: AI-powered career tool that identifies career steps and learning opportunities
  • Support: An internal mobility team focused on helping you achieve your career goals
  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
  • Flexibility: Full-flex work week to own your priorities at work and at home
  • Community: Award-winning culture of innovation and a military-friendly workplace
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ICAM Identity Provider (IdP) Engineer Enterprise Authentication Services
ICAM Identity Provider (IdP) Engineer Enterprise Authentication Services

General Dynamics Information Technology • Fort Meade (MD)

On-site
USD 110,000 - 160,000
ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services
ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services

General Dynamics Information Technology • United States

On-site
USD 140,000 - 190,000
Growth opportunities
Internal mobility program
Benefits & wellness package
+2
Remote ICAM IdP Architect - Enterprise Authentication Leader
Remote ICAM IdP Architect - Enterprise Authentication Leader

General Dynamics - IT • Virginia (IL)

Hybrid
USD 180,000 - 250,000
ICAM IdP Engineer – Enterprise Authentication
ICAM IdP Engineer – Enterprise Authentication

General Dynamics Information Technology • United States

On-site
USD 140,000 - 190,000
Growth opportunities
Internal mobility program
Benefits & wellness package
+2
ICAM Systems Engineer & Manager
ICAM Systems Engineer & Manager

General Dynamics Corporation • Town of Florida (NY), Northern (KY)

Hybrid
USD 113,000 - 132,000
ICAM IdP Engineer — Enterprise Identity & Access Expert
ICAM IdP Engineer — Enterprise Identity & Access Expert

General Dynamics Information Technology • Fort Meade (MD)

On-site
USD 110,000 - 160,000
ICAM Software Engineer - SailPoint/Radiant Logic
ICAM Software Engineer - SailPoint/Radiant Logic

General Dynamics - IT • Fort Meade (MD)

Hybrid
USD 125,000 - 160,000
Growth opportunities
Internal mobility support
Comprehensive benefits & wellness
+2
Remote ICAM IdP Engineer — Secure Authentication & SSO
Remote ICAM IdP Engineer — Secure Authentication & SSO

General Dynamics Information Technology • Falls Church (VA)

On-site
USD 140,000 - 190,000
Health insurance
401K with company match
Paid time off
+1
Senior ICAM IdP Engineer - Remote, SSO & MFA Expert
Senior ICAM IdP Engineer - Remote, SSO & MFA Expert

General Dynamics Information Technology • United States

On-site
USD 170,000 - 230,000
Remote ICAM IdP Engineer – Enterprise Authentication
Remote ICAM IdP Engineer – Enterprise Authentication

General Dynamics - IT • Home (KS)

On-site
USD 140,000 - 180,000
401K with company match
Comprehensive benefits
Paid time off