ICAM Security Engineer

Leidos Inc

Gaithersburg (MD)

Hybrid

USD 90,000 - 157,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Leidos is seeking an ICAM / Identity Engineer to join the Air Traffic Business Area, delivering the L-CAP platform with an AI-first engineering mindset in a hybrid cloud environment. You will implement ICAM layers, integrate with government ICAM services, and enforce per-session authorization across distributed services, including RBAC/ABAC and mTLS.

You will work within SAFe/Agile processes to deliver iterative value, supporting government programs and maintaining security logging, audit

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology or related field with 4+ years of experience.
  • Hands‑on experience with OAuth 2.0 and OpenID Connect, including token validation, introspection, and claims mapping.
  • Experience with enterprise identity providers and federation (Keycloak, Okta, Ping, Entra ID, or equivalent).
  • Experience implementing RBAC and/or ABAC within distributed applications.
  • Working knowledge of PKI, certificate lifecycle management, mutual TLS, and service mesh identity.
  • Understanding of Zero Trust principles with per-session authorization and default-deny principles.
  • Experience implementing audit logging for access and authorization events.
  • Proficiency in Java, Python, Go or similar language.
  • Working knowledge of NIST SP 800-53 AC and AU controls.
  • U.S. citizenship with ability to obtain Public Trust and complete government background investigations.

Responsibilities

  • Integrate L-CAP with government ICAM services using OAuth 2.0 / OpenID Connect, including token issuance and validation.
  • Implement identity federation and user stores (Keycloak or equivalent).
  • Enforce per-session authentication and authorization for user-to-service and service-to-service requests.
  • Manage mutual TLS, service mesh identity, and certificate lifecycle processes.
  • Design and implement RBAC and ABAC aligned to operations and support roles.
  • Handle sign-in, sign-out, and time-on-position logging for operational users.
  • Develop and maintain ICAM audit logging for access events.
  • Oversee API gateway authorization and protect external endpoints via API management.
  • Contribute to ICAM control evidence and AI-assisted development to improve quality and delivery.

Skills

OAuth 2.0 / OpenID Connect
Identity federation
RBAC / ABAC
PKI / mTLS
Zero Trust
Audit logging
Java / Python / Go
Kubernetes
NIST SP 800-53 AC AU
U.S. citizenship

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology

Tools

Keycloak
Okta
Ping Identity
Microsoft Entra ID
Federation protocols

Job description

Description

Leidos is seeking an ICAM / Identity Engineer to join the Air Traffic Business Area within the Homeland Sector, supporting the development of the Leidos Common Automation Platform (L-CAP). L-CAP is a mission-critical, future-ready automation platform built on a hybrid cloud data mesh architecture, enabling next-generation air traffic management capabilities. We are building with an AI-first engineering mindset, embracing emerging AI capabilities and modern development practices to accelerate delivery, improve software quality, and continuously evolve how we design and build mission-critical systems. This role operates within a SAFe/Agile framework as part of an Agile Release Train (ART) delivering iterative value across the program. This position supports government programs and requires the ability to obtain and maintain a favorable Public Trust investigation.

This is a hybrid position requiring 3 days onsite and 2 days working from home, if you are located within a commutable distance (Less than 1 hour's drive one-way during normal traffic) from Gaithersburg, MD; Eagan, MN; or Egg Harbor Township, NJ. However, if you do not reside within a commutable distance, you may be considered for a 100% remote role.

In this role, you will implement the identity, credential, and access management (ICAM) layer that governs every user and service interaction with L-CAP. You will integrate the platform with government-provided ICAM services, enforce per-session authorization across distributed mission services, and build the access control and audit foundations that operational and support users depend on.

What You'll Do:
  • Integrate L-CAP services with government-provided ICAM services using OAuth 2.0 and OpenID Connect, including token issuance, validation, and claims mapping.
  • Implement and maintain identity federation and user stores (Keycloak or equivalent), including role-based test account provisioning.
  • Implement per-session authentication and authorization for user-to-service and service-to-service requests, enforcing default-deny access regardless of network location.
  • Implement mutual TLS (mTLS), service mesh/workload identity, and certificate lifecycle management, including issuance, rotation, expiration monitoring, and revocation.
  • Design and implement role-based (RBAC) and attribute-based (ABAC) access controls aligned to operational and support roles.
  • Implement authentication and session management for operational users, including sign-in/sign-out and time-on-position logging.
  • Implement authentication and authorization audit logging, including event capture, storage, and retrieval.
  • Implement API gateway authorization and ensure external-facing endpoints are registered and protected through the API management layer.
  • Support security authorization and continuous monitoring by producing ICAM control evidence, resolving identity integration issues across distributed services, and leveraging AI-assisted development and automation to improve quality and delivery.
Core Technical Qualifications:
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field with 4+ years of relevant experience.(additional experience, education and training may be considered in lieu of degree)
  • Hands‑on experience with OAuth 2.0 and OpenID Connect, including token validation, introspection, and claims mapping.
  • Experience with enterprise identity providers and federation such as Keycloak, Okta, Ping, Microsoft Entra ID, or equivalent.
  • Experience implementing RBAC and/or ABAC within distributed applications.
  • Working knowledge of PKI, certificate lifecycle management, mutual TLS (mTLS), and/or service mesh identity.
  • Understanding of Zero Trust principles, including per-session authorization and default-deny service communication.
  • Experience implementing audit logging for access and authorization events.
  • Proficiency in Java, Python, Go, or a comparable programming/scripting language.
  • Working knowledge of NIST SP 800-53 Access Control (AC) and Audit and Accountability (AU) controls.
  • Experience with Kubernetes and containerized service deployments.
  • U.S. citizenship required, with the ability to obtain and maintain a Public Trust and successfully complete required government background investigations.
  • Must meet FAA facility and information system access requirements, including continuous U.S. residency for at least 3 of the previous 5 years.
Preferred / Desired Qualifications:
  • Security+ CE, CySA+, or equivalent DoD 8570 IAT Level II certification.
  • Federal ICAM/FICAM experience, including PIV/CAC or agency ICAM integrations.
  • Experience with SAML 2.0 and SCIM provisioning.
  • Experience with Kubernetes RBAC and workload identity (SPIFFE/SPIRE).
  • Experience with service mesh implementation (Istio, Linkerd).
  • Experience with API gateway authorization policy (Kong, Apigee, or equivalent).
  • Familiarity with FIPS 140-3 validated cryptographic modules, hardware security modules, or enterprise key management.
  • Knowledge of privileged access management practices.
  • Experience in aviation, FAA, or other safety-critical environments.
  • Experience with SAFe or large-scale Agile delivery.
Why Leidos?

You'll work on systems where performance, precision, and reliability matter - every second. This is not experimental AI for prototypes. This is disciplined, responsible AI applied to mission-critical software that supports national infrastructure.

If you're excited by solving complex problems in regulated, real-world environments - and using AI as a force multiplier rather than a shortcut - we'd like to talk.

Original Posting:

September 21, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $87,100.00 - $157,450.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Pay and Benefits

Pay and benefits are fundamental to any career decision that's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

ICAM Security Engineer
ICAM Security Engineer

Leidos Inc • Eagan (MN)

Hybrid
USD 87,000 - 157,000
ICAM Security Engineer
ICAM Security Engineer

Leidos • Eagan (MN)

Hybrid
USD 87,000 - 157,000
Hybrid work model
ICAM Security Engineer
ICAM Security Engineer

Leidos Inc • Egg Harbor Township (NJ)

Hybrid
USD 87,000 - 157,000
ICAM Security Engineer
ICAM Security Engineer

Leidos • Gaithersburg (MD)

Hybrid
USD 87,000 - 157,000
ICAM Security Engineer
ICAM Security Engineer

Leidos • Egg Harbor Township (NJ)

Hybrid
USD 87,000 - 157,000
ICAM Security Engineer Leidos · Gaithersburg, NJ + 1 more Full-time · On-site $87,100–157,450 2 hours ago
ICAM Security Engineer Leidos · Gaithersburg, NJ + 1 more Full-time · On-site $87,100–157,450 2 hours ago

Emploive • Gaithersburg (MD), Northern (KY)

Hybrid
USD 87,000 - 157,000
ICAM Engineering Support Staff 24x7
ICAM Engineering Support Staff 24x7

Leidos • Hanover (MD)

On-site
USD 87,000 - 158,000
Paid Time Off
401K with 6% company match
Flexible Schedules
+2
Lead Identity and Access Management (ICAM) Engineer
Lead Identity and Access Management (ICAM) Engineer

Leidos Inc • Rockville (MD)

On-site
USD 131,000 - 237,000
Senior ICAM Federation & App Onboarding Engineer
Senior ICAM Federation & App Onboarding Engineer

Via Logic LLC • Reston (VA)

On-site
Senior AD/ICAM Administrator
Senior AD/ICAM Administrator

Leidos • Virginia (MN)

Hybrid
USD 142,000 - 237,000