ICAM Specialist

CELESTIAL INNOVATIONS GROUP LLC

Washington (District of Columbia)

Hybrid

USD 120,000 - 150,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

401(k)
Competitive salary
Dental insurance
Health insurance
Opportunity for advancement
Paid time off
Training & development
Vision insurance

Job summary

Celestial Innovations Group (CIG) seeks an Identity, Credential, and Access Management (ICAM) Specialist to deliver enterprise ICAM support for federal clients, focusing on PIV-enabled access across enterprise systems. The ideal candidate brings Federal PKI/ICAM expertise, including hands-on PIV/PIV-I credential issuance and lifecycle management, and Intercede MyID CMS Enterprise deployment.

This role supports Zero Trust initiatives and mandates, with onsite and remote support for the DC Metro

Qualifications

  • 5+ years in cybersecurity engineering, network security, or IT infrastructure
  • Federal government or DoD/civilian agency experience preferred
  • 5+ years Federal PKI/ICAM experience with hands-on PIV/PIV-I issuance

Responsibilities

  • Deliver ICAM support with priority on PIV-enabled access
  • Perform PIV/PIV-I credential issuance and lifecycle management
  • Design and deploy Intercede MyID CMS Enterprise and integrate with PKI
  • Implement Entra Certificate Based Authentication (CBA)
  • Own top-level Conditional Access policy design and privileged access governance
  • Translate ZTA mandates into actionable implementation plans

Skills

ICAM experience
PIV/PIV-I
ZTA
Federal PKI
Entra ID
CMS Enterprise

Tools

Intercede MyID CMS
Microsoft Entra
SCCM
Intune
Workspace ONE
Qualys
Palo Alto

Job description

Benefits:
  • 401(k)
  • Competitive salary
  • Dental insurance
  • Health insurance
  • Opportunity for advancement
  • Paid time off
  • Training & development
  • Vision insurance
POSITION SUMMARY

Celestial Innovations Group (CIG) is seeking an Identity, Credential, and Access Management (ICAM) Specialist to deliver Enterprise ICAM support services for federal agency clients, with priority focus on PIV-enabled logical access implementation across enterprise systems. The specialist will bring Federal PKI/ICAM experience, including hands-on PIV/PIV-I Smartcard credential issuance and lifecycle management, Intercede MyID CMS Enterprise architecture and deployment, and Microsoft Entra Certificate Based Authentication (CBA).

This work supports the Identity pillar of Zero Trust Architecture (ZTA) programs guided by the principle of "never trust, always verify," and aligned with federal mandates including EO 14028, OMB M-22-09, NIST SP 800-207, and the CISA Zero Trust Maturity Model.

These responsibilities and strategies are currently shared across three teams and, as a result, are owned by none of them. Current cyber threats require aligning, consolidating, and bridging access control strategies and policies into a unified front, so the organization can maintain a strong security posture ahead of adversaries.

Must be located in the DC Metro Area as this role requires onsite and remote support.

KEY RESPONSIBILITIES
ICAM and PIV Credentialing
  • Deliver Enterprise Identity, Credential, and Access Management (ICAM) support services, with priority focus on PIV-enabled logical access implementation across enterprise systems
  • Perform PIV/PIV-I Smartcard credential issuance and lifecycle management
  • Design, deploy, configure, and operate Intercede MyID CMS Enterprise, including credential profiles, enrollment workflows, Smartcard issuance, certificate provisioning, renewal, and revocation
  • Integrate Intercede MyID CMS Enterprise with PKI and enterprise identity services
  • Implement and support Microsoft Entra Certificate Based Authentication (CBA)
Identity and Access Management
  • Implement Identity and Access Management controls including CAC/PIV authentication, MFA, role-based access control (RBAC), and Just-in-Time (JIT) Privileged Access Management
  • Own top-level Conditional Access policy design and privileged access governance in Microsoft Entra ID/M365
  • Own access policy exception management, including governance workflows and audit-ready evidence documentation
Zero Trust Integration
  • Support Zero Trust Architecture assessments, gap analyses, and roadmap development for federal clients, with emphasis on the Identity pillar
  • Translate federal ZTA mandates (EO 14028, OMB M-22-09, CISA ZT Maturity Model) into actionable implementation plans
  • Enforce device posture as a condition of access decisions, integrating SCCM, Intune, Workspace ONE (WS1), Purview, Qualys, and Palo Alto NGFW signals
  • Define and enforce application-layer access policy and decisions across M365, Palo Alto NGFW, Entra ID, and Workspace ONE (WS1)
Compliance and Authorization
  • Align implementations with NIST SP 800-53 Rev 5, NIST SP 800-207, DISA STIGs, and continuous diagnostics and mitigation program requirements
  • Support the Risk Management Framework (RMF) lifecycle, including SSP authoring, continuous monitoring, and ATO maintenance
  • Document controls for system security packages, POA&Ms, and security assessment reports
Client Engagement and Collaboration
  • Serve as a trusted ICAM and ZTA advisor to federal agency stakeholders, program managers, and ISSO/ISSM counterparts
  • Produce executive-level briefings, technical white papers, and implementation status reports
  • Collaborate cross-functionally with cloud, networking, data analytics, and infrastructure teams
TECHNOLOGY ECOSYSTEM EXPERIENCE

Candidates are expected to bring experience with the following platforms, with cross-platform fluency strongly preferred:

Intercede MyID CMS Enterprise:

Credential profiles, enrollment workflows, Smartcard issuance, certificate provisioning, renewal, revocation, and integration with PKI and enterprise identity services

Microsoft Identity and Zero Trust:

Microsoft Entra ID (Azure AD), Entra Certificate Based Authentication (CBA), Conditional Access, Intune/MEM, Microsoft Defender suite, Sentinel SIEM/SOAR, Purview data governance, M365 compliance center

Zero Trust Platforms:

Palo Alto Networks (Prisma), and the CISA Zero Trust Maturity Model five-pillar maturity assessment

Additional Enterprise Tooling:

SCCM, Workspace ONE (WS1), Qualys vulnerability management, and Cisco network/wireless fabric, supporting device posture enforcement

REQUIRED QUALIFICATIONS
Experience
  • 5+ years of experience in cybersecurity engineering, network security, or IT infrastructure roles
  • Experience supporting federal government clients or DoD/civilian agency environments
  • 5+ years of Federal PKI and Identity, Credential, and Access Management (ICAM) experience
  • Federal PKI/ICAM experience, with demonstrated hands-on PIV/PIV-I Smartcard credential issuance and lifecycle management experience
  • Credential Management System (CMS) experience, including Intercede MyID CMS Enterprise architecture and deployment
  • Hands-on experience designing, deploying, configuring, and operating Intercede MyID CMS Enterprise, including credential profiles, enrollment workflows, Smartcard issuance, certificate provisioning, renewal, revocation, and integration with PKI and enterprise identity services
  • Microsoft Entra Certificate Based Authentication (CBA)
  • Demonstrated understanding of ZTA concepts across all five pillars per NIST SP 800-207 and the CISA Zero Trust Maturity Model
Technical Skills
  • Identity and access management: Entra ID, Active Directory, LDAP, PKI, MFA, and PAM tooling
  • Endpoint security: device compliance policy enforcement
  • Cloud environments: Azure, AWS, or hybrid cloud architectures
  • Familiarity with SIEM/SOAR platforms (Microsoft Sentinel, SumoLogic, Google SecOps, or equivalent)
PREFERRED QUALIFICATIONS
  • Proficiency in at least one of the following: Palo Alto Prisma, or Microsoft Zero Trust stack
  • Certifications: CISSP, CISM, CompTIA Security+, Cloud+, or relevant AWS/Azure security certifications
  • Zero Trust vendor certifications: PCCSE, PCNSE, Microsoft SC-100 (Cybersecurity Architect Expert)
  • Familiarity with RMF processes: NIST SP 800-37, SSP authoring, ATO package preparation
  • Experience with ServiceNow, Salesforce, or IT service management tooling in a federal context

Flexible work from home options available.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Zero Trust Identity and ICAM Engineer Mid Level
Zero Trust Identity and ICAM Engineer Mid Level

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 120,000 - 180,000
401(k)
Competitive salary
Dental insurance
+5
Senior Zero Trust Identity and ICAM Engineer
Senior Zero Trust Identity and ICAM Engineer

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 135,000 - 180,000
401(k)
Competitive salary
Dental insurance
+4
Senior Identity, Credential, and Access Management (ICAM) Security Engineer
Senior Identity, Credential, and Access Management (ICAM) Security Engineer

Ampcus, Inc • Washington

On-site
USD 100,000 - 130,000
Senior ICAM Engineer
Senior ICAM Engineer

Leidos • United States

On-site
USD 131,000 - 238,000
CMS- ICAM Policy Analyst
CMS- ICAM Policy Analyst

RiseMe • McLean (VA)

On-site
USD 120,000 - 135,000
Lead Specialist, Federal ICAM (Identity, Credential, and Access Management) Engineer
Lead Specialist, Federal ICAM (Identity, Credential, and Access Management) Engineer

KPMG LLP • McLean (VA)

On-site
USD 140,000 - 180,000
ICAM Architect
ICAM Architect

SAIC • Springfield (VA)

On-site
USD 120,000 - 160,000
ICAM Architect: PIV, Zero Trust for Federal, DC Onsite
ICAM Architect: PIV, Zero Trust for Federal, DC Onsite

CELESTIAL INNOVATIONS GROUP LLC • Washington

Hybrid
USD 120,000 - 150,000
401(k)
Competitive salary
Dental insurance
+5
ICAM Security Engineer
ICAM Security Engineer

Leidos • United States

Hybrid
USD 140,000 - 170,000
Senior ICAM Engineer
Senior ICAM Engineer

Easy Dynamics Corp. • United States

On-site
USD 160,000 - 200,000