Identity and Access Management Engineer

ECS

Fairfax (VA)

Hybrid

USD 130,000 - 180,000

Full time

36 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

null

Job summary

Everforth ECS is seeking an Identity Infrastructure Engineer to join our Fairfax, VA team in a hybrid capacity. You will own the health, integrity, and security of our identity backbone, administering Active Directory, PKI, and identity lifecycle across thousands of users and systems.

The role demands hands-on expertise, clear communication, and a focus on security controls. You will implement RBAC across EntraID, AWS, NGINX, AppGate, and Keycloak, enforce least privilege, and manage PAM, access

Qualifications

  • Must be a U.S. citizen with DoD Secret clearance.
  • 6+ years in Identity and Access Management in complex enterprise or federal environments.
  • Active certifications: DoD 8140 IAT II Security+, AWS Certified Solutions Architect – Associate, AZ-104 or AZ-800.
  • Hybrid work capability in Fairfax, VA (up to 3 days in office).
  • Strong knowledge of AppGate SDP architecture and Keycloak admin interfaces.
  • Experience with EntraID/Azure AD, IAM policies, and Zero Trust concepts.
  • Proficient in SAML, OpenID Connect, LDAP, MFA and related IAM protocols.
  • Ability to translate business access needs into documented security requirements.
  • Experience onboarding users, endpoints, applications, and network resources.
  • Proven track record conducting access reviews, audits, and compliance reporting.
  • Excellent written and verbal communication with diverse stakeholders.
  • Federal ICAM policies familiarity and RBAC design expertise.

Responsibilities

  • Design and implement an RBAC framework across EntraID, AWS, NGINX, AppGate, and Keycloak.
  • Enforce least-privilege policies aligned with Zero Trust and federal directives.
  • Validate access controls against Zero Trust requirements.
  • Develop identity lifecycle processes from joiners to leavers.
  • Lead PAM program governance, monitoring, and privileged account management.
  • Conduct access reviews and PAR/RAR reporting to support compliance.
  • Create role-to-privilege mappings and function definitions to reduce ambiguity.
  • Collaborate with program leadership to align IAM policies with organizational changes.
  • Support AppGate SDP Zero Trust Network Access implementation and operations.
  • Translate user, application, device, and connectivity needs into access-control requirements.
  • Assist senior engineers with identity-based, least-privilege policy design.
  • Onboard users and network resources; maintain IAM metrics and dashboards.
  • Act as IAM SME for program compliance activities and government engagements.

Skills

U.S. Citizen
DoD Secret clearance
Identity & Access Management
6+ years IAM experience
RBAC design
Zero Trust Architecture
Microsoft EntraID / Azure AD
AWS IAM
AppGate SDP
Keycloak
Active Directory
Networking fundamentals
SAML / OpenID Connect
PAM / privileged access
Documentation & communication

Education

High School Diploma

Tools

AppGate SDP
Keycloak Admin Console
Azure AD / EntraID
Active Directory
NGINX

Job description

Job Description

Everforth ECS is seeking an Identity Infrastructure Engineer to work in our Fairfax, VA office in a hybrid capacity. Everforth ECS is seeking an experienced and technically sharp Identity Infrastructure Engineer to join a team responsible for managing and maintaining multiple network enclaves to support the DoW community. This role oversees the design, implementation, and ongoing support of the organization's directory and identity management solutions which is the foundational layer that underpins access, authentication, and security across the entire enterprise. In this role, you will own the health, integrity, and security of the organization's identity infrastructure. That means administering Microsoft Active Directory and related directory services, managing PKI and certificate lifecycle operations, and ensuring that the identity backbone supporting thousands of users and systems is reliable, well-documented, and hardened against threats. This is a hands-on senior-level role for someone who takes pride in keeping complex infrastructure running cleanly, communicates clearly with teams across the organization, and understands that identity is not just a technical function but a critical security control.

Key Responsibilities
  • Design and implement a formal RBAC framework across associated environments, including EntraID, AWS, NGINX, AppGate, And Keycloak
  • Establish and enforce least privilege policies in alignment with Zero Trust Architecture principles and federal directives
  • Validate that implemented access controls align with organizational Zero Trust and security requirements.
  • Develop and manage identity lifecycle processes for joiners, movers, and leavers across the program, ensuring timely provisioning and deprovisioning
  • Implement and manage a Privileged Access Management (PAM) program including identification, governance, and monitoring of privileged accounts
  • Lead access review and audit processes to support PAR/RAR reporting requirements and ongoing compliance obligations
  • Develop and maintain role-to-privilege mappings and job function definitions across the program to eliminate access ambiguity
  • Collaborate with program leadership, system owners, to ensure IAM policies align with organizational changes and personnel transitions
  • Support the implementation and ongoing operation of AppGate SDP Zero Trust Network Access solutions.
  • Gather user, application, device and connectivity requirements and translate them into documented access-control requirements.
  • Assist senior engineers with designing identity-based, least-privilege access policies.
  • Support onboarding of users, endpoints, applications and protected network resources into AppGate SDP.
  • Produce IAM metrics, reports, and dashboards to communicate access risk and governance posture to program leadership
  • Serve as the IAM subject matter expert for program compliance activities, audits, and government stakeholder engagements
  • Other duties, as assigned.

Note: Salary is commensurate with skillset, qualifications, experience, and educational background.

Salary Range: $130,000-180,000

Required Skills
  • U.S. Citizen.
  • Active DoD Secret security clearance.
  • High School Diploma and 6+ years of experience in Identity and Access Management in a complex enterprise or federal environment.
  • Required Active Certifications:
    • DoD 8140 IAT Level II Security+ (or higher).
    • SAA-C03 AWS Certified Solutions Architect - Associate.
    • AZ-104 Azure Administrator - Associate OR Exam AZ-800: Administering Windows Server Hybrid Core Infrastructure.
  • Ability to work in a hybrid capacity in Fairfax, VA (up to 3 days in office).
  • Working knowledge of AppGate SDP architecture, components, policies, entitlements and conditions.
  • Understanding of Zero Trust Network Access, least-privilege access and identity-based security principles.
  • Knowledge of TCP/IP, DNS, routing, firewalls, ports and common network troubleshooting methods.
  • Familiarity with identity and access-management technologies, including SAML, OpenID Connect, LDAP, Active Directory, Keycloak, and multifactor authentication.
  • Ability to:
    • Gather technical requirements and translate business access needs into documented security requirements.
    • Diagnose basic authentication, client-connectivity, entitlement and application-access issues.
  • Experience supporting:
    • User, endpoint, application and network-resource onboarding.
    • Or implementing PAM solutions and privileged account governance
  • Demonstrated expertise with:
    • Microsoft EntraID (Azure AD) including conditional access, role assignments, and identity governance
    • AWS IAM, including policies, roles, permission boundaries, and access analysis tools
  • Strong knowledge of RBAC design, least privilege principles, and Zero Trust Architecture frameworks
  • Familiarity with:
    • CDM program requirements, PAR/RAR processes, and federal ICAM policies
    • Keycloak Admin Console, command-line tools and REST Admin API.
  • Experience conducting access reviews, audits, and compliance reporting
  • Strong documentation and communication skills with the ability to present complex IAM concepts to both technical and non-technical stakeholders
  • Understanding of Keycloak clustering, high availability, caching, database connectivity, backup and disaster recovery.
  • Ability to document identity architecture, authentication flows, integrations and operating procedures.
  • Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
  • Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).
Desired Skills
  • Preferred certifications:
    • SC-300, AZ-500, AWS Security Specialty, CISSP, or CISM.
    • AppGate - SDP Ranger - Partner Certification
    • CLF-C02 AWS Certified Cloud Practitioner
  • Experience with:
    • DOD program tools and frameworks.
    • Microsoft 365 technologies and administration
    • Cloud management platforms such as Microsoft Azure or AWS
  • Prior experience in a federal contractor or agency environment.
  • Familiarity with:
    • NIST SP 800-53, NIST SP 800-207 (Zero Trust), and OMB Memoranda related to identity.
    • Enterprise mobility management and related Windows-based systems.
  • Scripting and automation experience in PowerShell, Bash, Perl, or VBScript.
  • Microsoft License Management experience.

#EverforthECS1

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS is the federal segment of Everforth, a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We Value
  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven

Meet the challenge. Make a difference with Everforth ECS!

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity and Access Management Engineer
Identity and Access Management Engineer

ecsfederal • Virginia (MN)

Hybrid
USD 130,000 - 180,000
Identity Infrastructure Engineer
Identity Infrastructure Engineer

ECS • Washington

On-site
USD 120,000 - 130,000
Identity and Access Management Lead
Identity and Access Management Lead

ECS • Arlington (VA)

On-site
USD 126,000 - 189,000
Identity Security Engineer
Identity Security Engineer

ECS • Washington

On-site
USD 120,000 - 130,000
Identity Security Engineer
Identity Security Engineer

Everforth, Inc. • Washington

Remote
USD 120,000 - 150,000
Technical Support Lead
Technical Support Lead

Everforth ECS • Washington

On-site
USD 140,000 - 190,000
Cloud DevSecOps Engineer
Cloud DevSecOps Engineer

ECS • United States

Remote
USD 130,000 - 175,000
Authentication Engineer
Authentication Engineer

Everforth, Inc. • Washington

On-site
USD 120,000 - 160,000
Hybrid work model
Technical Lead
Technical Lead

ECS • Fairfax (VA)

On-site
USD 170,000 - 210,000
Cloud/Network Infrastructure Engineer, Senior
Cloud/Network Infrastructure Engineer, Senior

Everforth ECS • Arlington (VA)

On-site
USD 150,000 - 190,000