Identity Engineer (USSOCOM-Zero Trust)

Kentro

Tampa (FL)

Hybrid

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
401(k) with employer match
Education reimbursement
Work-life balance

Job summary

Kentro, in partnership with IT Concepts, seeks a Senior Identity Engineer to support the United States Special Operations Command Zero Trust modernization under the EDAT contract. The role designs, implements, integrates, and sustains enterprise ICAM solutions aligned with DoD Zero Trust Architecture requirements.

You will design IAM and PAM, integrate applications with SAML, OAuth 2.0, OIDC, and SCIM, and mentor junior engineers while ensuring RMF, STIG, and cybersecurity audit readiness.

Qualifications

  • Requires 10+ years in IAM/Enterprise Security Engineering.
  • DoD/Federal cybersecurity environments experience preferred.
  • Certifications: DoD 8570/8140 IAT II or IAM II required.

Responsibilities

  • Design, implement, and maintain IAM solutions supporting Zero Trust.
  • Engineer secure authentication using SAML, OAuth 2.0, OIDC, SCIM, and PKI.
  • Develop IGA capabilities with automated provisioning and RBAC.
  • Implement PAM solutions for privileged identities.
  • Integrate applications with federation services and centralized auth platforms.
  • Provide technical leadership and mentorship to junior engineers.

Skills

Identity & Access Management
Zero Trust Architecture
RMF compliance
Cybersecurity audits
Mentoring
Strong communication

Education

Bachelor’s degree in Computer Science/Information Technology/Cybersecurity/Engineering

Tools

SailPoint
Saviynt
CyberArk
BeyondTrust
Delinea
Microsoft Entra ID

Job description

Senior Identity Engineer

Join IT Concepts dba Kentro, where innovation drives opportunity and collaboration leads to success. The Senior Identity Engineer will support the Zero Trust modernization initiative under the EDAT contract for United States Special Operations Command. The role designs, implements, integrates, and sustains enterprise Identity, Credential, and Access Management (ICAM) solutions aligned with DoD Zero Trust Architecture requirements.

Location: Hybrid in Tampa, FL.

Responsibilities
  • Design, implement, and maintain enterprise Identity and Access Management (IAM) solutions supporting Zero Trust initiatives.
  • Engineer secure authentication and authorization services using SAML, OAuth 2.0, OpenID Connect (OIDC), SCIM, and PKI.
  • Design and implement Identity Governance and Administration (IGA) capabilities including automated provisioning, lifecycle management, and role‑based access control (RBAC).
  • Implement and maintain Privileged Access Management (PAM) solutions to secure privileged identities and administrative accounts.
  • Integrate enterprise applications with centralized authentication platforms and federation services.
  • Support Continuous Authentication and Conditional Access capabilities aligned with Zero Trust principles.
  • Develop identity automation using scripting languages such as PowerShell, Python, or REST APIs.
  • Perform identity architecture reviews and recommend improvements to authentication, authorization, and identity lifecycle processes.
  • Develop and maintain identity‑related documentation including architecture diagrams, implementation guides, SOPs, and security documentation.
  • Troubleshoot complex authentication, federation, directory services, and identity synchronization issues.
  • Collaborate with cybersecurity teams to support RMF, STIG implementation, vulnerability remediation, and audit readiness.
  • Provide technical leadership and mentoring to junior engineers and support personnel.
  • Participate in architecture reviews, design sessions, and technical planning activities supporting enterprise modernization efforts.
  • Ensure identity services comply with DoD, DISA, NIST 800‑53, NIST SP 800‑207, and USSOCOM cybersecurity requirements.
Qualifications
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or related field (or equivalent experience).
  • Minimum of 10 years of experience in Identity and Access Management, Identity Engineering, or Enterprise Security Engineering.
  • Minimum of 5 years supporting DoD or Federal enterprise cybersecurity environments.
  • Technical skills: experience implementing or administering IGA platforms, PAM solutions, integrating applications with SAML, OAuth 2.0, OIDC, and SCIM; automating identity management through PowerShell, Python, or REST APIs; supporting cloud identity services in Microsoft Azure; strong understanding of Zero Trust Architecture principles; supporting RMF, STIG compliance, and cybersecurity audits.
  • Excellent written and verbal communication skills.
  • DoD 8570/8140 IAT Level II or IAM Level II compliant certification required.
Preferred Qualifications
  • Experience supporting USSOCOM, DoD, or Intelligence Community environments.
  • Experience with SailPoint, Saviynt, or similar Identity Governance platforms.
  • Experience with CyberArk, BeyondTrust, Delinea, or comparable Privileged Access Management solutions.
  • Experience with Microsoft Entra ID Identity Protection and Conditional Access.
  • Experience supporting enterprise cloud migrations.
  • Familiarity with DevSecOps and Infrastructure as Code (IaC) methodologies.
  • Experience implementing Zero Trust maturity initiatives aligned with DoD guidance.
Clearance Requirement
  • Active TS/SCI security clearance.
  • Must be a US citizen.
Benefits
  • Competitive benefits package including paid time off, healthcare benefits, supplemental benefits, 401(k) with employer match, discount perks, rewards, and more.
  • Education reimbursement for certifications, degrees, or professional development.
  • Work‑life balance with virtual and in‑person activities, events, and celebrations.
  • Commitment to continuous professional development and career growth.
Equal Opportunity Employment & VEVRAA

Kentro is an equal‑opportunity employer and is committed to compliance with VEVRAA and other applicable federal, state, and local laws governing equal employment opportunity. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable law.

Accommodations

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions. If you need to discuss reasonable accommodations, please contact careers@kentro.us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Data Protection Engineer (USSOCOM-Zero Trust, Azure Security & Network DLP)
Senior Data Protection Engineer (USSOCOM-Zero Trust, Azure Security & Network DLP)

Kentro • Tampa (FL)

Hybrid
USD 100,000 - 130,000
Paid time off
Healthcare benefits
401(k) with employer match
+1
Senior Integration Engineer (API/Cross Enclave), Zero Trust (TS/SCI)
Senior Integration Engineer (API/Cross Enclave), Zero Trust (TS/SCI)

Kentro • Tampa (FL)

On-site
USD 100,000 - 130,000
Paid time off
Healthcare benefits
401(k) with employer match
+1
Senior Data Security Engineer - DRM (TS/SCI)
Senior Data Security Engineer - DRM (TS/SCI)

Kentro Estelle iLab • Tampa (FL)

Hybrid
USD 150,000 - 190,000
Healthcare benefits
401k with employer match
Education reimbursement
Senior Data Security Engineer (USSOCOM-Zero Trust, Azure Security & DLP)
Senior Data Security Engineer (USSOCOM-Zero Trust, Azure Security & DLP)

Kentro • Tampa (FL)

Hybrid
USD 110,000 - 145,000
Paid time off
Healthcare benefits
401k with employer match
+1
Senior Data Security Engineer (USSOCOM-Zero Trust, Azure Security & DLP)
Senior Data Security Engineer (USSOCOM-Zero Trust, Azure Security & DLP)

Kentro Estelle iLab • Tampa (FL)

Hybrid
USD 90,000 - 120,000
Healthcare benefits
401k with employer match
Paid time off
+1
Senior Identity Engineer — DoD Zero Trust & PAM Expert
Senior Identity Engineer — DoD Zero Trust & PAM Expert

Kentro • Tampa (FL)

Hybrid
USD 120,000 - 180,000
Health benefits
401(k) with employer match
Education reimbursement
+1
Identity Management Engineer / Architect (R-00197)
Identity Management Engineer / Architect (R-00197)

Socket.dev • United States

Remote
USD 120,000 - 180,000
Competitive salary
Best medical coverage
Premium medical premiums covered by us
+3
EDAT- System Information Assurance and Security Engineer
EDAT- System Information Assurance and Security Engineer

Barbaricum • Tampa (FL)

On-site
USD 130,000 - 180,000
Senior Data Security Engineer - DRM (TS/SCI)
Senior Data Security Engineer - DRM (TS/SCI)

Kentro • Tampa (FL)

Hybrid
USD 120,000 - 160,000
Paid time off
Healthcare benefits
401(k) with employer match
+1
EDAT- Journeyman Cyber Security Engineer (Microsoft) – Zero Trust- Tampa, FL
EDAT- Journeyman Cyber Security Engineer (Microsoft) – Zero Trust- Tampa, FL

Barbaricum • Tampa (FL)

On-site
USD 110,000 - 150,000