Lead Identity and Access Management (ICAM) Engineer

Leidos Inc

Rockville (MD)

On-site

USD 131,000 - 237,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Leidos is seeking an expert-level Lead Identity and Access Management Engineer to act as the senior technical authority for enterprise IAM initiatives across cloud and on‑prem environments. The candidate will leverage deep Microsoft identity expertise to design, implement, and mature IAM architectures and processes while mentoring junior engineers.

Responsibilities include leading IAM design, governance, RBAC/ABAC, audits, and cross‑functional collaboration with security, compliance and

Qualifications

  • 8+ years in identity and access management with progressive responsibilities.
  • 5+ years in senior/lead or SME capacity owning enterprise IAM architecture.
  • Experience with cloud IAM services (Azure Entra ID, AWS IAM/SSO, GCP IAM).
  • Hands-on with at least two IAM platform categories: IGA, PAM, SSO/Federation, Directory Services.

Responsibilities

  • Lead design, engineering, and continuous improvement of enterprise IAM solutions (IGA, PAM, SSO, MFA, directories).
  • Serve as SME for IAM architecture decisions, tool selection, and integration strategy across cloud and on-premise platforms.
  • Define and enforce identity lifecycle processes (joiner-mover-leaver) and RBAC/ABAC with least-privilege.
  • Lead IAM audits, risk assessments, and remediation; ensure regulatory/commercial obligations compliance.
  • Partner with security, application owners, and compliance teams to integrate apps into IAM platforms.
  • Provide technical leadership and mentorship to IAM engineers; support incident response.
  • Evaluate emerging IAM technologies and propose adoption strategies; produce architecture docs and executive reports.

Skills

IAM architecture
Microsoft identity solutions
EntraID/Azure AD
PAM (CyberArk, Beyond Trust)
SSO/Federation
RBAC/ABAC
PowerShell
Graph API
Zero Trust
Identity governance
Cloud IAM (Azure, AWS, GCP)
Active Directory/Entra ID

Education

Bachelor's degree in computer science or equivalent

Tools

Active Directory
Azure AD/Entra ID

Job description

Description

Leidos Digital Civilian Agency Solutions division is seeking an expert-level Lead Identity and Access Management Engineer to serve as the senior technical authority for complex enterprise identity management solutions for large-scale government digital transformation initiatives. The ideal candidate will have deep expertise in Microsoft identity technologies and a proven track record of designing, implementing, and maturing IAM architecture and processes across cloud and on-premises environments, ensuring alignment with industry frameworks and regulatory requirements, and provides technical leadership and mentorship to junior and mid-level IAM engineers. advanced enterprise-level identity solutions.

Candidate MUST

Be a US Citizen or US Person who has lived in the United States for at least three consecutive years and have the ability to obtain a Public Trust level 4 clearance

Primary Responsibilities
  • Lead the design, engineering, and continuous improvement of enterprise IAM solutions, including Identity Governance and Administration (IGA), Privileged Access Management (PAM), Single Sign-On (SSO)/Federation, Multi-Factor Authentication (MFA), and directory services.
  • Serve as the SME for IAM architecture decisions, tool selection, and integration strategy across cloud (Azure, AWS, GCP) and on-premises platforms.
  • Define and enforce Identity lifecycle management processes (joiner-mover-leaver), role-based/attribute-based access control (RBAC/ABAC), and least-privilege principles.
  • Lead IAM-related audits, risk assessments, and remediation efforts; ensure compliance with regulatory and contractual obligations.
  • Partner with security operations, application owners, and compliance teams to integrate applications into enterprise IAM platforms (e.g., Microsoft Entra ID/Azure AD, Okta, Ping Identity, CyberArk).
  • Provide technical leadership, mentoring, and peer review for IAM engineering staff.
  • Support incident response and forensic investigations involving identity-related events.
  • Evaluate emerging IAM technologies (e.g., password less authentication, decentralized identity, Zero Trust architecture) and recommend adoption strategies.
  • Prepare technical documentation, architecture diagrams, and executive-level reporting on IAM posture and roadmap.
Required Qualifications
  • Bachelor's degree in computer science, Information Technology, or equivalent and 12 years of general experience, preferably supporting system engineering. 6 years of additional experience is equivalent to a Bachelor's degree. With a Master's degree, 10 years of general experience is required.
  • 8+ years of progressive experience focusing on identity and access management.
  • 5+ years in a senior/lead or SME capacity, with demonstrated ownership of enterprise-scale IAM architecture.
  • Hands-on experience with at least two of the following IAM platform categories:
    • IGA: Microsoft Identity Manager
    • PAM: CyberArk, Beyond Trust
    • SSO/Federation: Okta, Microsoft Entra ID, Ping Identity
    • Directory Services: Active Directory, Azure AD/Entra ID, LDAP
  • Experience supporting federal, defense, or highly regulated environments preferred (especially for government/contractor roles).
  • Experience with cloud IAM services (Azure Entra ID, AWS IAM/SSO, GCP IAM).
  • Deep understanding of authentication and authorization protocols: SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), SCIM, Kerberos.
  • Extensive hands-on experience with Microsoft identity solutions (Entra ID, AD FS, Microsoft 365, MIM).
  • Proven experience in large-scale, multi-forest Active Directory and Entra ID architectures.
  • Advanced knowledge of identity protocols (SAML, OAuth 2.0, OpenID Connect, WS-Federation, CBA).
  • Strong experience with Entra B2B and B2C for external identity management.
  • Experience with Entra AD Connect, including custom synchronization rules.
  • Strong proficiency in PowerShell and Graph API for identity management automation.
  • Familiarity with Zero Trust architecture and identity-related security best practices.
Preferred Qualifications
  • Relevant certifications, hold at least one or two of the following, aligned to seniority:
    • CIAM (Certified Identity and Access Manager) or CIGE (Certified Identity Governance Expert)
    • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
    • CyberArk Defender/Sentry/Guardian
    • Okta Certified Professional/Consultant/Administrator
    • Ping Identity Certified Professional
    • CompTIA Security+
  • Knowledge of identity-related compliance standards (e.g., NIST, FISMA, SOC, FedRamp).
  • Experience with Azure AD Verifiable Credentials and decentralized identity concepts.
  • Understanding of biometric authentication methods and their Azure AD integration.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range $131,300.00 - $237,350.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

Securing Your Data

Beware of fake employment opportunities using Leidos' name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system - never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at LeidosCareersFraud@leidos.com.

If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Identity and Access Management (ICAM) Engineer
Lead Identity and Access Management (ICAM) Engineer

Via Logic LLC • Rockville (MD)

On-site
USD 131,000 - 237,000
Competitive compensation
Health and Wellness programs
Income Protection
+1
Lead Identity and Access Management (ICAM) Engineer
Lead Identity and Access Management (ICAM) Engineer

Koitecc Solutions • Rockville (MD)

On-site
USD 131,000 - 237,000
Health and Wellness programs
Income Protection
Paid Leave and Retirement
Senior AD/ICAM Administrator
Senior AD/ICAM Administrator

Leidos Inc • Virginia (MN)

On-site
USD 131,000 - 237,000
Lead Identity and Access Management (ICAM) Engineer
Lead Identity and Access Management (ICAM) Engineer

Leidos • Rockville (MD)

On-site
USD 131,000 - 237,000
Senior AD/ICAM Administrator
Senior AD/ICAM Administrator

Leidos • Virginia (MN)

Hybrid
USD 142,000 - 237,000
Identity and Access Engineer (ICAM) Engineer
Identity and Access Engineer (ICAM) Engineer

Leidos • Rockville (MD)

On-site
USD 87,000 - 157,000
Identity and Access Engineer (ICAM) Engineer
Identity and Access Engineer (ICAM) Engineer

Leidos Inc • Rockville (MD)

On-site
USD 87,000 - 157,000
ICAM/AD Solutions Architect
ICAM/AD Solutions Architect

COMFORT SYSTEMS • Washington

On-site
USD 131,000 - 238,000
Senior ICAM Federation & App Onboarding Engineer
Senior ICAM Federation & App Onboarding Engineer

Via Logic LLC • Reston (VA)

On-site
ICAM Engineering Support Staff 24x7
ICAM Engineering Support Staff 24x7

Leidos • Hanover (MD)

On-site
USD 87,000 - 158,000
Paid Time Off
401K with 6% company match
Flexible Schedules
+2