Senior Cloud DevOps Engineer - Identity Management

CACI

San Antonio (TX)

On-site

USD 86,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CACI is seeking a Senior Cloud DevOps Engineer specializing in Identity Management to design, secure, and operate enterprise ICAM across hybrid and multi-cloud environments.

You will lead Keycloak deployments, implement Vault-based secrets management, and integrate AWS, Azure, and on-prem stores into a unified ICAM architecture. Collaboration with security and DevOps teams is essential for Zero Trust and scalability.

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, or related technical field.
  • 5+ years of experience in DevOps, Cloud Engineering, or Infrastructure Automation roles.
  • Hands-on experience managing Keycloak, HashiCorp Vault, or comparable IAM and secrets management tools.
  • Strong understanding of identity federation (SAML, OIDC, OAuth2) and directory integration concepts.
  • Proficiency with infrastructure as code (Terraform, Ansible, or CloudFormation).

Responsibilities

  • Architect, deploy, and maintain Keycloak identity management systems in hybrid and multi-cloud environments.
  • Implement and manage secrets management solutions using HashiCorp Vault, including dynamic secrets, PKI, and access policies.
  • Integrate cloud-native and on-prem identity stores (e.g., AWS IAM, Azure AD, LDAP, Active Directory) into unified ICAM architectures.
  • Develop and automate CI/CD pipelines for deploying and maintaining ICAM-related infrastructure as code (IaC).
  • Define and enforce security policies for authentication, authorization, and token management across distributed systems.
  • Collaborate with security teams to implement Zero Trust and least-privilege access principles.
  • Configure and maintain high availability, backup, and recovery strategies for Keycloak and Vault services.
  • Monitor, troubleshoot, and optimise performance and reliability of identity systems and associated integrations.
  • Maintain documentation of configurations, operational procedures, and identity management standards.
  • Support compliance initiatives by ensuring alignment with NIST, FedRAMP, and organizational security frameworks.

Skills

DevOps
Cloud engineering
IAM
SAML/OIDC/OAuth2
IaC
Scripting

Education

Bachelor's degree

Tools

Keycloak
HashiCorp Vault
AWS
Azure
GCP
Terraform
Ansible
CloudFormation
Kubernetes

Job description

Job Title: Senior Cloud DevOps Engineer - Identity Management

Job Category: Information Technology

Time Type: Full time

Minimum Clearance Required to Start: TS/SCI

Employee Type: Regular

Percentage of Travel Required: None

Type of Travel: None

The Opportunity:

Join a forward-thinking cloud engineering team responsible for designing, securing, and maintaining enterprise identity and access management systems. Lead the integration and automation of identity services across hybrid cloud and on-premises infrastructures.

  • Drive the modernization of authentication, authorization, and secrets management capabilities using Keycloak, HashiCorp Vault, and related technologies.
  • Collaborate with cybersecurity, DevSecOps, and infrastructure teams to enhance security posture and streamline identity workflows.
  • Play a critical role in ensuring seamless, secure, and scalable access to secure multi-cloud and on-prem systems across the organization.
Responsibilities:
  • Architect, deploy, and maintain Keycloak identity management systems in hybrid and multi-cloud environments.
  • Implement and manage secrets management solutions using HashiCorp Vault, including dynamic secrets, PKI, and access policies.
  • Integrate cloud-native and on-prem identity stores (e.g., AWS IAM, Azure AD, LDAP, Active Directory) into unified ICAM architectures.
  • Develop and automate CI/CD pipelines for deploying and maintaining ICAM-related infrastructure as code (IaC).
  • Define and enforce security policies for authentication, authorization, and token management across distributed systems.
  • Collaborate with security teams to implement Zero Trust and least-privilege access principles.
  • Configure and maintain high availability, backup, and recovery strategies for Keycloak and Vault services.
  • Monitor, troubleshoot, and optimise performance and reliability of identity systems and associated integrations.
  • Maintain documentation of configurations, operational procedures, and identity management standards.
  • Support compliance initiatives by ensuring alignment with NIST, FedRAMP, and organizational security frameworks.
Qualifications:
  • Bachelor's degree in Computer Science, Information Systems, or related technical field.
  • 5+ years of experience in DevOps, Cloud Engineering, or Infrastructure Automation roles.
  • Hands-on experience managing Keycloak, HashiCorp Vault, or comparable IAM and secrets management tools.
  • Strong understanding of identity federation (SAML, OIDC, OAuth2) and directory integration concepts.
  • Proficiency with infrastructure as code (Terraform, Ansible, or CloudFormation).
  • Experience with at least one major cloud provider (AWS, Azure, or GCP) and hybrid integration patterns.
  • Strong scripting skills in Bash, Python, or Go for automation and operational tasks.
  • Solid understanding of networking, PKI, TLS, and secure service-to-service communication.
  • Demonstrated ability to troubleshoot complex system and identity-related issues in production environments.
Desired:
  • Experience implementing Zero Trust architectures or enterprise ICAM modernization initiatives.
  • Knowledge of Kubernetes, containerised deployments, and service mesh identity integration.
  • Familiarity with regulatory compliance frameworks (FedRAMP, DoD RMF, ISO 27001).
  • Experience with GitOps workflows and CI/CD tools such as GitLab CI, Jenkins, or ArgoCD.
  • Relevant certifications such as HashiCorp Certified Vault Associate, Certified Kubernetes Administrator (CKA), or AWS Certified DevOps Engineer.
What You Can Expect:

A culture of integrity.

At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose - to ensure the safety of our nation.

An environment of trust.

CACI values the unique contributions that every employee brings to our company and our customers - every day. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.

A focus on continuous growth.

Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy.

Pay Range

There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.

The proposed salary range for this position is:

$85,800 - $180,200

CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or other protected characteristic.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud DevOps Engineer - Identity Management
Senior Cloud DevOps Engineer - Identity Management

CACI International Inc • San Antonio (TX)

On-site
USD 85,000 - 181,000
Senior Cloud DevOps Engineer - Identity Management San Antonio, TX, US
Senior Cloud DevOps Engineer - Identity Management San Antonio, TX, US

CACI International Inc. • San Antonio (TX)

On-site
USD 85,000 - 181,000
DevOps Engineer, Senior Chantilly, VA, US
DevOps Engineer, Senior Chantilly, VA, US

CACI International Inc. • Chantilly (VA), Northern (KY)

Hybrid
USD 113,000 - 238,000
DevSecOps Engineer
DevSecOps Engineer

CACI International Inc • King of Prussia (PA)

On-site
USD 69,000 - 142,000
DevSecOps Engineer
DevSecOps Engineer

CACI International • Town of Aurora (NY)

On-site
USD 69,000 - 142,000
Sr. DevSecOps Engineer
Sr. DevSecOps Engineer

CACI • Fairfax (VA)

On-site
USD 98,000 - 207,000
Cloud Operations Administrator
Cloud Operations Administrator

CACI International Inc • Hampton (VA)

On-site
USD 75,000 - 158,000
Senior DevOps Engineer
Senior DevOps Engineer

CACI International Inc • Arlington (VA)

On-site
USD 113,000 - 238,000
DevOps Engineer - Junior
DevOps Engineer - Junior

CACI • Denver (CO)

On-site
USD 58,000 - 116,000
Infrastructure/Operations Engineer Aberdeen Proving Ground, MD, US
Infrastructure/Operations Engineer Aberdeen Proving Ground, MD, US

CACI International Inc. • Aberdeen (MD), Northern (KY)

Hybrid
USD 99,000 - 209,000