Senior ICAM Engineer

Leidos LLC

Fort Meade (MD)

On-site

USD 131,000 - 237,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Leidos is hiring for an ICAM engineering leader to plan and execute integration activities across senior leadership, customers, and operations teams. You will configure and sustain platforms like Okta, Ping Federate, SailPoint, and Keycloak, while advancing Zero Trust and FICAM-aligned architectures.

You will drive onboarding of diverse applications, troubleshoot authentication and authorization challenges, and guide teams in DevSecOps, IAM governance, and security controls across cloud,

Qualifications

  • BS degree required; 12+ years relevant experience or equivalent.
  • Hands-on experience with IdAM/ICAM delivery systems, authentication, authorization, and identity governance.
  • Experience integrating and troubleshooting enterprise identity providers and federation services.
  • Proficient in SAML 2.0, OIDC, OAuth 2.0, SCIM, REST APIs, PKI, MFA, and token-based authentication.

Responsibilities

  • Plan and execute ICAM engineering and integration activities using Agile methodologies.
  • Lead configuration, integration, troubleshooting, and sustainment of ICAM platforms.
  • Onboard legacy, cloud-native, SaaS, mission, and coalition applications into enterprise ICAM services.
  • Troubleshoot federation, authentication, claims mapping, token transformation, and access control issues.

Skills

Leadership
Agile
Communication
Problem solving
Mentoring

Education

BS degree

Tools

Okta
Ping Federate
SailPoint
Delinea
Radiant Logic
HashiCorp
Keycloak
Microsoft Entra ID
CAC/PIV, MFA tooling

Job description

Primary Responsibilities

Work with senior leadership, customers, application owners, security teams, mission partners, and operations personnel to plan and execute ICAM engineering and integration activities using Agile methodologies. Lead hands‑on configuration, integration, troubleshooting, and sustainment of ICAM platforms including Okta, Ping Federate, SailPoint, Delinea, Radiant Logic, HashiCorp, Corsha, Keycloak, Microsoft Entra ID, and related identity and access management technologies. Implement and maintain authentication, authorization, federation, identity governance, privileged access management, and application onboarding capabilities supporting Zero Trust and FICAM-aligned enterprise architectures. Lead integration and onboarding of legacy, cloud-native, SaaS, mission, and coalition applications into enterprise ICAM services. Troubleshoot federation, authentication, claims mapping, token transformation, provisioning, entitlement, and access control issues across enterprise and mission environments. Develop and maintain implementation procedures, onboarding standards, deployment documentation, operational engineering practices, and sustainment processes supporting ICAM delivery. Configure and integrate SAML 2.0, OIDC, OAuth 2.0, SCIM, REST APIs, PKI, CAC/PIV, MFA, and passwordless authentication technologies. Support implementation of RBAC, ABAC, context‑aware access control, device posture validation, and risk‑based authentication capabilities. Implement and maintain DevSecOps pipelines, infrastructure‑as‑code, deployment automation, and configuration management processes supporting ICAM services. Support integration of ICAM services across cloud, enterprise, hybrid, and multi‑domain mission environments including AWS, GovCloud, IL5/IL6, and classified systems where applicable. Provide hands‑on engineering support during testing, deployment, operational transition, incident response, troubleshooting, and production sustainment activities. Develop and present integration artifacts, implementation plans, deployment procedures, technical briefings, and operational status updates to internal and external stakeholders. Guide engineering teams in implementing scalable, secure, and operationally sustainable ICAM capabilities aligned to mission objectives. Serve as the technical lead for ICAM engineering, federation integration, application onboarding, and operational delivery activities while mentoring junior engineers. Recognized as a trusted technical leader for enterprise ICAM modernization, Zero Trust implementation, and mission integration.

Required Qualifications

Active DoD Secret Clearance or higher. Typically requires BS degree and 12+ years relevant experience. Additional experience may be considered in lieu of degree. Experience with IdAM / ICAM delivery systems, authentication, authorization, federated identity management, identity governance, entitlement management, privileged access management, attributes, and digital policy management. Hands‑on experience integrating and troubleshooting enterprise identity providers, federation services, MFA platforms, provisioning systems, and application onboarding solutions. Experience configuring and supporting SAML 2.0, OIDC, OAuth 2.0, SCIM, REST APIs, CAC/PIV, PKI, MFA, token‑based authentication, and claims transformation technologies. Experience with security accreditation processes and implementation of identity‑related security controls supporting DoD environments. Experience architecting, implementing, and sustaining enterprise cloud‑hosted ICAM services within AWS or comparable cloud environments using infrastructure‑as‑code and automation concepts. Understanding of Zero Trust architecture, federation, RBAC, ABAC, risk‑based authentication, context‑aware access, and cloud‑native security principles. Experience supporting application onboarding and federation integration across enterprise, cloud, mission, and coalition environments. Experience interacting with cross‑functional teams including Software Development, Systems Engineering, Security, Operations, Compliance, Verification and Validation, and Quality Assurance. Experience working in Agile, SAFe, or Scrum environments using DevSecOps and CI/CD technologies such as Git, Jenkins, Docker, Azure DevOps, Puppet, Terraform, and Confluence. Knowledge of software configuration management lifecycle deliverables, operational sustainment processes, and deployment management practices. Excellent oral and written communication skills.

Required Certification(s)

One or more DoD 8140.01 Level III Certifications Active Computing Environment certification relevant to job duties such as AWS Cloud, Microsoft Cloud, Okta, Ping Identity, SailPoint, Microsoft Entra ID, or related ICAM platform certifications.

Desired Qualifications

Minimum of one AWS Associate‑level certification such as AWS Certified Solutions Architect Associate, AWS Certified Developer Associate, or AWS Certified SysOps Administrator Associate. Experience supporting C2S, DoD cloud, GovCloud, IL5/IL6, or classified mission environments. Experience implementing CloudFormation, Terraform, serverless architectures, and cloud‑native deployment patterns. Experience integrating legacy, COTS, SaaS, cloud‑native, financial management, and mission applications into enterprise ICAM services. Experience supporting large‑scale ICAM modernization, application migration, and federation onboarding initiatives. Experience with API security, secrets management, certificate lifecycle management, claims transformation, and token exchange capabilities. Familiarity with NIST 800‑53, NIST 800‑63, DoD Zero Trust guidance, and FICAM architectures. TS/SCI eligible.

At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Original Posting: May 22, 2026. For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range: Pay Range $131,300.00 - $237,350.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Leidos Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $17.2 billion for the fiscal year ended January 2, 2026. For more information, visit www.Leidos.com.

Pay and Benefits Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here.

Securing Your Data Leidos will never ask you to provide payment‑related information at any part of the employment application process. And Leidos will communicate with you only through emails that are sent from a Leidos.com email address. If you receive an email purporting to be from Leidos that asks for payment‑related information or any other personal information, please report the email to spam.leidos@leidos.com.

Commitment and Diversity All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior ICAM Federation and App Integration Engineer
Senior ICAM Federation and App Integration Engineer

Leidos LLC • Fort Meade (MD)

On-site
USD 131,000 - 237,000
Health and Wellness programs
Income Protection
Paid Leave
+1
Senior ICAM Identity Governance and Provisioning Engineer
Senior ICAM Identity Governance and Provisioning Engineer

Leidos LLC • Fort Meade (MD)

On-site
USD 131,000 - 237,000
Health and Wellness programs
Paid leave and retirement
Senior AD/ICAM Administrator
Senior AD/ICAM Administrator

Leidos LLC • United States

Remote
USD 131,000 - 237,000
ICAM Security Engineer
ICAM Security Engineer

Leidos Inc • Egg Harbor Township (NJ)

On-site
USD 87,000 - 157,000
Principal IAM-Zero Trust Solutions Architect
Principal IAM-Zero Trust Solutions Architect

Leidos LLC • Fort Meade (MD)

On-site
USD 154,000 - 278,000
Systems Engineer Expert
Systems Engineer Expert

Leidos LLC • Chantilly (VA)

On-site
USD 131,000 - 237,000
ICAM Security Engineer
ICAM Security Engineer

Leidos • Eagan (MN)

Hybrid
USD 87,000 - 157,000
Hybrid work model
ICAM Security Engineer
ICAM Security Engineer

Via Logic LLC • Egg Harbor Township (NJ)

On-site
USD 87,000 - 157,000
Lead Identity and Access Management (ICAM) Engineer
Lead Identity and Access Management (ICAM) Engineer

Leidos LLC • Rockville (MD)

On-site
USD 131,000 - 237,000
Health and Wellness programs
Paid Leave
Retirement benefits
ICAM Engineering Support Staff 24x7
ICAM Engineering Support Staff 24x7

Leidos • Hanover (MD)

On-site
USD 87,100 - 157,450
Paid Time Off
401K with 6% company match
Flexible Schedules
+2