Senior ICAM Engineer

Leidos

United States

On-site

USD 131,300 - 237,350

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Leidos is seeking a hands-on technical ICAM Engineering Lead to drive integration, onboarding, and operational delivery across enterprise, cloud, coalition, and mission environments. You will lead the implementation and modernization of Zero Trust identity and access management, including authentication, authorization, and privileged access management, aligned to DoD and NIST standards.

You will guide teams through platform integration, federation engineering, claims transformation, and

Qualifications

  • Active DoD Secret Clearance or higher.
  • BS degree and 12+ years relevant experience; equivalent experience considered.
  • Experience with IdAM/ICAM delivery systems and identity governance.
  • Hands-on integration of enterprise identity providers and federation services.
  • Experience configuring SAML 2.0, OIDC, OAuth 2.0, SCIM, REST APIs, MFA.

Responsibilities

  • Plan and execute ICAM engineering and integration activities using Agile methodologies.
  • Lead hands-on configuration, integration, and sustainment of ICAM platforms (Okta, Ping Federate, SailPoint, etc.).
  • Implement authentication, authorization, federation, and identity governance capabilities.
  • Lead onboarding of legacy, cloud-native, SaaS, and mission applications into ICAM services.
  • Troubleshoot federation, authentication, token transformation, provisioning, and access control issues.

Skills

Leadership
SAFeScrum
Agile
CI/CD
Communication

Education

BS degree

Tools

Git
Jenkins
Docker
Terraform
Azure DevOps

Job description

Overview

Hands-on technical lead for ICAM engineering, integration, onboarding, and operational delivery across enterprise, cloud, coalition, and mission environments. Leads the implementation, configuration, troubleshooting, sustainment, and modernization of Zero Trust identity and access management services including authentication, authorization, federation, identity governance, privileged access management, and enterprise application integration aligned to DoD, FICAM, NIST, and Intelligence Community standards.

Drives technical execution across the full ICAM lifecycle, including platform integration, application onboarding, federation engineering, claims transformation, provisioning automation, deployment automation, operational transition, and production sustainment. Supports enterprise ICAM modernization efforts across cloud-hosted, hybrid, multi-domain, and mission partner environments.

Primary Responsibilities
  • Work with senior leadership, customers, application owners, security teams, mission partners, and operations personnel to plan and execute ICAM engineering and integration activities using Agile methodologies.
  • Lead hands-on configuration, integration, troubleshooting, and sustainment of ICAM platforms including Okta, Ping Federate, SailPoint, Delinea, Radiant Logic, HashiCorp, Corsha, Keycloak, Microsoft Entra ID, and related identity and access management technologies.
  • Implement and maintain authentication, authorization, federation, identity governance, privileged access management, and application onboarding capabilities supporting Zero Trust and FICAM-aligned enterprise architectures.
  • Lead integration and onboarding of legacy, cloud-native, SaaS, mission, and coalition applications into enterprise ICAM services.
  • Troubleshoot federation, authentication, claims mapping, token transformation, provisioning, entitlement, and access control issues across enterprise and mission environments.
  • Develop and maintain implementation procedures, onboarding standards, deployment documentation, operational engineering practices, and sustainment processes supporting ICAM delivery.
  • Configure and integrate SAML 2.0, OIDC, OAuth 2.0, SCIM, REST APIs, PKI, CAC/PIV, MFA, and passwordless authentication technologies.
  • Support implementation of RBAC, ABAC, context-aware access control, device posture validation, and risk-based authentication capabilities.
  • Implement and maintain DevSecOps pipelines, infrastructure-as-code, deployment automation, and configuration management processes supporting ICAM services.
  • Support integration of ICAM services across cloud, enterprise, hybrid, and multi-domain mission environments including AWS, GovCloud, IL5/IL6, and classified systems where applicable.
  • Provide hands-on engineering support during testing, deployment, operational transition, incident response, troubleshooting, and production sustainment activities.
  • Develop and present integration artifacts, implementation plans, deployment procedures, technical briefings, and operational status updates to internal and external stakeholders.
  • Guide engineering teams in implementing scalable, secure, and operationally sustainable ICAM capabilities aligned to mission objectives.
  • Serve as the technical lead for ICAM engineering, federation integration, application onboarding, and operational delivery activities while mentoring junior engineers.
  • Recognized as a trusted technical leader for enterprise ICAM modernization, Zero Trust implementation, and mission integration.
Required Qualifications
  • Active DoD Secret Clearance or higher.
  • Typically requires BS degree and 12+ years relevant experience. Additional experience may be considered in lieu of degree.
  • Experience with IdAM / ICAM delivery systems, authentication, authorization, federated identity management, identity governance, entitlement management, privileged access management, attributes, and digital policy management.
  • Hands-on experience integrating and troubleshooting enterprise identity providers, federation services, MFA platforms, provisioning systems, and application onboarding solutions.
  • Experience configuring and supporting SAML 2.0, OIDC, OAuth 2.0, SCIM, REST APIs, CAC/PIV, PKI, MFA, token-based authentication, and claims transformation technologies.
  • Experience with security accreditation processes and implementation of identity-related security controls supporting DoD environments.
  • Experience architecting, implementing, and sustaining enterprise cloud-hosted ICAM services within AWS or comparable cloud environments using infrastructure-as-code and automation concepts.
  • Understanding of Zero Trust architecture, federation, RBAC, ABAC, risk-based authentication, context-aware access, and cloud-native security principles.
  • Experience supporting application onboarding and federation integration across enterprise, cloud, mission, and coalition environments.
  • Experience interacting with cross-functional teams including Software Development, Systems Engineering, Security, Operations, Compliance, Verification and Validation, and Quality Assurance.
  • Experience working in Agile, SAFe, or Scrum environments using DevSecOps and CI/CD technologies such as Git, Jenkins, Docker, Azure DevOps, Puppet, Terraform, and Confluence.
  • Knowledge of software configuration management lifecycle deliverables, operational sustainment processes, and deployment management practices.
  • Excellent oral and written communication skills.
Required Certification(s)
  • One or more DoD 8140.01 Level III Certifications
  • Active Computing Environment certification relevant to job duties such as AWS Cloud, Microsoft Cloud, Okta, Ping Identity, SailPoint, Microsoft Entra ID, or related ICAM platform certifications.
Desired Qualifications
  • Minimum of one AWS Associate-level certification such as AWS Certified Solutions Architect Associate, AWS Certified Developer Associate, or AWS Certified SysOps Administrator Associate.
  • Experience supporting C2S, DoD cloud, GovCloud, IL5/IL6, or classified mission environments.
  • Experience implementing CloudFormation, Terraform, serverless architectures, and cloud-native deployment patterns.
  • Experience integrating legacy, COTS, SaaS, cloud-native, financial management, and mission applications into enterprise ICAM services.
  • Experience supporting large-scale ICAM modernization, application migration, and federation onboarding initiatives.
  • Experience with API security, secrets management, certificate lifecycle management, claims transformation, and token exchange capabilities.
  • Familiarity with NIST 800-53, NIST 800-63, DoD Zero Trust guidance, and FICAM architectures.
  • TS/SCI eligible.

Pay Range: $131,300.00 - $237,350.00

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior ICAM Identity Governance and Provisioning Engineer
Senior ICAM Identity Governance and Provisioning Engineer

Leidos • United States

On-site
USD 131,000 - 238,000
ICAM Architect
ICAM Architect

SAIC • Springfield (VA)

On-site
USD 120,000 - 160,000
Senior ICAM Federation and App Integration Engineer
Senior ICAM Federation and App Integration Engineer

Leidos Inc • Fort Meade (MD)

On-site
USD 150,000 - 190,000
Senior ICAM Federation and App Integration Engineer
Senior ICAM Federation and App Integration Engineer

Leidos • United States

On-site
USD 140,000 - 190,000
Senior ICAM Identity Governance and Provisioning Engineer
Senior ICAM Identity Governance and Provisioning Engineer

Via Logic LLC • Reston (VA)

On-site
USD 100,000 - 130,000
ICAM Engineer – Identity, Credential, and Access Management
ICAM Engineer – Identity, Credential, and Access Management

RMantra Solutions • Alexandria (VA), Northern (KY)

Hybrid
USD 140,000 - 190,000
Senior ICAM Federation and App Integration Engineer
Senior ICAM Federation and App Integration Engineer

Via Logic LLC • Reston (VA)

On-site
USD 120,000 - 150,000
Senior Identity, Credential, and Access Management (ICAM) Security Engineer
Senior Identity, Credential, and Access Management (ICAM) Security Engineer

Ampcus Inc • Washington

On-site
USD 100,000 - 130,000
Identity, Credential, and Access Management (ICAM) Analyst
Identity, Credential, and Access Management (ICAM) Analyst

Jobless • Arlington (TX), Northern (KY)

Hybrid
USD 170,000 - 250,000
ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services
ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services

General Dynamics - IT • Virginia (IL)

Hybrid
USD 180,000 - 250,000