Senior ICAM Federation and App Integration Engineer

Leidos LLC

Fort Meade (MD)

On-site

USD 131,000 - 237,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health and Wellness programs
Income Protection
Paid Leave
Retirement

Job summary

Leidos is seeking a senior ICAM architect to lead federation and application onboarding initiatives in a DoD/ICAM environment. You will integrate Okta, Ping Federate, Microsoft Entra ID, Keycloak, ForgeRock, SailPoint, Delinea, HashiCorp and related platforms with enterprise and mission applications, delivering scalable SSO, MFA, and API security solutions.

As technical lead, you will mentor junior engineers, develop architecture diagrams, provide demonstrations, and present technical briefings

Qualifications

  • Active DoD Secret Clearance or higher; BS degree and 12+ years experience.
  • Experience with IdAM/ICAM delivery systems, SSO, federation, APIs, and security controls.
  • Experience with cloud-hosted identity services and security certifications.

Responsibilities

  • Plan and execute ICAM federation and application onboarding using Agile.
  • Integrate major ICAM platforms with enterprise and mission apps.
  • Develop federation designs, test plans, resources, and onboarding demonstrations.
  • Mentor junior engineers and lead federation activities.
  • Provide risk assessments and architecture diagrams to stakeholders.

Skills

ICAM federation
SSO
MFA
Identity provider
Security architecture

Education

BS degree

Tools

Okta
Ping Federate
Radiant Logic
Microsoft Entra ID
Keycloak
ForgeRock
SailPoint
Delinea
HashiCorp

Job description

Primary Responsibilities

Work with senior leadership, customers, application owners, security teams, mission partners, and operations teams to plan and execute ICAM federation and application onboarding activities using Agile methodologies. Integrate Okta, Ping Federate, Radiant Logic, Microsoft Entra ID, Keycloak, ForgeRock, SailPoint, Delinea, HashiCorp, and related ICAM platforms with enterprise and mission applications. Assess current application authentication and access management architectures; analyze alternatives and implement federation and onboarding solutions that accelerate integration with enterprise ICAM services. Develop and present federation designs, claims mappings, integration artifacts, test plans, technical briefings, and application onboarding demonstrations. Evaluate emerging federation and authentication technologies and guide engineering teams in implementing scalable, secure, and mission-aligned SSO, MFA, API integration, and application onboarding solutions. Develop service design procedures and technical recommendations for application integration, claims release, federation protocols, MFA, API security, deployment automation, and operational handoff. Ensure engineering teams deliver effective SSO, federation, MFA, API integration, and onboarding capabilities supporting enterprise mission objectives. Support integration of enterprise identity providers and access management services across cloud, mission, and hybrid application environments. Provide technical status updates and implementation risk assessments to internal and external stakeholders. Serve as a technical lead for federation, identity provider, and application onboarding activities while mentoring junior engineers. Prepare and present architecture diagrams, implementation plans, technical demonstrations, and integration briefings. Recognized as a trusted technical leader for ICAM federation, single sign-on, multifactor authentication, and enterprise application integration.

Required Qualifications

Active DoD Secret Clearance or higher. Typically requires BS degree and 12+ years relevant experience. Additional experience may be considered in lieu of degree. Experience with IdAM / ICAM delivery systems, enterprise identity providers, SSO, authentication and authorization services, federated identity management, claims engineering, access management APIs, entitlement management, and digital policy management. Experience with security accreditation processes and identity-related security control implementation. Experience supporting cloud-hosted identity services, enterprise application integration, and AWS or comparable cloud environments. Experience with SAML 2.0, OIDC, OAuth 2.0, FIDO2/WebAuthn, CAC/PIV, PKI, MFA, step-up authentication, and token-based access control concepts. Understanding of context-aware access, RBAC, ABAC, device posture, network context, and risk-based authentication principles. Experience integrating enterprise applications using federation protocols, APIs, claims transformation, and identity provider technologies. Excellent oral and written communication skills. Required Certification(s): One or more DoD 8140.01 Level III Certifications Active Computing Environmental certification (CE) in job-related duties such as Okta, Ping Identity, Microsoft Entra ID, F5, Keycloak, or related ICAM platform certification.

Desired Qualifications

Minimum of one identity provider, federation, cloud, or security certification such as Okta, Ping Identity, Microsoft Entra ID, AWS Associate, CISSP, or equivalent 5+ years of Commercial Cloud Services (C2S), DoD cloud, or classified mission environment experience. Experience integrating legacy, COTS, SaaS, cloud-native, financial management, and custom applications with enterprise ICAM services. Experience designing and implementing configurable MFA, step-up authentication, non-CAC authentication, self-service, and mission partner access patterns. Experience with API security, policy enforcement points, claims transformation, token exchange, secrets management, and certificate lifecycle considerations. Managing complex Sponsor relationships and requirements gathering across enterprise, component, application owner, and operations communities. Experience migrating applications from local authentication or legacy SSO to enterprise identity provider and federation services. Injecting detailed technical direction into teams for adoption of federation, application onboarding, CI/CD, and operational integration practices. TS/SCI eligible.

TS/SCI eligible

TS/SCI eligible.

At Leidos

At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares. Leidos Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $17.2 billion for the fiscal year ended January 2, 2026. For more information, visit www.Leidos.com.

Original Posting

Original Posting: May 22, 2026. For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range

Pay Range: Pay Range $131,300.00 - $237,350.00. The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers.

  • Competitive compensation
  • Health and Wellness programs
  • Income Protection
  • Paid Leave
  • Retirement

More details are available here.

Securing Your Data

Leidos will never ask you to provide payment-related information at any part of the employment application process. And Leidos will communicate with you only through emails that are sent from a Leidos.com email address. If you receive an email purporting to be from Leidos that asks for payment-related information or any other personal information, please report the email to spam.leidos@leidos.com.

Commitment and Diversity

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior ICAM Engineer
Senior ICAM Engineer

Leidos LLC • Fort Meade (MD)

On-site
USD 131,000 - 237,000
Senior ICAM Identity Governance and Provisioning Engineer
Senior ICAM Identity Governance and Provisioning Engineer

Leidos LLC • Fort Meade (MD)

On-site
USD 131,000 - 237,000
Health and Wellness programs
Paid leave and retirement
ICAM Security Engineer
ICAM Security Engineer

Leidos Inc • Egg Harbor Township (NJ)

On-site
USD 87,000 - 157,000
Systems Engineer Expert
Systems Engineer Expert

Leidos LLC • Chantilly (VA)

On-site
USD 131,000 - 237,000
Senior AD/ICAM Administrator
Senior AD/ICAM Administrator

Leidos LLC • United States

Remote
USD 131,000 - 237,000
Lead Identity and Access Management (ICAM) Engineer
Lead Identity and Access Management (ICAM) Engineer

Leidos Inc • Rockville (MD)

On-site
USD 131,000 - 237,000
Senior Software Integration Engineer
Senior Software Integration Engineer

Leidos LLC • Chantilly (VA)

On-site
USD 108,000 - 195,000
Competitive compensation
Health and Wellness programs
Income Protection
+1
Staff Cyber Security Engineer
Staff Cyber Security Engineer

Via Logic LLC • Bethesda (MD)

On-site
USD 108,000 - 195,000
Paid Time Off
11 paid Holidays
401K with 6% company match
+4
Lead Identity and Access Management (ICAM) Engineer
Lead Identity and Access Management (ICAM) Engineer

Leidos LLC • Rockville (MD)

On-site
USD 131,000 - 237,000
Health and Wellness programs
Paid Leave
Retirement benefits
ICAM Security Engineer
ICAM Security Engineer

Via Logic LLC • Egg Harbor Township (NJ)

On-site
USD 87,000 - 157,000