Senior ICAM Identity Governance and Provisioning Engineer

Leidos LLC

Fort Meade (MD)

On-site

USD 131,000 - 237,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health and Wellness programs
Paid leave and retirement

Job summary

Leidos LLC is seeking a senior technical engineer to lead ICAM identity governance, automated provisioning, and Master User Record implementations across DoD enterprise, cloud, and legacy environments. You will design workflows, assess environments, and guide engineering teams in scalable, compliant solutions.

The role requires active DoD clearance and 12+ years of experience, with hands-on work across SailPoint, Okta, Saviynt, and related ICAM platforms.

Qualifications

  • Active DoD Secret Clearance or higher.
  • BS degree and 12+ years relevant experience.
  • Experience with IdAM/ICAM delivery and provisioning systems.
  • Experience integrating identity governance platforms with cloud/directories.
  • Understanding RBAC/ABAC and identity audit/compliance processes.
  • Experience in cloud-hosted and hybrid environments.
  • Cross-functional collaboration with software, security, and operations.
  • Excellent oral and written communication skills.

Responsibilities

  • Plan and execute ICAM governance and provisioning activities with stakeholders.
  • Integrate identity governance, provisioning, directory, and audit capabilities across platforms.
  • Assess environments and implement modernized identity lifecycle management solutions.
  • Develop workflow designs, provisioning rules, and access review materials.
  • Evaluate new identity tech and guide scalable, compliant implementations.
  • Develop procedures and recommendations for identity lifecycle management and data integration.
  • Ensure provisioning, de-provisioning, audit, and compliance capabilities meet enterprise needs.
  • Support cross-environment integration of provisioning across cloud and mission apps.
  • Provide status updates and risk assessments to stakeholders.
  • Serve as technical lead for identity governance and provisioning automation, mentoring junior engineers.

Skills

Security clearance
Oral and written communication

Education

Bachelor's degree

Tools

SailPoint
Radiant Logic
Okta
Saviynt
Delinea
ServiceNow
Microsoft Entra ID
Active Directory
LDAP
SCIM
REST
SQL

Job description

Serves as a senior technical engineer for ICAM identity governance, automated account provisioning, entitlement management, and Master User Record capabilities; designing, configuring, integrating, and sustaining identity lifecycle workflows, role and attribute models, access certification, audit reporting, and identity data synchronization across DoD enterprise, cloud, mission, and legacy environments; supporting Zero Trust and FICAM-aligned ICAM services; and ensuring compliance with DoD, NIST, and Intelligence Community standards and frameworks.

Primary Responsibilities
  • Work with senior leadership, customers, application owners, and mission partners to plan and execute ICAM governance and provisioning activities using Agile methodologies.
  • Integrate identity governance, provisioning, directory, and audit capabilities across platforms such as SailPoint, Radiant Logic, Okta, Saviynt, Delinea, ServiceNow, Microsoft Entra ID, Active Directory, LDAP, and related ICAM technologies.
  • Assess current identity governance, provisioning, directory, and entitlement environments; analyze alternatives and implement solutions that modernize enterprise account lifecycle management and replace manual access request processes.
  • Develop and present workflow designs, integration artifacts, provisioning rules, access review materials, test plans, technical briefings, and demonstrations.
  • Evaluate emerging identity governance and provisioning technologies and guide engineering teams in implementing scalable, compliant, and mission-aligned solutions.
  • Develop service design procedures and technical recommendations for identity lifecycle management, delegated administration, access certification, entitlement management, and identity data integration.
  • Ensure engineering teams deliver efficient and effective identity governance, provisioning, de-provisioning, audit, and compliance capabilities supporting enterprise mission objectives.
  • Support integration of provisioning and entitlement services across cloud, enterprise directory, and mission application environments.
  • Provide technical status updates and implementation risk assessments to internal and external stakeholders.
  • Serve as a technical lead for identity governance, automated provisioning, and Master User Record implementation activities while mentoring junior engineers.
  • Prepare and present technical briefings, demonstrations, architecture diagrams, and implementation plans.
  • Recognized as a trusted technical leader for ICAM identity governance, entitlement management, and provisioning automation.
Required Qualifications
  • Active DoD Secret Clearance or higher.
  • Typically requires BS degree and 12+ years relevant experience. Additional experience may be considered in lieu of degree.
  • Experience with IdAM / ICAM delivery systems, identity governance, automated provisioning and de-provisioning, authentication, authorization, entitlement management, access certification, role engineering, and digital policy management.
  • Experience integrating identity governance platforms with cloud, enterprise directory, and mission application environments using APIs, SCIM, LDAP, Active Directory, REST, SQL, and workflow automation technologies.
  • Understanding of RBAC, ABAC, segregation of duties, privileged account auditing, identity data normalization, and identity-related audit/compliance processes supporting DoD accreditation requirements.
  • Experience supporting identity governance and provisioning services within cloud-hosted and hybrid enterprise environments.
  • Experience interacting with cross-functional teams including Software Development, Systems Engineering, Security, Compliance, Verification and Validation, Quality Assurance, and Operations.
  • Excellent oral and written communication skills.
Required Certification(s)
  • One or more DoD 8140.01 Level III Certifications
  • Active Computing Environmental certification (CE) in job-related duties such as SailPoint, Okta, Saviynt, Microsoft Entra ID, AWS Cloud, Microsoft Cloud, or related ICAM platform certification
Desired Qualifications
  • Experience supporting DoD ICAM, Zero Trust, or FICAM initiatives.
  • Experience implementing SailPoint, Saviynt, Okta Identity Governance, or equivalent IGA platforms.
  • Experience supporting Master User Record (MUR), enterprise entitlement reporting, or insider threat analytics capabilities.
  • Experience integrating legacy applications into enterprise identity governance and provisioning architectures.
  • Experience supporting IL5/IL6, GovCloud, C2S, or classified cloud environments.
  • Familiarity with NIST 800-53, NIST 800-63, NIST 800-162, and DoD Zero Trust guidance.
  • TS/SCI eligible.
Pay Range

Pay Range: $131,300.00 - $237,350.00. The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary.

Pay and Benefits
  • Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement.
  • Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers.
Commitment and Diversity

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Company Culture

At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior ICAM Engineer
Senior ICAM Engineer

Leidos LLC • Fort Meade (MD)

On-site
USD 131,000 - 237,000
Senior ICAM Federation and App Integration Engineer
Senior ICAM Federation and App Integration Engineer

Leidos LLC • Fort Meade (MD)

On-site
USD 131,000 - 237,000
Health and Wellness programs
Income Protection
Paid Leave
+1
ICAM Security Engineer
ICAM Security Engineer

Leidos Inc • Egg Harbor Township (NJ)

On-site
USD 87,000 - 157,000
Senior AD/ICAM Administrator
Senior AD/ICAM Administrator

Leidos LLC • United States

Remote
USD 131,000 - 237,000
Lead Identity and Access Management (ICAM) Engineer
Lead Identity and Access Management (ICAM) Engineer

Leidos LLC • Rockville (MD)

On-site
USD 131,000 - 237,000
Health and Wellness programs
Paid Leave
Retirement benefits
ICAM Security Engineer
ICAM Security Engineer

Leidos • Eagan (MN)

Hybrid
USD 87,000 - 157,000
Hybrid work model
Principal IAM-Zero Trust Solutions Architect
Principal IAM-Zero Trust Solutions Architect

Leidos Inc • Odenton (MD)

On-site
USD 168,000 - 278,000
Senior AD/ICAM Administrator
Senior AD/ICAM Administrator

Leidos • Virginia (MN)

On-site
USD 142,000 - 237,000
ICAM Security Engineer
ICAM Security Engineer

Via Logic LLC • Egg Harbor Township (NJ)

On-site
USD 87,000 - 157,000
ICAM Security Engineer
ICAM Security Engineer

Leidos Inc • Eagan (MN)

On-site
USD 87,000 - 157,000