Senior IdAM Engineer IRES - SSFB/HSV/FBEL

Amentum company

Colorado Springs (CO)

On-site

USD 175,000 - 220,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health, dental, and vision insurance
401(k) matching
Educational reimbursement
Parental leave
Employee stock purchase plan
Disability and life insurance
Pet insurance

Job summary

Amentum is seeking a Senior IdAM Engineer to support the Next Generation Environment on the IRES contract. You will engineer, deploy, automate, secure, and sustain the IdAM/ICAM ecosystem underpinning the Missile Defense Agency’s digital environment across on-premises and cloud.

You will implement IGA workflows, SSO, directory integrations, PKI aligned with Zero Trust, and collaborate with government teams to ensure continuous, compliant identity services within DoD environments.

Responsibilities

  • Implement, deploy, configure, and sustain SailPoint IdentityIQ (IIQ) solutions with O&M and onboarding.
  • Design identity lifecycle workflows (joiner/mover/leaver), RBAC/ABAC, and compliance reporting.
  • Engineer, deploy, and maintain PingFederate SSO across enterprise apps.
  • Integrate Azure AD and AWS IAM in DoD IL5/IL6 boundaries.
  • Configure AD DS/AD FS and manage Kerberos, LDAP/S, and trust configurations.
  • Deploy DoD NSS PKI components including CAs and token integration.
  • Enforce zero-trust policies per NIST SP 800-207 and DISA RMF requirements.
  • Collaborate with multi-contractor teams for identity interfaces and integrations.
  • Develop automation scripts (PowerShell, Bash, Python, Java) for provisioning.
  • Create and maintain design docs, SOPs, and test plans.

Job description

Position Title: Senior IdAM Engineer

Location: Schriever Space Force Base, Colorado Springs, CO, Redstone Arsenal, Huntsville, AL or Fort Belvoir, VA

Relocation Assistance: None available at this time

Remote/Telework: NO - Not available for this position

Clearance Type: DoW Secret

Shift: Day shift

Travel Required: Up to 10% of the time

Description of Duties

As a Senior IdAM Engineer supporting the Next Generation Environment (NGE) on the Integrated Research and Development for Enterprise Solutions (IRES) contract, you will serve as a senior technical contributor responsible for engineering, deploying, automating, securing, and sustaining the Identity, Credential, and Access Management (IdAM / ICAM) ecosystem underpinning the Missile Defense Agency’s (MDA) unified digital environment.


In this role, you will help advance NGE’s hybrid and multi-cloud identity modernization strategy by implementing robust Identity Governance and Administration (IGA) workflows, federation and Single Sign-On (SSO) services, enterprise directory integrations, and DoD/NSS Public Key Infrastructure (PKI) aligned with the Zero Trust Security Model. You will work across engineering, cybersecurity, hybrid cloud, infrastructure, contract consortium performers, and Government stakeholder teams to deliver resilient identity services across on-premises and cloud-hosted mission environments.


You will play a key role in standardizing identity lifecycle automation, enhancing authentication security, eliminating credential risks, strengthening access controls, and ensuring continuous compliance with DoD, DISA, and MDA security requirements.


Description of Duties

Identity Governance & Administration (IGA)


  • Implement, deploy, configure, and sustain SailPoint IdentityIQ (IIQ) solutions, including Operations & Maintenance (O&M), platform upgrades, capability enhancements, and enterprise application onboarding.

  • Design and customize identity lifecycle management workflows (joiner, mover, leaver), certification campaigns, role-based/attribute-based access controls (RBAC/ABAC), custom Java rules, and compliance reporting.


Federation & Single Sign-On (SSO)


  • Engineer, deploy, and maintain PingIdentity PingFederate services to enable secure, federated Single Sign-On (SSO) across enterprise and mission partner applications.

  • Lead application onboarding and integration utilizing modern authentication and authorization protocols, including SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), and phishing-resistant Multi-Factor Authentication (MFA).


Hybrid Cloud Identity Integration


  • Implement and sustain secure identity and access architectures across hybrid multi-cloud environments, including Microsoft Entra ID (Azure AD) and Amazon Web Services (AWS IAM and AWS IAM Identity Center) operating within DoD IL5/IL6 boundaries.

  • Ensure secure synchronization, conditional access policy enforcement, and seamless identity interoperability between on-premises domains and cloud service providers.


Directory Services & Authentication


  • Configure, optimize, and administer Microsoft Directory Services, including Active Directory Domain Services (AD DS) and Active Directory Federation Services (AD FS), maintaining high availability and schema integrity.

  • Maintain Kerberos, LDAP/S, and federated trust configurations across complex multi-forest and segmented enterprise environments.


DoD & NSS Public Key Infrastructure (PKI)


  • Deploy, maintain, and support DoD and National Security Systems (NSS) Public Key Infrastructure (PKI) components, including Certificate Authorities (CAs), hardware tokens (CAC/PIV/SIPR tokens), Certificate Validation services (OCSP/CRL), and certificate lifecycle management.

  • Ensure cryptographic enforcement and certificate-based authentication across all network boundaries, endpoints, and server infrastructure.


Zero Trust Architecture & Security Compliance


  • Implement dynamic, identity-centric security policies and controls supporting the DoD Zero Trust Strategy and NIST SP 800-207.

  • Harden identity platforms and services in accordance with DISA STIGs, Risk Management Framework (RMF), and MDA cybersecurity requirements to support continuous Authorization to Operate (cATO).


Consortium & Cross-Functional Engineering Collaboration


  • Collaborate with multi-contractor consortium performers, systems engineers, network architects, DevSecOps teams, and Government personnel to standardize identity interfaces and integration protocols.

  • Serve as an identity integration focal point during Joint Interoperability Test events, cross-domain coordination, and enterprise cutovers.


Automation & Scripting


  • Develop and maintain automated provisioning scripts, API integrations (SCIM, REST), and administrative routines utilizing PowerShell, Bash, Python, or Java to streamline identity operations and eliminate manual configuration drift.


Documentation & Engineering Governance


  • Author and maintain comprehensive engineering deliverables, including Low-Level Designs (LLDs), Interface Control Documents (ICDs), standard operating procedures (SOPs), deployment runbooks, and test/validation plans.


Technology Evaluation & Continuous Improvement


  • Research and assess emerging IdAM/ICAM technologies, cloud identity features, and PAM/IGA enhancements to optimize security posture, scalability, and user experience across NGE.


Stakeholder Reporting & Technical Communication


  • Provide technical status, risk analysis, and engineering recommendations to program leadership and Government stakeholders.

  • Translate complex identity, PKI, and federation requirements into actionable engineering plans and mission outcomes.


Basic Requirements


  • Must have 12, or more, years of general (full-time) work experience

  • May be reduced with completion of advanced education

  • Must have 6, or more, years of dedicated Identity, Credential, and Access Management (IdAM / ICAM) experience.

  • Must have 1, or more, years of experience in technical leadership, mentoring, or engineering management roles.

  • Must have direct experience supporting the IRES contract or previous technical experience supporting the Missile Defense Agency (MDA).

  • Must have demonstrated, hands-on, engineering proficiency across enterprise identity solutions, specifically:

  • Must have a combination of experience, or familiarity, with the following:

  • SailPoint IdentityIQ (IIQ) (deployments, lifecycle workflows, rules, and connectors).

  • PingIdentity PingFederate (SAML, OAuth2, OIDC, MFA federation).

  • Microsoft Directory Services (AD DS, AD FS).

  • Cloud Identity Management (Microsoft Entra ID, AWS IAM).

  • DoD / NSS Public Key Infrastructure (PKI) (Certificate Authorities, validation, and token integration).

  • Must hold a current DoW 8140/8570 IAT Level II or higher certification (e.g., Security+ CE, CySA+, CASP+ CE, CISSP).

  • Must have an active DoW Secret security clearance with the ability to obtain a Top Secret clearance (or active Top Secret).

  • Must have an active DoW Secret Security Clearance


Desired Requirements


  • Have an active DoW Top Secret clearance.

  • Have a Bachelor’s degree, or higher, in Computer Science, Information Technology, or Cybersecurity.

  • Professional certifications in core tools:

  • SailPoint Certified IdentityIQ Engineer / Architect

  • Ping Identity Certified Professional

  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)

  • AWS Certified Security – Specialty

  • Have experience integrating identity solutions with Privileged Access Management (PAM) platforms (e.g., CyberArk) and enterprise ITSM systems (e.g., ServiceNow).

  • Have experience with Model-Based Systems Engineering (MBSE) concepts and Agile/SAFe methodologies within DoD/MDA environments.


Compensation Details

$175,000 – $220,000


The compensation range or hourly rate listed for this position is provided as a good-faith estimate of what the company intends to offer for this role at the time this posting was issued. Actual compensation may vary based on factors such as job responsibilities, education, experience, skills, internal equity, market data, applicable collective bargaining agreements, and relevant laws.


Benefits Overview


  • Health, dental, and vision insurance

  • Paid time off and holidays

  • Retirement benefits (including 401(k) matching)

  • Educational reimbursement

  • Parental leave

  • Employee stock purchase plan

  • Tax-saving options

  • Disability and life insurance

  • Pet insurance


Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O'Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.


Amentum is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, sex, sexual orientation, pregnancy (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, ancestry, United States military or veteran status, color, religion, creed, marital or domestic partner status, medical condition, genetic information, national origin, citizenship status, low-income status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law. Learn more about your rights under Federal laws and supplemental language at Labor Laws Posters.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior IdAM Engineer IRES - SSFB/HSV/FBEL
Senior IdAM Engineer IRES - SSFB/HSV/FBEL

Amentum • Huntsville (AL)

On-site
USD 175,000 - 220,000
Health insurance
Dental insurance
Vision insurance
+7
NGE – Platform Integration Engineer IRES - SSFB/HSV/FBEL
NGE – Platform Integration Engineer IRES - SSFB/HSV/FBEL

Amentum company • Colorado Springs (CO)

On-site
USD 160,000 - 200,000
Health, dental, and vision insurance
Paid time off and holidays
401(k) retirement matching
+6
IT Integration Manager IRES - SSFB/HSV
IT Integration Manager IRES - SSFB/HSV

Amentum company • Colorado Springs (CO)

On-site
USD 140,000 - 160,000
Senior DevSecOps Engineer IRES - SSFB/HSV/FBEL
Senior DevSecOps Engineer IRES - SSFB/HSV/FBEL

Amentum • Shreveport (LA)

On-site
USD 175,000 - 220,000
Health insurance
Dental and vision insurance
401(k) matching
+1
NGE – Platform Integration Engineer IRES - SSFB/HSV/FBEL
NGE – Platform Integration Engineer IRES - SSFB/HSV/FBEL

Amentum • Huntsville (AL)

On-site
USD 160,000 - 200,000
Health insurance
401(k) matching
Paid time off
NGE – Platform Integration Engineer IRES - SSFB/HSV/FBEL
NGE – Platform Integration Engineer IRES - SSFB/HSV/FBEL

Amentum • Colorado Springs (CO)

On-site
USD 160,000 - 200,000
Health, dental, and vision insurance
401(k) matching
Educational reimbursement
+5
Next Generation Environment (NGE) IT Digital Infrastructure Design IRES - SSFB/HSV
Next Generation Environment (NGE) IT Digital Infrastructure Design IRES - SSFB/HSV

Amentum • Huntsville (AL)

Hybrid
USD 100,000 - 225,000
Health insurance
401(k) matching
Paid time off
+3
Jr. Applications Engineer IRES - SSFB/HSV
Jr. Applications Engineer IRES - SSFB/HSV

Amentum company • Colorado Springs (CO)

On-site
USD 70,000 - 100,000
Health insurance
Paid time off
401(k) matching
+6
IT Integration Manager IRES - SSFB/HSV
IT Integration Manager IRES - SSFB/HSV

Amentum • Huntsville (AL)

On-site
USD 140,000 - 160,000
Health insurance
Paid time off
Retirement benefits (401k)
+6
Senior Network Architect IRES - SSFB/HSV
Senior Network Architect IRES - SSFB/HSV

Amentum • Shreveport (LA)

On-site
USD 155,000 - 175,000
Health, dental, vision insurance
401(k) matching
Educational reimbursement
+5