Senior Systems Engineer

GDH

Alexandria (VA)

Hybrid

USD 83,000 - 90,000

Full time

31 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid work schedule

Job summary

GDH is seeking a Senior Systems Engineer specializing in cross-cutting support and ICAM Enterprise Architecture to advance identity, credential, and access management initiatives. You will design, engineer, and implement secure identity-centric access across diverse enterprise architectures while guiding security posture and compliance with federal standards.

The role provides strategic technical leadership for enterprise identity systems, including SSO, PKI, MFA, and PAM, with a hybrid work

Qualifications

  • Active DoD 8570 IAT Level II certification or higher (e.g., Security+ CE, CySA+).
  • Federated identity protocols including SAML, OAuth, OIDC, and LDAP/Active Directory.
  • Hands-on experience with Smart Card/CAC authentication and PKI certificate validation.
  • Proven experience implementing NIST SP 800-207 Zero Trust principles within enterprise networks.
  • U.S. citizenship and eligibility for a U.S. Government security clearance.
  • Experience with RESTful API authorization protocols, secure gateways, and data schema security standards.

Responsibilities

  • Serve as the primary technical authority for enterprise identity management and access control frameworks.
  • Lead the modernization of legacy access controls into secure ICAM solutions.
  • Manage enterprise directories, federation, authentication, authorization, and single sign-on (SSO) protocols.
  • Architect identity lifecycles, user provisioning workflows, and privilege management controls.
  • Design and deploy Zero Trust identity principles based on NIST SP 800-207 across network hubs.
  • Configure and manage enterprise PKI systems, credentials, and authenticators.
  • Implement logical and physical access control systems, including MFA, SSO, and PAM.
  • Build federated identity services for secure interoperability with mission partners.
  • Conduct root cause analysis, privilege audits, and system performance tuning to optimize security posture.
  • Develop technical interfaces, architectures, data flows, and compliance documentation to support ICAM initiatives.
  • Own the overarching hybrid identity strategy and ensure interoperability across enterprise identity systems.

Job description

A Senior Systems Engineer specializing in Cross-Cutting Support and ICAM Enterprise Architecture is sought to support critical identity, credential, and access management enhancement initiatives. This technical position involves designing, engineering, and implementing secure, identity-centric access control frameworks across diverse enterprise architectures. The role provides strategic technical leadership for enterprise identity management systems, ensuring alignment with federal security standards and best practices.

Responsibilities
  • Serve as the primary technical authority for enterprise identity management and access control frameworks.
  • Lead the modernization of legacy access controls into secure ICAM solutions.
  • Manage enterprise directories, federation, authentication, authorization, and single sign-on (SSO) protocols.
  • Architect identity lifecycles, user provisioning workflows, and privilege management controls.
  • Design and deploy Zero Trust identity principles based on NIST SP 800-207 across network hubs.
  • Configure and manage enterprise PKI systems, credentials, and authenticators.
  • Implement logical and physical access control systems, including MFA, SSO, and privileged access management (PAM).
  • Build federated identity services for secure interoperability with mission partners.
  • Conduct root cause analysis, privilege audits, and system performance tuning to optimize security posture.
  • Develop technical interfaces, architectures, data flows, and compliance documentation to support ICAM initiatives.
  • Own the overarching hybrid identity strategy and ensure interoperability across enterprise identity systems.
Qualifications
  • High school diploma with 10+ years of relevant experience or equivalent technical background.
  • Active DoD 8570 IAT Level II certification or higher (e.g., Security+ CE, CySA+).
  • Extensive knowledge of federated identity protocols including SAML, OAuth, OIDC, and LDAP/Active Directory architecture.
  • Hands‑on experience managing Smart Card/CAC authentication and PKI certificate validation.
  • Proven expertise implementing NIST SP 800-207 Zero Trust principles within enterprise networks.
  • This position requires eligibility for a U.S. Government security clearance. In accordance with federal law, U.S. citizenship is required.
  • Strong understanding of enterprise identity tools and frameworks, including SailPoint, Okta, Microsoft Entra ID, or Ping Identity.
  • Familiarity with integrating data governance with ICAM solutions to enforce data access controls.
  • Experience with RESTful API authorization protocols, secure gateways, and data schema security standards.

Publishing Pay Range: $60.00 – $65.00 hourly
This position offers a hybrid schedule, with time split between the office and remote work.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior ICAM & Zero Trust Systems Architect (Hybrid)
Senior ICAM & Zero Trust Systems Architect (Hybrid)

GDH • Alexandria (VA)

Hybrid
USD 83,000 - 90,000
Hybrid work schedule
Senior ICAM Engineer
Senior ICAM Engineer

Leidos • United States

On-site
USD 131,300 - 237,350
Senior ICAM Identity Governance and Provisioning Engineer
Senior ICAM Identity Governance and Provisioning Engineer

Leidos • United States

On-site
USD 131,300 - 237,350
ICAM Architect
ICAM Architect

SAIC • Springfield (VA)

On-site
USD 120,001 - 160,000
Senior ICAM Engineer, Remote, United States
Senior ICAM Engineer, Remote, United States

Technologist, Inc. • Northern (KY)

Remote
USD 120,000 - 160,000
Health Care Plan
401k with employer match
Paid Time Off
+2
Senior Identity, Credential, and Access Management (ICAM) Security Engineer
Senior Identity, Credential, and Access Management (ICAM) Security Engineer

Ampcus, Inc • Washington

On-site
USD 100,000 - 130,000
SME Systems Engineer (Azure AD)
SME Systems Engineer (Azure AD)

GovCIO • Alexandria (VA)

On-site
USD 135,000 - 172,000
Azure Cloud Engineer – ICAM
Azure Cloud Engineer – ICAM

EdgeByte Solutions • Northern (KY)

Hybrid
USD 75,000 - 150,000
CMS- ICAM Policy Analyst
CMS- ICAM Policy Analyst

easy-dynamics-corporation • United States

On-site
USD 120,000 - 135,000
Sr ICAM Engineer
Sr ICAM Engineer

Easy Dynamics Corp • McLean (VA)

On-site
USD 144,000 - 176,000