SME Systems Engineer (ICAM Architect)

GovCIO

Alexandria (VA)

Hybrid

USD 135,000 - 172,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

GovCIO is seeking an experienced SME Systems Engineer focused on ICAM Enterprise Architecture to support U.S. Coast Guard modernization efforts. The role emphasizes secure identity-centric access management, Zero Trust, PKI, and cross-product coordination across legacy and modern systems.

Location is Alexandria, VA with a hybrid work schedule. You will serve as a technical authority, define enterprise identity frameworks, manage directories and SSO, and collaborate with DHS/USCG stakeholders to

Qualifications

  • High School with 10+ years (or commensurate experience).
  • DoD 8570 IAT Level II or higher or equivalent certifications.
  • Experience with federated identity concepts (SAML, OAuth, OIDC) and AD/LDAP architecture.
  • Hands-on PKI/authentication and CAC/SAM card familiarity.
  • Experience applying NIST SP 800-207 Zero Trust guidelines in enterprise networks.

Responsibilities

  • Serve as primary technical authority for enterprise identity management and access control framework.
  • Lead modernization of legacy access controls into ICAM solutions.
  • Manage directories, federation, authentication, SSO, and PAM configurations.
  • Architect identity lifecycles, provisioning workflows, and privilege management.
  • Design and deploy Zero Trust across network hubs and PKI systems.
  • Build federated identity services for secure interoperability with partners.
  • Develop interfaces, data flows, and compliance documentation.

Skills

DoD 8570 IAT Level II
Federated identity concepts
CAC/SAMRT authentication
NIST 800-207 Zero Trust

Education

High School with 10+ years experience

Tools

SailPoint
Okta
Microsoft Entra ID
Ping Identity
DigiCert
Power BI

Job description

Overview

GovCIO is currently hiring a highly experienced SME Systems Engineer specializing in Cross-Cutting Support Across All Product Lines with a primary focus on ICAM Enterprise Architecture. This technical role supports critical Identity, Credential, and Access Management (ICAM) modernization activities for the U.S. Coast Guard (USCG). This position focuses on designing, engineering, and executing secure, identity-centric access control frameworks across legacy and modern enterprise architectures. This position will be located in Alexandria, VA, and will be a hybrid position.

Overview

GovCIO is currently hiring a highly experienced SME Systems Engineer specializing in Cross-Cutting Support Across All Product Lines with a primary focus on ICAM Enterprise Architecture. This technical role supports critical Identity, Credential, and Access Management (ICAM) modernization activities for the U.S. Coast Guard (USCG). This position focuses on designing, engineering, and executing secure, identity-centric access control frameworks across legacy and modern enterprise architectures. This position will be located in Alexandria, VA, and will be a hybrid position.

Responsibilities

The SME Systems Engineer / ICAM Engineer will serve as a primary technical authority for the enterprise identity management and access control framework. Core responsibilities include:

  • Lead Modernize legacy access controls into robust, secure ICAM solutions.
  • Manage enterprise directories, federation, authentication, authorization, and SSO protocols.
  • Architect identity lifecycles, user provisioning workflows, and privilege management controls.
  • Design and deploy strict Zero Trust identity principles (NIST SP 800-207) across network hubs.
  • Configure and manage enterprise-grade PKI systems, credentials, and authenticators.
  • Implement logical and physical access control systems, including MFA, SSO, and PAM.
  • Build federated identity services to enable secure interoperability with mission partners.
  • Conduct technical root cause analysis, privilege audits, and system performance tuning.
  • Develop custom technical interfaces, architectures, data flows, and compliance documentation.
  • Provide advanced engineering and architecture ownership across the following specialization:
    • ICAM Enterprise Architecture (Primary Product Area: Cross-cutting support for all product lines): Serve as the chief technical architect for the consolidated ICAM enterprise. Own the overarching hybrid identity strategy, ensuring the on-premises Active Directory and the Entra ID tenant are designed to function to be a seamless, secure, and integrated system. Own the architectural design, placement, and lifecycle strategy for all Domain Controllers (DCs). Ensure that solutions designed by the other SMEs are interoperable and aligned with overall enterprise architecture standards. Lead the technical design for large-scale, cross-product initiatives and act as the primary technical liaison between the ICAM team and other enterprise architecture groups.
Qualifications

High School with 10+ years (or commensurate experience)

Required Skills & Experience
  • Certifications: DoD 8570 IAT Level II or higher (e.g., Security+ CE, CySA+, or vendor-specific identity certifications).
  • Deep technical understanding of federated identity concepts, including SAML, OAuth, OIDC, and Active Directory / LDAP architecture.
  • Hands-on engineering experience managing Smart Card / Common Access Card (CAC) authentication and PKI certificate validation.
  • Proven experience designing and applying federal Zero Trust identity guidelines (NIST SP 800-207) within enterprise networks.

Clearance Level: Must have an active Secret clearance

Preferred Skills & Experience
  • Prior experience supporting U.S. Coast Guard (USCG) or Department of Homeland Security (DHS) identity management programs.
  • Familiarity with integrating data governance frameworks with ICAM solutions to enforce data-level access controls.
  • Direct experience with enterprise identity tools such as SailPoint, Okta, Microsoft Entra ID, Ping Identity, DigiCert, or Power BI.
  • Advanced knowledge of RESTful API authorization protocols, secure gateways, and data schema security standards.

#JP #USCG #DICE

Posted Salary Range: USD $135,000.00 - USD $172,000.00 /Yr.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SME Systems Engineer (Azure AD)
SME Systems Engineer (Azure AD)

GovCIO • Alexandria (VA)

Hybrid
USD 135,000 - 172,000
SME Systems Engineer (Governance Analytics)
SME Systems Engineer (Governance Analytics)

GovCIO • Alexandria (VA)

Hybrid
USD 135,000 - 172,000
SME Systems Engineer (Cloud PKI)
SME Systems Engineer (Cloud PKI)

GovCIO • Alexandria (VA)

Hybrid
USD 135,000 - 172,000
SME Systems Engineer (Entra)
SME Systems Engineer (Entra)

GovCIO • Alexandria (VA)

Hybrid
USD 135,000 - 172,000
SME Systems Engineer (Power Platform)
SME Systems Engineer (Power Platform)

GovCIO • Alexandria (VA)

Hybrid
USD 135,000 - 172,000
SME Systems Engineer
SME Systems Engineer

GDH • Alexandria (VA)

Hybrid
USD 83,000 - 90,000
Hybrid work schedule
Senior ICAM Systems Engineer - Hybrid, Secret Clearance
Senior ICAM Systems Engineer - Hybrid, Secret Clearance

GovCIO • Alexandria (VA)

Hybrid
USD 135,000 - 172,000
Entra ICAM Systems Engineer (Hybrid, Secret)
Entra ICAM Systems Engineer (Hybrid, Secret)

GovCIO • Alexandria (VA)

Hybrid
USD 135,000 - 172,000
Senior Power Platform Identity Architect (Zero Trust, ICAM)
Senior Power Platform Identity Architect (Zero Trust, ICAM)

GovCIO • Alexandria (VA)

Hybrid
USD 135,000 - 172,000
ICAM Systems Engineer – Access Governance & Zero Trust
ICAM Systems Engineer – Access Governance & Zero Trust

GovCIO • Alexandria (VA)

Hybrid
USD 135,000 - 172,000