Zero Trust ICAM & PKI SME

General Dynamics Information Technology

Tampa (FL)

On-site

USD 130,000 - 173,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

General Dynamics Information Technology seeks a seasoned Zero Trust ICAM & PKI SME to advance identity-centric security across USCENTCOM networks. You will lead engineering, deployment, and operational integration of identity management, credentialing, and access control solutions, aligned with DISA and DoD Zero Trust architectures.

The role demands 10+ years in enterprise IT/cybersecurity, DoD certifications, and US citizenship, with ongoing collaboration across cross-functional teams to

Qualifications

  • 10+ years of related engineering and operations experience.
  • U.S. Citizenship required.
  • DoD 8140 / DoD 8570 IAT Level II/III or IAM Level II/III certification.
  • Active Secret clearance with ability to obtain Top Secret/SCI (as applicable)

Responsibilities

  • Design, implement, and operate enterprise ICAM and PKI infrastructures across DoD environments.
  • Lead identity management derivations including MUR, AD, and automated provisioning pipelines.
  • Configure and harden PKI components (CAs, RAs, OCSP, HSMs) and manage certificate lifecycle processes.
  • Oversee access governance, PAM deployments, and SSO integrations to enforce Zero Trust principles.

Skills

Access Management
Credentialing
Identity Management
PKI Certificate Management

Education

Bachelor's Degree

Job description

Type of Requisition

Regular Clearance Level Must Currently Possess: Secret Clearance Level Must Be Able to Obtain: Top Secret/SCI Public Trust/Other Required: None

Job Family

IT Infrastructure and Operations

Job Qualifications

Skills: Access Management, Credentialing, Identity Management (IdM), PKI Certificate Management

Certifications: None

Experience: 10 + years of related experience

US Citizenship Required: Yes

Job Description

Advance how our customers operate while you advance your career. Join GDIT as a Zero Trust ICAM & PKI SME and build an impactful career in enterprise IT, collaborating with people who are driven and resourceful like you.

MEANINGFUL WORK AND PERSONAL IMPACT As a Zero Trust ICAM & PKI SME, the work you do at GDIT will be impactful to the mission of supporting infrastructure security on the CITS contract for USCENTCOM. You will play a crucial role in leading the engineering, deployment, and operational integration of identity-centric, credentialing, and access control solutions across USCENTCOM’s network enclaves, aligned with DoD Zero Trust principles.

How a Zero Trust ICAM & PKI SME will make an impact
  1. Identity Management (Identity Lifecycle & Directory Services)
    • Design, implement, and maintain enterprise Identity Management solutions, prioritizing DISA’s enterprise solution to ensure seamless integration with Zero Trust architectures.
    • Architect and manage Master User Records (MUR), directory services (e.q., Active Directory), and Automated Account Provisioning (AAP) pipelines.
    • Troubleshoot complex identity synchronization, profile mapping, and lifecycle workflows across heterogeneous enclaves and mission partners.
    • Build, deploy, and maintain identity connectors and integrations with enterprise HR/authoritative data sources and cloud environments.
    • Maintain system documentation, data dictionaries, and SOPs for identity lifecycle management tasks.
  2. Credentialing & PKI (Authenticators, Non-Person Entities & Cryptography)
    • Design, engineer, and operate enterprise Public Key Infrastructure (PKI) solutions aligned with DoD/NSS PKI standards, CNSSP-1300, and CJCSM requirements.
    • Configure, harden, and maintain Certification Authorities (CAs), Registration Authorities (RAs), Validation Authorities (OCSP), and Hardware Security Modules (HSMs).
    • Architect and operationalize enterprise Certificate Lifecycle Management (CLM) processes, automating certificate issuance, renewal, and revocation across web servers, endpoints, and secure communication channels.
    • Implement Network Device Enrollment and automated Non-Person Entity (NPE) credentialing utilizing protocols such as SCEP, EST, and ACME.
    • Lead PKI-enablement for enterprise applications, network appliances, and workloads to enforce mutual TLS (mTLS) and smart-card/phishing-resistant MFA (CAC/PIV, hardware tokens).
    • Maintain disaster recovery, business continuity, and key recovery/custody plans for cryptographic infrastructure.
  3. Access Management & Governance (Authorization, Federation & PAM)
    • Configure, enforce, and optimize fine-grained access control models, including Role-Based (RBAC), Attribute-Based (ABAC), Policy-Based (PBAC), and Identity-Based Access Control (IBAC).
    • Lead the deployment and operational administration of Privileged Access Management (PAM) platforms (e.g., Delinea) to safeguard privileged accounts and enforce just-in-time access.
    • Implement Identity Governance and Administration (IGA) solutions (e.g., SailPoint) for access certifications, segregation of duties (SoD), and role mining.
    • Troubleshoot complex federation and Single Sign-On (SSO) integrations utilizing modern protocols (SAML 2.0, OAuth 2.0, OIDC).
    • Collaborate with multi-disciplinary cybersecurity teams to enforce continuous authentication and dynamic authorization in line with Zero Trust principles.
Cross-Pillar Operations & Compliance

Perform regular maintenance, vulnerability scanning, security STIG remediation, and patching across all ICAM and PKI server environments.

Ensure strict adherence to DoD ICAM policies, DISA STIGs, FIPS cryptographic benchmarks, and DoD Zero Trust reference architectures.

Interface with third-party vendors (e.g., F5, Microsoft, SailPoint, Delinea, Keyfactor, Thales) for tier-3/escalated troubleshooting.

Produce management reports, audit metrics, compliance packages, and system administration runbooks.

What You'll Need to Succeed

Clearance: Active Secret Citizenship: U.S. Citizenship required Education: Bachelor's Degree in a related discipline (Cybersecurity or Information Assurance concentration preferred) or six (6) years of real-world or military experience in information assurance, network security, or systems administration.

Certification: Applicable DoD 8140 / DoD 8570 IAT Level II/III or IAM Level II/III Certification (e.g., Security+ CE, CASP+, CISSP) along with relevant role-based credentials (e.g., CIAM, CIGE, CIMP, Microsoft Certified: Identity and Access Administrator Associate, or Okta Certified Professional).

Experience: 10+ years of related engineering and operations experience in enterprise IT and cybersecurity.

Technical Competencies by Pillar
  1. Identity Management
    • 10+ years of experience in enterprise identity architectures and directory infrastructure (Active Directory, LDAP).
    • Deep understanding of Master User Records (MUR), Identity Governance & Administration (IGA platforms such as SailPoint), and automated provisioning workflows.
    • Familiarity with DISA enterprise identity solutions and federal identity federation models.
  2. Credentialing & PKI
    • In-depth expertise in Public Key Infrastructure (PKI) concepts: X.509 certificates, CA trust hierarchies, Certificate Revocation Lists (CRLs), and Online Certificate Status Protocol (OCSP).
    • Hands‑on engineering experience administering enterprise CA platforms (e.g., Microsoft AD CS, Keyfactor) and integrating with DoD/Federal PKI (FPKI).
    • Direct experience with Certificate Lifecycle Management (CLM) tools and automated enrollment protocols (SCEP, EST, ACME).
    • Experience with CAC/PIV middleware, hardware tokens, and Hardware Security Modules (HSMs) (e.g., Thales/SafeNet).
  3. Access Management & Governance
    • Advanced proficiency in designing and implementing access control models (RBAC, ABAC, PBAC, and IBAC).
    • Hands‑on experience configuring and managing Privileged Access Management (PAM) suites (e.g., Delinea).
    • Strong understanding of modern authentication protocols and federation mechanisms (SAML 2.0, OAuth, OpenID Connect, Kerberos, mTLS).
    • Proven experience supporting Zero Trust policy enforcement points (PEP) and policy decision points (PDP).
Desired Skills & Qualifications
  • Microsoft Windows Hybrid Administrator or ITIL 4 Foundation Certification.
  • Operational familiarity with USCENTCOM mission networks, enclaves, and operating environments.
  • Scripting and automation proficiency (PowerShell, Python, or Bash) for automating identity provisioning and certificate management workflows.
  • Experience integrating mTLS and certificate validation within enterprise API gateways, microservices, and reverse proxies.
  • Proven ability to author system architecture documents, CONOPS, disaster recovery runbooks, and engineering implementation guides.
Travel Requirements

Required USCENTCOM remote location support of up to 10% Travel during the Year to OCONUS Locations

Company Overview

GDIT is a leading technology integrator solving our nation's most complex modernization and readiness challenges. We provide innovative technology solutions and services across Defense, Intelligence, Homeland Security, Federal Civilian, and Health markets. GDIT IS YOUR PLACE At GDIT, the mission is our purpose, and our people are at the center of everything we do.

Total Rewards at GDIT
  • Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match.
  • To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave.
  • To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available.
  • We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
Equal Opportunity Employer

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans Opportunity Owned From working with technologies like AI, cyber and cloud to careers in intelligence and health, we offer endless opportunities to apply your expertise to create a safer, smarter world.

Salary

The likely salary range for this position is $129,813 - $172,500. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Work Hours and Location

Scheduled Weekly Hours: 40 Travel Required: Less than 10% Telecommuting Options: Onsite Work Location: USA FL MacDill AFB Additional Work Locations:

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Zero Trust ICAM & PKI SME
Zero Trust ICAM & PKI SME

General Dynamics IT • United States

On-site
USD 140,000 - 190,000
ICAM Systems Engineer & Manager
ICAM Systems Engineer & Manager

General Dynamics Corporation • Town of Florida (NY), Northern (KY)

Hybrid
USD 113,000 - 132,000
ICAM Systems Engineer & Manager
ICAM Systems Engineer & Manager

General Dynamics Information Technology • Tampa (FL)

On-site
USD 113,000 - 132,000
401(k) plan
Paid time off
Disability benefits
+1
Systems Administrator (Compliance)
Systems Administrator (Compliance)

General Dynamics Information Technology • Tampa (FL)

On-site
USD 89,000 - 121,000
401K match
Paid time off
Health benefits
+1
Compliance Systems Administrator
Compliance Systems Administrator

General Dynamics Corporation • Town of Florida (NY), Northern (KY)

Hybrid
USD 89,000 - 121,000
Systems Engineer
Systems Engineer

General Dynamics Information Technology • Tampa (FL)

On-site
USD 94,000 - 127,000
Platform / Software Engineer
Platform / Software Engineer

General Dynamics Information Technology • Tampa (FL)

On-site
USD 109,000 - 147,000
401K with company match
Health and wellness packages
Paid vacation and holidays
+1
Systems Engineer
Systems Engineer

General Dynamics Corporation • Town of Florida (NY), Northern (KY)

Hybrid
USD 94,000 - 127,000
Platform / Software Engineer, Senior
Platform / Software Engineer, Senior

General Dynamics Information Technology • Tampa (FL)

On-site
USD 119,000 - 161,000
401K with company match
Health and wellness packages
Paid vacation and holidays
Information Security Analyst Principal
Information Security Analyst Principal

General Dynamics Information Technology • Hawaii

On-site
USD 108,000 - 140,000