Type of Requisition
Regular
Clearance Level Must Currently Possess
Secret
Clearance Level Must Be Able to Obtain
Top Secret/SCI
Public Trust/Other Required
None
Job Family
IT Infrastructure and Operations
Job Qualifications
- Skills: Access Management, Credentialing, Identity Management (IdM), PKI Certificate Management
- Certifications: None
- Experience: 10 + years of related experience
- US Citizenship Required: Yes
Job Description
Advance how our customers operate while you advance your career. Join GDIT as a Zero Trust ICAM & PKI SME and build an impactful career in enterprise IT, collaborating with people who are driven and resourceful like you.
MEANINGFUL WORK AND PERSONAL IMPACT
As a Zero Trust ICAM & PKI SME , the work you do at GDIT will be impactful to the mission of supporting infrastructure security on the CITS contract for USCENTCOM. You will play a crucial role in leading the engineering, deployment, and operational integration of identity-centric, credentialing, and access control solutions across USCENTCOM's network enclaves, aligned with DoD Zero Trust principles.
HOW A ZERO TRUST ICAM & PKI SME WILL MAKE AN IMPACT
Your responsibilities span across the three core ICAM pillars:
Identity Management (Identity Lifecycle & Directory Services)
- Design, implement, and maintain enterprise Identity Management solutions, prioritizing DISA's enterprise solution to ensure seamless integration with Zero Trust architectures.
- Architect and manage Master User Records (MUR), directory services (e.q., Active Directory), and Automated Account Provisioning (AAP) pipelines.
- Troubleshoot complex identity synchronization, profile mapping, and lifecycle workflows across heterogeneous enclaves and mission partners.
- Build, deploy, and maintain identity connectors and integrations with enterprise HR/authoritative data sources and cloud environments.
- Maintain system documentation, data dictionaries, and SOPs for identity lifecycle management tasks.
Credentialing & PKI (Authenticators, Non-Person Entities & Cryptography)
- Design, engineer, and operate enterprise Public Key Infrastructure (PKI) solutions aligned with DoD/NSS PKI standards, CNSSP-1300, and CJCSM requirements.
- Configure, harden, and maintain Certification Authorities (CAs), Registration Authorities (RAs), Validation Authorities (OCSP), and Hardware Security Modules (HSMs).
- Architect and operationalize enterprise Certificate Lifecycle Management (CLM) processes, automating certificate issuance, renewal, and revocation across web servers, endpoints, and secure communication channels.
- Implement Network Device Enrollment and automated Non-Person Entity (NPE) credentialing utilizing protocols such as SCEP, EST, and ACME.
- Lead PKI-enablement for enterprise applications, network appliances, and workloads to enforce mutual TLS (mTLS) and smart-card/phishing-resistant MFA (CAC/PIV, hardware tokens).
- Maintain disaster recovery, business continuity, and key recovery/custody plans for cryptographic infrastructure.
Access Management & Governance (Authorization, Federation & PAM)
- Configure, enforce, and optimize fine-grained access control models, including Role-Based (RBAC), Attribute-Based (ABAC), Policy-Based (PBAC), and Identity-Based Access Control (IBAC).
- Lead the deployment and operational administration of Privileged Access Management (PAM) platforms (e.g., Delinea) to safeguard privileged accounts and enforce just-in-time access.
- Implement Identity Governance and Administration (IGA) solutions (e.g., SailPoint) for access certifications, segregation of duties (SoD), and role mining.
- Troubleshoot complex federation and Single Sign-On (SSO) integrations utilizing modern protocols (SAML 2.0, OAuth 2.0, OIDC).
- Collaborate with multi-disciplinary cybersecurity teams to enforce continuous authentication and dynamic authorization in line with Zero Trust principles.
Cross-Pillar Operations & Compliance
- Perform regular maintenance, vulnerability scanning, security STIG remediation, and patching across all ICAM and PKI server environments.
- Ensure strict adherence to DoD ICAM policies, DISA STIGs, FIPS cryptographic benchmarks, and DoD Zero Trust reference architectures.
- Interface with third-party vendors (e.g., F5, Microsoft, SailPoint, Delinea, Keyfactor, Thales) for tier-3/escalated troubleshooting.
- Produce management reports, audit metrics, compliance packages, and system administration runbooks.
WHAT YOU'LL NEED TO SUCCEED
Bring your technology expertise and drive for innovation to GDIT. The Zero Trust ICAM & PKI SME must have:
- Clearance: Active Secret
- Citizenship: U.S. Citizenship required
- Education: Bachelor's Degree in a related discipline (Cybersecurity or Information Assurance concentration preferred) or six (6) years of real-world or military experience in information assurance, network security, or systems administration.
- Certification: Applicable DoD 8140 / DoD 8570 IAT Level II/III or IAM Level II/III Certification (e.