Zero Trust ICAM & PKI SME

General Dynamics IT

United States

On-site

USD 140,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

General Dynamics IT is seeking a Zero Trust ICAM & PKI SME to advance mission-critical security for USCENTCOM. You will lead the engineering, deployment, and operational integration of identity-centric credentialing and access control solutions across enclaves in support of DoD Zero Trust.

You will design and operate PKI, manage CAs/RA/OCSP/HSMs, enable mTLS and CAC/PIV authentication, implement SSO, and ensure compliance with STIGs and DoD reference architectures while coordinating with

Qualifications

  • Active Secret clearance required.
  • U.S. citizenship required.
  • Bachelor's degree in cybersecurity or related field, or 6+ years of equivalent military/IA experience.
  • DoD 8140 / DoD 8570 IAT II/III or IAM II/III certification required.

Responsibilities

  • Design, engineer, and operate enterprise PKI solutions aligned with DoD/NSS PKI standards.
  • Configure, harden, and maintain Certification Authorities, Registration Authorities, Validation Authorities, and HSMs.
  • Architect and operationalize Certificate Lifecycle Management across web servers, endpoints, and secure channels.
  • Lead PKI-enablement for enterprise applications, network appliances, and workloads with mTLS and CAC/PIV authentication.
  • Interface with vendors for triage, create runbooks, and deliver audit metrics and compliance packages.

Skills

Access Management
Credentialing
Identity Management
PKI Certificate Management

Education

Bachelor's Degree in Cybersecurity or related field
6 years of related information assurance experience

Tools

Active Directory

Job description

Type of Requisition

Regular

Clearance Level Must Currently Possess

Secret

Clearance Level Must Be Able to Obtain

Top Secret/SCI

Public Trust/Other Required

None

Job Family

IT Infrastructure and Operations

Job Qualifications
  • Skills: Access Management, Credentialing, Identity Management (IdM), PKI Certificate Management
  • Certifications: None
  • Experience: 10 + years of related experience
  • US Citizenship Required: Yes
Job Description

Advance how our customers operate while you advance your career. Join GDIT as a Zero Trust ICAM & PKI SME and build an impactful career in enterprise IT, collaborating with people who are driven and resourceful like you.

MEANINGFUL WORK AND PERSONAL IMPACT

As a Zero Trust ICAM & PKI SME , the work you do at GDIT will be impactful to the mission of supporting infrastructure security on the CITS contract for USCENTCOM. You will play a crucial role in leading the engineering, deployment, and operational integration of identity-centric, credentialing, and access control solutions across USCENTCOM's network enclaves, aligned with DoD Zero Trust principles.

HOW A ZERO TRUST ICAM & PKI SME WILL MAKE AN IMPACT

Your responsibilities span across the three core ICAM pillars:

Identity Management (Identity Lifecycle & Directory Services)
  • Design, implement, and maintain enterprise Identity Management solutions, prioritizing DISA's enterprise solution to ensure seamless integration with Zero Trust architectures.
  • Architect and manage Master User Records (MUR), directory services (e.q., Active Directory), and Automated Account Provisioning (AAP) pipelines.
  • Troubleshoot complex identity synchronization, profile mapping, and lifecycle workflows across heterogeneous enclaves and mission partners.
  • Build, deploy, and maintain identity connectors and integrations with enterprise HR/authoritative data sources and cloud environments.
  • Maintain system documentation, data dictionaries, and SOPs for identity lifecycle management tasks.
Credentialing & PKI (Authenticators, Non-Person Entities & Cryptography)
  • Design, engineer, and operate enterprise Public Key Infrastructure (PKI) solutions aligned with DoD/NSS PKI standards, CNSSP-1300, and CJCSM requirements.
  • Configure, harden, and maintain Certification Authorities (CAs), Registration Authorities (RAs), Validation Authorities (OCSP), and Hardware Security Modules (HSMs).
  • Architect and operationalize enterprise Certificate Lifecycle Management (CLM) processes, automating certificate issuance, renewal, and revocation across web servers, endpoints, and secure communication channels.
  • Implement Network Device Enrollment and automated Non-Person Entity (NPE) credentialing utilizing protocols such as SCEP, EST, and ACME.
  • Lead PKI-enablement for enterprise applications, network appliances, and workloads to enforce mutual TLS (mTLS) and smart-card/phishing-resistant MFA (CAC/PIV, hardware tokens).
  • Maintain disaster recovery, business continuity, and key recovery/custody plans for cryptographic infrastructure.
Access Management & Governance (Authorization, Federation & PAM)
  • Configure, enforce, and optimize fine-grained access control models, including Role-Based (RBAC), Attribute-Based (ABAC), Policy-Based (PBAC), and Identity-Based Access Control (IBAC).
  • Lead the deployment and operational administration of Privileged Access Management (PAM) platforms (e.g., Delinea) to safeguard privileged accounts and enforce just-in-time access.
  • Implement Identity Governance and Administration (IGA) solutions (e.g., SailPoint) for access certifications, segregation of duties (SoD), and role mining.
  • Troubleshoot complex federation and Single Sign-On (SSO) integrations utilizing modern protocols (SAML 2.0, OAuth 2.0, OIDC).
  • Collaborate with multi-disciplinary cybersecurity teams to enforce continuous authentication and dynamic authorization in line with Zero Trust principles.
Cross-Pillar Operations & Compliance
  • Perform regular maintenance, vulnerability scanning, security STIG remediation, and patching across all ICAM and PKI server environments.
  • Ensure strict adherence to DoD ICAM policies, DISA STIGs, FIPS cryptographic benchmarks, and DoD Zero Trust reference architectures.
  • Interface with third-party vendors (e.g., F5, Microsoft, SailPoint, Delinea, Keyfactor, Thales) for tier-3/escalated troubleshooting.
  • Produce management reports, audit metrics, compliance packages, and system administration runbooks.
WHAT YOU'LL NEED TO SUCCEED

Bring your technology expertise and drive for innovation to GDIT. The Zero Trust ICAM & PKI SME must have:

  • Clearance: Active Secret
  • Citizenship: U.S. Citizenship required
  • Education: Bachelor's Degree in a related discipline (Cybersecurity or Information Assurance concentration preferred) or six (6) years of real-world or military experience in information assurance, network security, or systems administration.
  • Certification: Applicable DoD 8140 / DoD 8570 IAT Level II/III or IAM Level II/III Certification (e.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Zero Trust ICAM & PKI SME
Zero Trust ICAM & PKI SME

General Dynamics Information Technology • Tampa (FL)

On-site
USD 130,000 - 173,000
ICAM Systems Engineer & Manager
ICAM Systems Engineer & Manager

General Dynamics Information Technology • Tampa (FL)

On-site
USD 113,000 - 132,000
401(k) plan
Paid time off
Disability benefits
+1
ICAM Systems Engineer & Manager
ICAM Systems Engineer & Manager

General Dynamics Corporation • Town of Florida (NY), Northern (KY)

Hybrid
USD 113,000 - 132,000
Zero Trust ICAM & PKI SME for DoD Networks
Zero Trust ICAM & PKI SME for DoD Networks

General Dynamics Information Technology • Tampa (FL)

On-site
USD 130,000 - 173,000
Senior Zero Trust ICAM & PKI SME
Senior Zero Trust ICAM & PKI SME

General Dynamics IT • United States

On-site
USD 140,000 - 190,000
ICAM Identity Provider (IdP) Engineer Enterprise Authentication Services
ICAM Identity Provider (IdP) Engineer Enterprise Authentication Services

General Dynamics Information Technology • Fort Meade (MD)

On-site
USD 110,000 - 160,000
Senior ICAM Engineer
Senior ICAM Engineer

Leidos • United States

On-site
USD 131,000 - 238,000
Cloud PKI & ICAM Systems Engineer | Zero Trust
Cloud PKI & ICAM Systems Engineer | Zero Trust

GovCIO • Alexandria (VA)

Hybrid
USD 135,000 - 172,000
ICAM Identity Provider (IdP) Engineer - Enterprise Authentication Services
ICAM Identity Provider (IdP) Engineer - Enterprise Authentication Services

General Dynamics Corporation • Falls Church (VA), Northern (KY)

Hybrid
USD 170,000 - 230,000
PKI Systems Administrator - active Top Secret required
PKI Systems Administrator - active Top Secret required

General Dynamics Information Technology • Washington

On-site
USD 128,000 - 173,000