AWS Cloud Security and ICAM Specialist

General Dynamics Information Technology
Indianapolis, United States of America
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 207K

Job location

Remote
Indianapolis, United States of America

Tech stack

Kubernetes Security
Microsoft Access
Adobe InDesign
API
Agile Methodologies
Amazon Web Services (AWS)
Software System Penetration Testing
Confluence
JIRA
User Authentication
Azure
Software as a Service
Cloud Computing
Computer Security
Information Systems
Federated Identity Management
Identity and Access Management
Information Security Management
Information Systems Security Architecture Professional
Network Security
Microsoft Visio
OAuth
OpenID
Public Key Infrastructure
Role-Based Access Control
Power BI
Azure
Zero Trust Network Access
Security Assertion Markup Language (SAML)
SharePoint
Single Sign-On
Statistical Process Control (SPC)
Software Vulnerability Management
Datadog
SSL Certificate Management
Data Logging
Okta
Cyberark
Apigee
Customer Identity Access Management
Containerization
Pingfederate
Infrastructure Automation Frameworks
Hashicorp
Api Gateway
SailPoint
Splunk
Devsecops
Api Management
ELK
Microservices

Job description

The AWS Cloud Security and ICAM Specialist supports the Case Management Modernization (CMM) Program for the Administrative Office of the U.S. Courts (AO) by designing, implementing, and managing secure authentication and authorization frameworks across modernized cloud-based applications. This role ensures compliance with federal identity governance, FedRAMP, and Zero Trust Architecture (ZTA) principles within an AWS environment. The ICAM Specialist collaborates with architecture, security, and DevSecOps teams to ensure access control, identity federation, and credential management are integrated seamlessly across all layers of the CMM application ecosystem., * Design and maintain the ICAM architecture for identity, access, and authentication management across AWS-hosted CMM applications and other legacy ICAM

  • Implement federated identity and single sign-on (SSO) solutions using modern protocols (SAML, OAuth2.0, OIDC)
  • Collaborate with Cloud and Security Architects to enforce Zero Trust Architecture (ZTA) across microservices and APIs
  • Configure and maintain directory services and identity providers (e.g., AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify , Key Cloak)
  • Deep experience integrating KeyCloak as a broker IdP federating upstream enterprise IdPs while issuing downstream OIDC token to application
  • Design ICAM brokerage solutions and support compliance assessments, ensuring adherence to FISMA, NIST 800-63, and FedRAMP security controls
  • Develop and document identity lifecycle management processes-provisioning, deprovisioning, and access reviews
  • Design and implement least privileged roles, groups, functionalities based on ZTA for both privileged and non-privileged users for a FedRAMP High system
  • Experience defining workflow, rules, policies within ICAM tools particularly IBM Verify and Key Cloak
  • Conduct access audits, user entitlement reviews, and anomaly detection to ensure least-privilege compliance
  • Provide subject matter expertise in identity federation, PKI, certificate management, and secure API authorization
  • Design strategies for logging, monitoring and auditing authentication and authorization related events in combination with other AWS event logs
  • Design and implement storage level, microservice level Authentication and Authorization
  • Support ATO process by providing solutions to all security controls, document implementation plan, maintain Visio diagrams
  • Participate in design sessions and work closely with the security lead
  • Collaborate with DevSecOps teams to embed ICAM policies within CI/CD pipelines and Infrastructure-as-Code (IaC) templates
  • Direct and lead Pen testing, Review architecture diagrams produced by different teams
  • Independently lead design and implement of vulnerability management
  • Heavily participate in ATO activity
  • Lead and direct engineering team

Deliverable Alignment & Performance Outcomes:

  • Architecture Diagrams: Depicting identity flow, federation, and integration points with AWS and CMM systems
  • Access Control Documentation: Policies, RBAC models, and credential management workflows
  • Compliance Verification Reports: Audit results aligned to NIST 800-63, FedRAMP, and FISMA standards
  • Zero Trust Implementation Artifacts: Documentation and verification of ZTA enforcement within system components
  • Performance Outcomes:
  • 100% of CMM applications integrated with SSO and MFA.
  • Zero unauthorized access incidents attributable to configuration error
  • 100% compliance with NIST and FedRAMP ICAM control requirements Reduced account provisioning time by
  • 30% through automation

Tools & Technologies:

  • IAM & Federation: AWS Cognito, Azure AD, Okta, PingFederate
  • Access & Compliance: SailPoint, CyberArk, HashiCorp Vault
  • Cloud: AWS IAM, KMS, CloudTrail, Lambda
  • Protocols: SAML, OAuth2.0, OIDC, SCIM
  • Monitoring & Audit: ELK Stack, Splunk, Datadog, Power BI
  • Collaboration: Jira, Confluence, SharePoint, MS Teams

Requirements

Do you have experience in Zero Trust security?, Do you have a Bachelor's degree?, * Education: Bachelor's Degree in Cybersecurity, Information Systems, or related discipline required; Master's Degree preferred

  • Experience: 10+ years of experience in identity and access management, including 8+ years in cloud-based federal environments required; 12+ years of experience in information systems preferred
  • Strong knowledge of identity federation protocols (SAML, OAuth2.0, OIDC, SCIM) and modern authentication flows
  • Hands-on experience with AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify for SSO and MFA implementations
  • Expertise with RBAC/ABAC frameworks, policy-based access control, and least-privilege enforcement
  • Familiarity with NIST 800-63, FISMA, FedRAMP, and ZTA standards and compliance frameworks
  • Experience implementing ICAM solutions in Agile and DevSecOps environments
  • Working knowledge of PKI, digital certificates, and encryption technologies
  • Strong analytical and troubleshooting skills with ability to resolve identity integration issues
  • AWS Container security, Network security
  • Expert in designing logging and monitoring system by correlating events from several AWS and ICAM system
  • Experience supporting federal digital modernization or judiciary IT programs.
  • Expert level working experience with AWS services and integration of ICAM with containerized workloads (ECS, EKS)
  • Familiarity with Zero Trust Architecture and micro segmentation principles
  • Exposure to API gateway authentication (Kong, Apigee, AWS API Gateway).
  • Experience integrating identity governance tools (SailPoint, Saviynt).
  • Excellent presentation and communication skills
  • Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationship
  • Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies
  • Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement
  • Demonstrated ability to work effectively, independently, and as part of a team

Certification(s):

  • Certified Information Systems Security Professional (CISSP) - preferred
  • AWS Certified Security - Specialty or Azure Identity & Access Administrator - preferred
  • Certified Identity and Access Manager (CIAM) or Certified Identity Professional (CIP) - beneficial
  • SAFe Practitioner (SPC/SSM) - a plus

Security Clearance Level: Ability to pass a background check to obtain and maintain a position of Public Trust with the Administrative Office of the US Courts.

Must be a US Person (Green Card Holder, US Permanent Resident Alien, Refugee, Asylee, US Citizen)., Years of Experience 10 + years of related experience

  • may vary based on technical training, certification(s), or degree

Certification

Certified Information Systems Security Professional (CISSP) | International Information System Security Certification Consortium (ISC2) - International Information System Security Certification Consortium (ISC2) Travel Required Less than 10%

Benefits & conditions

(part of General Dynamics) 3.73.7 out of 5 stars Indiana Remote $153,000 - $207,000 a year, Pulled from the full job description

  • 401(k) matching
  • Paid time off
  • Internal mobility program, At GDIT, the mission is our purpose, and our people are at the center of everything we do.
  • Growth: AI-powered career tool that identifies career steps and learning opportunities
  • Support: An internal mobility team focused on helping you achieve your career goals
  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
  • Community: Award-winning culture of innovation and a military-friendly workplace, The likely salary range for this position is $153,000 - $207,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

About the company

We are GDIT. A global technology and professional services company that delivers technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across over 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, cloud, cyber and application development. Together with our customers, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology. Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc.

Apply for this position