> Markdown version of [/jobs/ext/1215871-icam-integration-engineer](https://www.wearedevelopers.com/jobs/ext/1215871-icam-integration-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ICAM Integration Engineer - **Company:** Makpar Corporation - **Location:** United States (Remote available) - **Contract:** Permanent contract - **Skills:** Application Integration Architecture, Identity and Access Management, OAuth, OpenID, Role-Based Access Control, Openid Connect, Single Sign-On, Data Logging, Enterprise Software Applications, Cloudwatch, Splunk, New Relic (SaaS), Servicenow - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=08537fe4f4abe527 ## About the Role * Experience with enterprise SSO and identity federation. * Experience with OAuth and OpenID Connect. * Experience with PIV-based authentication or certificate-backed authentication. * Experience implementing or supporting RBAC and/or ABAC. * Experience supporting application onboarding/integration across multiple environments. * Ability to troubleshoot identity, token, session, certificate, and access issues. * Ability to obtain favorable EOD / suitability and maintain required USCIS access. * U.S. citizenship likely required for DHS IT access unless waiver is granted - confirm before final posting., * Experience with Shibboleth IdP or similar identity provider platforms. * Experience with UAA, OAuth/OIDC token providers, LACS, ServiceNow, Splunk, New Relic, or CloudWatch. * Prior DHS, USCIS, or federal ICAM experience. * Experience supporting 100+ or 150+ application team environments. * Experience with automated access reviews, least privilege, and policy governance. ## Description Our Mission: We solve complex problems for the Federal government to accelerate access to citizen services. When it comes to excellence, we deliver. Learn more about our employer brand at makpar.com/careers. The ICAM Integration Engineer will support PIV-based authentication, SSO, OAuth/OIDC, application registration, authorization, and logical access control services for USCIS, DHS HQ, other government agencies, and GFE mobile users. The role is focused on helping application teams integrate securely with USCIS ICAM services and improving least privilege, RBAC/ABAC, and access governance. This role requires real identity integration experience. Generic cybersecurity experience is not enough., * Support PIV-based authentication and Single Sign-On for enterprise applications. * Register new applications for SSO across multiple environments. * Support major and minor enhancements requested by application teams. * Implement and maintain ABAC and RBAC capabilities during user SSO sessions. * Support least privilege enforcement, inactivity tracking, and just-in-time provisioning patterns. * Schedule and support rotation of credentials, keys, tokens, and certificates. * Troubleshoot SSO issues during and after application integration. * Support mobile authentication for GFE mobile devices. * Develop logging, safeguards, alerting, and dashboards for on-prem and cloud environments. * Create and maintain procedural documents, knowledge base articles, and training materials for users, system owners, requesters, and ServiceNow operators. * Develop automated access control audits and alerts. * Enhance dashboards using Splunk, New Relic, AWS CloudWatch, or similar data sources. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Un-complicate authorization maintenance](https://www.wearedevelopers.com/videos/889-un-complicate-authorization-maintenance) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)