> Markdown version of [/jobs/ext/1422483-senior-icam-federation-and-app-integration-engineer](https://www.wearedevelopers.com/jobs/ext/1422483-senior-icam-federation-and-app-integration-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior ICAM Federation and App Integration Engineer - **Company:** Leidos, Inc. - **Location:** Fort Meade, MD, United States - **Experience:** Expert - **Salary:** $131,300.0 - $237,350.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Agile Methodology, Amazon Web Services, Application Integration Architecture, User Authentication, Software as a Service, Cloud Computing, Cloud Engineering, System Configuration, Continuous Integration, Custom Software, Multi-Factor Authentication, Federated Identity Management, Identity and Access Management, Key Management, OAuth, OpenID, Ping (Networking Utility), Public Key Infrastructure, Role-Based Access Control, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Service Design, Single Sign-On, Systems Integration, Enterprise Application Integration, Enterprise Software Applications, Cloud Platform System, Okta, Software Security, Deployment Automation, Hashicorp, Api Design, SailPoint - **Published:** July 24, 2026 - **Apply:** https://dejobs.org/x/x/B0F0486D8EBC48069508C1ED06584263/job/ ## About the Role * Active DoD Secret Clearance or higher. * Typically requires BS degree and 12+ years relevant experience.Additionalexperience may be considered in lieu of degree. * Experience with IdAM / ICAM delivery systems, enterprise identity providers, SSO, authentication and authorization services, federated identity management, claims engineering, access management APIs, entitlement management, and digital policy management. * Experience with security accreditation processes and identity-related security control implementation. * Experience supporting cloud-hosted identity services, enterprise application integration, and AWS or comparable cloud environments. * Experience with SAML 2.0, OIDC, OAuth 2.0, FIDO2/WebAuthn, CAC/PIV, PKI, MFA, step-up authentication, and token-based access control concepts. * Understanding of context-aware access, RBAC, ABAC, device posture, network context, and risk-based authentication principles. * Experience integrating enterprise applications using federation protocols, APIs, claims transformation, and identity provider technologies. * Excellent oral and written communication skills., * Active Computing Environmental certification (CE) in job-related duties such as Okta, Ping Identity, Microsoft Entra ID,F5,Keycloak, or related ICAM platform certification, * Minimum of one identity provider, federation, cloud, or security certification such as Okta, Ping Identity, Microsoft Entra ID, AWS Associate, CISSP, or equivalent * 5+ years of Commercial Cloud Services (C2S), DoD cloud, or classified mission environment experience * Experience integrating legacy, COTS, SaaS, cloud-native,financial management, and custom applications with enterprise ICAM services * Experience designing and implementing configurable MFA, step-up authentication, non-CAC authentication, self-service, and mission partner access patterns * Experience with API security, policy enforcement points, claims transformation, token exchange, secrets management, and certificate lifecycle considerations * Managing complex Sponsor relationships and requirements gathering across enterprise,component, application owner, and operations communities * Experience migrating applications from local authentication or legacy SSO to enterprise identity provider and federation services * Injecting detailed technical direction into teams for adoption of federation, application onboarding, CI/CD, and operational integration practices * TS/SCI eligible ## Description Serves as a senior technical engineer for ICAM federation, application onboarding, authentication, authorization, and integration services; designing, configuring, integrating, testing, and sustaining enterprise identity provider, single sign-on, multifactor authentication, claims, token, and API-based access management capabilities across DoD enterprise, cloud, mission, and legacy applications; supporting Zero Trust and FICAM-aligned ICAM services; and ensuring compliance with DoD, NIST, and Intelligence Community standards and frameworks., * Work with senior leadership, customers, application owners, security teams, mission partners, and operations teams to plan and execute ICAM federation and application onboarding activities using Agile methodologies. * Integrate Okta, Ping Federate, Radiant Logic, Microsoft Entra ID,Keycloak, ForgeRock, SailPoint,Delinea,HashiCorp, and related ICAM platforms with enterprise and mission applications. * Assess current application authentication and access management architectures; analyze alternatives and implement federation and onboarding solutions that accelerate integration with enterprise ICAM services. * Develop and present federation designs, claims mappings, integration artifacts, test plans, technical briefings, and application onboarding demonstrations. * Evaluate emerging federation and authentication technologies and guide engineering teams in implementing scalable, secure, and mission-aligned SSO, MFA, API integration, and application onboarding solutions. * Develop service design procedures and technical recommendations for application integration, claims release, federation protocols, MFA, API security, deployment automation, and operational handoff. * Ensure engineering teams deliver effective SSO, federation, MFA, API integration, and onboarding capabilities supporting enterprise missionobjectives. * Support integration of enterprise identity providers and access management services across cloud, mission, and hybrid application environments. * Provide technical status updates and implementation risk assessments to internal and external stakeholders. * Serve as a technical lead for federation, identity provider, and application onboarding activities while mentoring junior engineers. * Prepare and present architecture diagrams, implementation plans, technical demonstrations, and integration briefings. * Recognized as a trusted technical leader for ICAM federation, single sign-on, multifactor authentication, and enterprise application integration. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [What Makes WeAreDevelopers World Congress Different From Every Other Tech Event?](https://www.wearedevelopers.com/magazine/701-what-makes-wearedevelopers-world-congress-different-from-every-other-tech-event) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)