Senior ICAM Identity Governance and Provisioning Engineer

Leidos, Inc.
Fort Meade, MD, United States
20 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Compensation
$131,300.0 - $237,350.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory Application Programming Interfaces (APIs) Agile Methodology Amazon Web Services Systems Engineering Microsoft Online Services Cloud Computing System Configuration Data Integration Data Normalization Data Synchronization Identity and Access Management
+15 more
Lightweight Directory Access Protocols (LDAP) Role-Based Access Control Azure Active Directory Zero Trust Network Access Service Design Software Engineering Verification and Validation (Software) SQL Databases Systems Integration Cloud Platform System Okta Data Analytics SailPoint Restful APIs Servicenow

Job description

Serves as a senior technical engineer for ICAM identity governance, automated account provisioning, entitlement management, and Master User Record capabilities; designing, configuring, integrating, and sustaining identity lifecycle workflows, role and attribute models, access certification, audit reporting, and identity data synchronization across DoD enterprise, cloud, mission, and legacy environments; supporting Zero Trust and FICAM-aligned ICAM services; and ensuring compliance with DoD, NIST, and Intelligence Community standards and frameworks., * Work with senior leadership, customers, application owners, and mission partners to plan and execute ICAM governance and provisioning activities using Agile methodologies.

  • Integrate identity governance, provisioning, directory, and audit capabilities across platforms such as SailPoint,Radiant Logic,Okta, Saviynt,Delinea, ServiceNow, Microsoft Entra ID, Active Directory, LDAP, and related ICAM technologies.
  • Assess current identity governance, provisioning, directory, and entitlement environments; analyze alternatives and implement solutions that modernize enterprise account lifecycle management and replace manual access request processes.
  • Develop and present workflow designs, integration artifacts, provisioning rules, access review materials, test plans, technical briefings, and demonstrations.
  • Evaluate emerging identity governance and provisioning technologies and guide engineering teams in implementing scalable, compliant, and mission-aligned solutions.
  • Develop service design procedures and technical recommendations for identity lifecycle management, delegated administration, access certification, entitlement management, and identity data integration.
  • Ensure engineering teams deliver efficient and effective identity governance, provisioning, de-provisioning, audit, and compliance capabilities supporting enterprise missionobjectives.
  • Support integration of provisioning and entitlement services across cloud, enterprise directory, and mission application environments.
  • Provide technical status updates and implementation risk assessments to internal and external stakeholders.
  • Serve as a technical lead for identity governance, automated provisioning, and Master User Record implementation activities while mentoring junior engineers.
  • Prepare and present technical briefings, demonstrations, architecture diagrams, and implementation plans.
  • Recognizedas a trusted technical leader for ICAM identity governance, entitlement management, and provisioning automation.

Requirements

  • Active DoD Secret Clearance or higher.
  • Typically requires BS degree and 12+ years relevant experience.Additionalexperience may be considered in lieu of degree.
  • Experience with IdAM / ICAM delivery systems, identity governance, automated provisioning and de-provisioning, authentication, authorization, entitlement management, access certification, role engineering, and digital policy management.
  • Experience integrating identity governance platforms with cloud, enterprise directory, and mission application environments using APIs, SCIM, LDAP, Active Directory, REST, SQL, and workflow automation technologies.
  • Understanding of RBAC, ABAC, segregation of duties, privileged account auditing, identity data normalization, and identity-related audit/compliance processes supporting DoD accreditation requirements.
  • Experience supporting identity governance and provisioning services within cloud-hosted and hybrid enterprise environments.
  • Experience interacting with cross-functional teams including Software Development, Systems Engineering, Security, Compliance, Verification and Validation, Quality Assurance, and Operations.
  • Excellent oral and written communication skills., * Active Computing Environmental certification (CE) in job-related duties such as SailPoint, Okta, Saviynt, Microsoft Entra ID, AWS Cloud, Microsoft Cloud, or related ICAM platform certification, * Experience supporting DoD ICAM, Zero Trust, or FICAM initiatives.
  • Experience implementing SailPoint, Saviynt, Okta Identity Governance, or equivalent IGA platforms.
  • Experience supporting Master User Record (MUR), enterprise entitlement reporting, or insider threat analytics capabilities.
  • Experience integrating legacy applications into enterprise identity governance and provisioning architectures.
  • Experience supporting IL5/IL6, GovCloud, C2S, or classified cloud environments.
  • Familiarity with NIST 800-53, NIST 800-63, NIST 800-162, and DoD Zero Trust guidance.
  • TS/SCI eligible.

Benefits & conditions

Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits .

About the company

If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 - and moving faster than anyone else dares., Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:24 min

Securing cloud deployments by utilizing OpenID Connect mapping

Chris Ayers · LIVE

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · WWC 2025

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

Videos

See all

Related articles

See all