> Markdown version of [/jobs/ext/1505468-iam-lead](https://www.wearedevelopers.com/jobs/ext/1505468-iam-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Lead - **Company:** ICF Incorporated, L.L.C. - **Location:** Richmond, VA, United States - **Experience:** Expert - **Salary:** $108,006.0 - $183,610.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Application Programming Interfaces (APIs), Biometrics, Identity and Access Management, IP Addressing, Virtual Private Networks (VPN), OAuth, OpenID, Role-Based Access Control, Phishing, Zero Trust Network Access, Runbook, Security Assertion Markup Language (SAML), Single Sign-On, Okta, HR Software - **Published:** July 30, 2026 - **Apply:** https://dejobs.org/x/x/4CFC64BBE435459180AC1D27D84D92B0/job/ ## About the Role * Bachelor's degree or equivalent * 7+ years of experience in identity and access management engineering or a related discipline * 3+ years of hands-on experience designing and operating Entra ID or Okta in production environments, including conditional access, lifecycle management, and federation * 2+ years implementing PAM solutions and just-in-time elevation controls for privileged accounts * 2+ years configuring authorization models including RBAC, PBAC, or ABAC in enterprise environments * 2+ years supporting federal IT programs in HHS, NIH, FDA, or other health-focused agencies * U .S . Citizenship required due to federal contract requirements * Ability to obtain andmaintaina Public Trust background investigation * Candidate mustresidein the US,be authorized towork in the US, and work must be performed in the US, * Experience implementing NIST SP 800-63 identity assurance levels (IAL/AAL) in a federal context * Experience federating external identities using Entra External ID, including self-service registration and consent workflows * Familiarity with FISMA, NIST 800-53, and Zero Trust architecture requirements as they apply to identity and access * Experience integrating identity platforms with HR systems for automated joiner, mover, and leaver workflows * Relevant certifications such as Microsoft Certified: Identity and Access Administrator, Okta Certified Administrator, or equivalent * Experience supporting identity incident response including account takeover, phishing, and access abuse investigations ## Description ICF is seeking an IAM Lead to architect, implement, and operate the identity and access management platform for a federal technology program. Reporting to engineering leadership, this role is the subject matter authority on how users, devices, and applications authenticate and are authorized across a cloud-first, Zero Trust environment. The IAM Lead owns the full identity lifecycle, from onboarding automation to privileged access controls to external identity federation. The ideal candidate is a senior identity engineer who has built and operated IAM programs in federal cloud environments. This is a deeply technical role. The right candidate understands not just the tooling but the underlying standards, can implement NIST identity assurance requirements, and can hold their own with cybersecurity and enterprise architecture teams on access policy design. Job Location: This is a remote-friendly position with occasional onsite requirements in the Washington, DC Metro area. This position requires that the job be performed in the United States. If you accept this position, you should note that ICF does monitor employee work locations and blocks access from foreign locations/foreign IP addresses and also prohibits personal VPN connections. What You'll Be Doing * Architect, configure, andmaintainidentity platforms including Entra ID, Entra External ID, and Okta, covering authentication, authorization, provisioning, and lifecycle management across all users, applications, and devices. * Configure and enforce phishing-resistant authentication for all users, including passkeys, FIDO2 security keys,WebAuthn, and biometrics. Drive the transition away from legacy authentication methods toward a fullypasswordlessposture. * Define and implement Zero Trust access rules based on user risk, device health, location, and behavior using risk-based and conditional access policies. * Design, configure, andoperateauthorization models including RBAC, PBAC, and ABAC, with fine-grained permissions and attribute-based access rules aligned to job function and least-privilege principles. * Manage privileged accounts and administrative roles using privileged access management (PAM) and just-in-time elevation, ensuring that standing admin access isminimizedand all elevated access is logged and time-bound. * Build andmaintainHR-driven joiner, mover, and leaver automation, including automated provisioning, license assignment, role changes, access revocation, and data archival triggered by HR system events. * Federate external identities including partners, contractors, and external collaborators using Entra External ID or equivalent, including self-service registration,verificationworkflows, and consent management. * Configure identity proofing and verification to NIST IAL and AAL levels whererequired, coordinating with cybersecurity and compliance teams on assurance requirements. * Integrate applications and APIs with identity platforms using OIDC, OAuth2, SAML, and SCIM for single sign-on and automated provisioning. * Monitor sign-in activity, risk signals, and anomalies. Respond to identity-related incidents including account takeover, phishing, access abuse, and fraud in coordination with the cybersecurity team. * Maintain identity data quality and consistency across directories, HR systems, and applications, including synchronization, schema management, and attribute mapping. * Support compliance and audit activities by producing access reports, certifications, attestations, and evidence of controls. * Documentidentity architectures, configurations, standards, and runbooks. Provide guidance to application teams on how toonboard tocentral identity platforms and implement authentication best practices. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) - [Break the Chain: Decentralized solutions for today’s Web2.0 privacy problems](https://www.wearedevelopers.com/videos/928-break-the-chain-decentralized-solutions-for-today-s-web2-0-privacy-problems) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers)