Trust and Identity Engineer

COHESION FORCE INC
Huntsville, AL, United States
about 1 month ago
Apply on www.cohesionforce.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Active Directory Application Programming Interfaces (APIs) Artificial Intelligence Continuous Integration Distributed Systems Python (Programming Language) Lightweight Directory Access Protocols (LDAP) OAuth OpenShift Windows PowerShell Role-Based Access Control Openid Connect
+13 more
Azure Active Directory Security Assertion Markup Language (SAML) Systems Integration Policy as Code Data Logging Scripting Okta Istio SC Clearance Git Flow Kubernetes Infrastructure Automation Frameworks Information Technology

Job description

CohesionForce is actively seeking candidates for a Trust and Identify Engineer to become part of our team in Huntsville, AL. This individual will design, implement, and support identity and access capabilities for users, applications, services, workloads, and AI-enabled systems. The engineer will work across platform, software, reliability, and customer teams to provide secure authentication, federation, authorization, credential management, and auditable access., Integrate Microsoft Entra ID, Active Directory, and other customer identity providers using OAuth 2.0, OpenID Connect, SAML, and LDAP-based technologies.

  • Configure and support identity providers and authentication proxies such as Keycloak, oauth2-proxy, or equivalent products.
  • Define stable claims, groups, roles, and application onboarding patterns.
  • Design identity for Kubernetes workloads, services, automation, and AI agents using service accounts, short-lived tokens, service principals, certificates, or workload identity federation.
  • Implement least-privilege access using RBAC, ABAC, policy as code, and centralized authorization services.
  • Establish issuance, delivery, rotation, revocation, and recovery procedures for secrets, keys, tokens, and certificates.
  • Automate identity configuration and validation using APIs, scripting, infrastructure as code, GitOps, and CI-CD.
  • Troubleshoot login, token, claim, session, certificate, federation, and authorization issues across distributed systems.
  • Define identity-related logging and tracing requirements and work with reliability engineers to support monitoring and incident resonse.
  • Develop architecture documentation, integration guides, test procedures, runbooks, and customer handoff material.

Requirements

Bachelor’s degree in an engineering, computer science, cybersecurity, infommation technology or a related discipline, or equivalent experience and combined education, with 5-10 years of experience, or relevant professional experience.

  • Production experience with OAuth 2.0, OpenID Connect, JWTs, federation, token lifecycle, and secure application onboarding.
  • Experience integrating Active Director, Microsoft Entra ID, LDAP, SAML, or comparible enterprise identity systems.
  • Experience with Kubernetes or OpenShift service accounts, RBAC, secrets, ingress, or service-mesh identity.
  • Experience implementing identity for non-human services, workloads, or automation.
  • Experience with fine-grained authorization, policy as code, API scopes, or external authorization services.
  • Ability to automate configuration and testing with Python, PowerShell, or comparable language.
  • Works well in a fast=paces collaborative team environment.
  • Must be willing to work onsite in a closed/classified area.
  • Active Department of Defense (DoD) Secret clearance., Experience operating Keycloak or another self-hosted identity provider in Kubernetes.
  • Experience with Microsoft Entra workload identity, managed identities, or service-principal governance.
  • Experience with OPA, Envoy, Istio, SPIFFE/SPIRE, or comparable technogies.
  • Experience with OpenBao, Vault, External Secrets, cert-manager, or enterprise certificate-management systems.
  • Experience applying identity and delegated authorization to AI agents and tool integrations.
  • Experience using OpenTelemetry for attributable activity and security-event diagnosis.
  • Strong oral and written communication skills.
  • Strong interpersonal and collaboration skills.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.cohesionforce.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · World Congress 2026 Europe

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

7:15 min

Installing Istio programmatically with bash scripts

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all