Trust and Identity Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+13 more
Job description
CohesionForce is actively seeking candidates for a Trust and Identify Engineer to become part of our team in Huntsville, AL. This individual will design, implement, and support identity and access capabilities for users, applications, services, workloads, and AI-enabled systems. The engineer will work across platform, software, reliability, and customer teams to provide secure authentication, federation, authorization, credential management, and auditable access., Integrate Microsoft Entra ID, Active Directory, and other customer identity providers using OAuth 2.0, OpenID Connect, SAML, and LDAP-based technologies.
- Configure and support identity providers and authentication proxies such as Keycloak, oauth2-proxy, or equivalent products.
- Define stable claims, groups, roles, and application onboarding patterns.
- Design identity for Kubernetes workloads, services, automation, and AI agents using service accounts, short-lived tokens, service principals, certificates, or workload identity federation.
- Implement least-privilege access using RBAC, ABAC, policy as code, and centralized authorization services.
- Establish issuance, delivery, rotation, revocation, and recovery procedures for secrets, keys, tokens, and certificates.
- Automate identity configuration and validation using APIs, scripting, infrastructure as code, GitOps, and CI-CD.
- Troubleshoot login, token, claim, session, certificate, federation, and authorization issues across distributed systems.
- Define identity-related logging and tracing requirements and work with reliability engineers to support monitoring and incident resonse.
- Develop architecture documentation, integration guides, test procedures, runbooks, and customer handoff material.
Requirements
Bachelor’s degree in an engineering, computer science, cybersecurity, infommation technology or a related discipline, or equivalent experience and combined education, with 5-10 years of experience, or relevant professional experience.
- Production experience with OAuth 2.0, OpenID Connect, JWTs, federation, token lifecycle, and secure application onboarding.
- Experience integrating Active Director, Microsoft Entra ID, LDAP, SAML, or comparible enterprise identity systems.
- Experience with Kubernetes or OpenShift service accounts, RBAC, secrets, ingress, or service-mesh identity.
- Experience implementing identity for non-human services, workloads, or automation.
- Experience with fine-grained authorization, policy as code, API scopes, or external authorization services.
- Ability to automate configuration and testing with Python, PowerShell, or comparable language.
- Works well in a fast=paces collaborative team environment.
- Must be willing to work onsite in a closed/classified area.
- Active Department of Defense (DoD) Secret clearance., Experience operating Keycloak or another self-hosted identity provider in Kubernetes.
- Experience with Microsoft Entra workload identity, managed identities, or service-principal governance.
- Experience with OPA, Envoy, Istio, SPIFFE/SPIRE, or comparable technogies.
- Experience with OpenBao, Vault, External Secrets, cert-manager, or enterprise certificate-management systems.
- Experience applying identity and delegated authorization to AI agents and tool integrations.
- Experience using OpenTelemetry for attributable activity and security-event diagnosis.
- Strong oral and written communication skills.
- Strong interpersonal and collaboration skills.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Navigating the AI Shift
Everything a Developer Needs to Know About MCP with Neo4j