> Markdown version of [/jobs/ext/1842683-trust-and-identity-engineer](https://www.wearedevelopers.com/jobs/ext/1842683-trust-and-identity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Trust and Identity Engineer - **Company:** COHESION FORCE INC - **Location:** Huntsville, AL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Application Programming Interfaces (APIs), Artificial Intelligence, Continuous Integration, Distributed Systems, Python (Programming Language), Lightweight Directory Access Protocols (LDAP), OAuth, OpenShift, Windows PowerShell, Role-Based Access Control, Openid Connect, Azure Active Directory, Security Assertion Markup Language (SAML), Systems Integration, Policy as Code, Data Logging, Scripting, Okta, Istio, SC Clearance, Git Flow, Kubernetes, Infrastructure Automation Frameworks, Information Technology - **Published:** July 31, 2026 - **Apply:** https://www.cohesionforce.com/job/trust-and-identity-engineer-26-014 ## About the Role Bachelor's degree in an engineering, computer science, cybersecurity, infommation technology or a related discipline, or equivalent experience and combined education, with 5-10 years of experience, or relevant professional experience. - Production experience with OAuth 2.0, OpenID Connect, JWTs, federation, token lifecycle, and secure application onboarding. - Experience integrating Active Director, Microsoft Entra ID, LDAP, SAML, or comparible enterprise identity systems. - Experience with Kubernetes or OpenShift service accounts, RBAC, secrets, ingress, or service-mesh identity. - Experience implementing identity for non-human services, workloads, or automation. - Experience with fine-grained authorization, policy as code, API scopes, or external authorization services. - Ability to automate configuration and testing with Python, PowerShell, or comparable language. - Works well in a fast=paces collaborative team environment. - Must be willing to work onsite in a closed/classified area. - Active Department of Defense (DoD) Secret clearance., Experience operating Keycloak or another self-hosted identity provider in Kubernetes. - Experience with Microsoft Entra workload identity, managed identities, or service-principal governance. - Experience with OPA, Envoy, Istio, SPIFFE/SPIRE, or comparable technogies. - Experience with OpenBao, Vault, External Secrets, cert-manager, or enterprise certificate-management systems. - Experience applying identity and delegated authorization to AI agents and tool integrations. - Experience using OpenTelemetry for attributable activity and security-event diagnosis. - Strong oral and written communication skills. - Strong interpersonal and collaboration skills. ## Description CohesionForce is actively seeking candidates for a Trust and Identify Engineer to become part of our team in Huntsville, AL. This individual will design, implement, and support identity and access capabilities for users, applications, services, workloads, and AI-enabled systems. The engineer will work across platform, software, reliability, and customer teams to provide secure authentication, federation, authorization, credential management, and auditable access., Integrate Microsoft Entra ID, Active Directory, and other customer identity providers using OAuth 2.0, OpenID Connect, SAML, and LDAP-based technologies. - Configure and support identity providers and authentication proxies such as Keycloak, oauth2-proxy, or equivalent products. - Define stable claims, groups, roles, and application onboarding patterns. - Design identity for Kubernetes workloads, services, automation, and AI agents using service accounts, short-lived tokens, service principals, certificates, or workload identity federation. - Implement least-privilege access using RBAC, ABAC, policy as code, and centralized authorization services. - Establish issuance, delivery, rotation, revocation, and recovery procedures for secrets, keys, tokens, and certificates. - Automate identity configuration and validation using APIs, scripting, infrastructure as code, GitOps, and CI-CD. - Troubleshoot login, token, claim, session, certificate, federation, and authorization issues across distributed systems. - Define identity-related logging and tracing requirements and work with reliability engineers to support monitoring and incident resonse. - Develop architecture documentation, integration guides, test procedures, runbooks, and customer handoff material. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Next-gen CI/CD with Gitops and Progressive Delivery](https://www.wearedevelopers.com/videos/1603-next-gen-ci-cd-with-gitops-and-progressive-delivery) ## Related Articles - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers)