> Markdown version of [/jobs/ext/1928620-identity-and-access-engineer-icam-engineer](https://www.wearedevelopers.com/jobs/ext/1928620-identity-and-access-engineer-icam-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity and Access Engineer (ICAM) Engineer - **Company:** Leidos, Inc. - **Location:** Rockville, MD, United States - **Experience:** Experienced - **Salary:** $87,100.0 - $157,450.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Windows, Active Directory, Systems Engineering, Biometrics, Identity and Access Management, OAuth, Windows PowerShell, Openid Connect, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Ws-federation, Information Technology, Graphql - **Published:** August 5, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9076203/identity-and-access-engineer-icam-engineer ## About the Role Leidos Digital Sector is seeking an Identity and Access (ICAM) Engineer to lead complex identity management solutions for large-scale government digital transformation initiatives. The ideal candidate will have deep expertise in Microsoft identity technologies and a proven track record of implementing advanced enterprise-level identity solutions. Candidate MUST: Be a US Citizen or US Person who has lived in the United States for at least three consecutive years and have the ability to obtain a Public Trust level 4 clearance, * Bachelor's degree in computer science, Information Technology, or equivalent and 5 years of experience or Master's with 3 plus years of general IT experience, preferably supporting system engineering. Additional years of experience may be substituted in lieu of degree. * 5+ years of experience focusing on identity and access management. * Experience in PIM and Azure AD Conditional Access policies. * Hands-on experience with Microsoft identity solutions (Entra ID, AD FS, Microsoft 365, MIM). * Proven experience in large-scale, multi-forest Active Directory and Entra ID architectures. * Advanced knowledge of identity protocols (SAML, OAuth 2.0, OpenID Connect, WS-Federation, CBA). * Strong experience with Azure AD B2B and B2C for external identity management. * Proficiency in PowerShell and Graph API for identity management automation. * Experience with Azure AD Connect, including custom synchronization rules. * Familiarity with Zero Trust architecture and identity-related security best practices., * Relevant Microsoft certifications (e.g., Microsoft 365 Certified: Enterprise Administrator Expert). * Experience in government or highly regulated industries. * Knowledge of identity-related compliance standards (e.g., NIST, FISMA). * Experience with Azure AD Verifiable Credentials and decentralized identity concepts. * Understanding of biometric authentication methods and their Azure AD integration. ## Description * Maintain Microsoft Entra ID solutions, including multi-tenant and cross-tenant synchronization for complex organizations. * Implement migration strategies evolving identify and access management platforms (i.e. migration from on-premises Active Directory to Microsoft Entra ID Native authentication.) * Implement advanced identity management solutions using Entra ID to optimize cost-efficiency and user experience. * Assisted with custom identity management tools and automate identity lifecycle processes. * Ensure identity solutions align with security, compliance, and business requirements. * Stay current with the latest Microsoft identity technologies and industry best practices. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Putting the Graph In GraphQL With The Neo4j GraphQL Library](https://www.wearedevelopers.com/videos/257-putting-the-graph-in-graphql-with-the-neo4j-graphql-library) - [Biometric Phone Chargers, $40m Domain Names & AI Movies Winning Awards - Peter Kröner](https://www.wearedevelopers.com/videos/1810-biometric-phone-chargers-40m-domain-names-ai-movies-winning-awards-peter-kroner) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Secure and Accessible Login Systems - Ramona Schwering](https://www.wearedevelopers.com/videos/1847-secure-and-accessible-login-systems-ramona-schwering) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026)