ICAM Engineer - Identity, Credential, and Access Management

RMANTRA SOLUTIONS INC.
Alexandria, VA, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Application Programming Interfaces (APIs) Amazon Web Services Systems Engineering Configuration Management Cyber Security Identity and Access Management Lightweight Directory Access Protocols (LDAP) Linux System Administration Log Analysis OAuth
+11 more
Performance Tuning Ansible Zero Trust Network Access Security Assertion Markup Language (SAML) Shell Script Software Vulnerability Management Enterprise Software Applications Gitlab Information Technology Software Version Control Jenkins

Job description

  • Engineering & Deployment: Engineer, deploy, secure, and maintain complex, mission-critical identity systems-specifically ForgeRock IdP/ICAM platforms-across Linux-based environments to meet DoD, DISA, and federal standards.
  • Integration & Federation: Integrate enterprise applications and directories (LDAP, Active Directory) with ICAM platforms using robust federation protocols (SAML, OAuth2, APIs) across cross-domain workflows and secure enclaves.
  • Lifecycle & Access Control: Manage the complete identity and credential lifecycle (issuing, renewing, revoking, and automating workflows) to enforce strict Zero Trust access controls.
  • Security & Compliance: Conduct system hardening, log analysis, and vulnerability management to support compliance with the Risk Management Framework (RMF) and participate in architectural and risk reviews.
  • Operations & Troubleshooting: Diagnose and resolve escalated ICAM and ForgeRock issues within defined SLAs, conducting root cause analysis, performance tuning, and active monitoring.
  • Documentation & Metrics: Create and version-control key engineering artifacts (CONOPS, SOPs, API documentation, and workflow diagrams) while maintaining ICAM performance metrics and dashboards.

Requirements

  • BS in Computer Science, IT, or related discipline and 8+ years of systems engineering experience (or equivalent experience in lieu of degree).
  • Active TS clearance with SCI eligibility
  • Ability to obtain and maintain a CI Poly and Special Program Access.
  • IAT Level II certification or higher (e.g., Security+ CE, CySA+, SSCP, CISSP).
  • Hands on experience with federation technologies (SAML, OAuth2) and ZeroTrust identity principles.
  • Experience engineering or administering the ForgeRock platform (AM, IDM, DS).
  • Strong understanding of ICAM concepts, identity lifecycle management, and enterprise access controls.
  • Experience with Windows and Linux systems administration, shell scripting, and troubleshooting., * Experience supporting DISA or DoD mission partners.
  • Active TS/SCI with CI Poly preferred.
  • Experience with any of the following:
  • JISG Access Controls
  • AWS cloud engineering, IAM, and security services
  • Ansible playbooks and automated configuration management
  • CI/CD pipelines (GitLab, Jenkins, etc.)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

1:02 min

Applying an ETL methodology to infrastructure configuration management

Axel Barbier · WWC 2023

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

1:52 min

Identifying environments that require strict credential management

Moritz Johner · WWC 2023

Videos

See all

Related articles

See all