> Markdown version of [/jobs/ext/1955554-lead-identity-and-access-management-icam-engineer](https://www.wearedevelopers.com/jobs/ext/1955554-lead-identity-and-access-management-icam-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Identity and Access Management (ICAM) Engineer - **Company:** Leidos, Inc. - **Location:** Rockville, MD, United States - **Experience:** Expert - **Salary:** $131,300.0 - $237,350.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Windows, Active Directory, Amazon Web Services, Systems Engineering, User Authentication, Microsoft Azure, Biometrics, CompTIA Security+, Cyber Security, Multi-Factor Authentication, Identity and Access Management, Kerberos (Protocol), Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Ping (Networking Utility), Windows PowerShell, Role-Based Access Control, Openid Connect, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Single Sign-On, Google Cloud, Okta, Cyberark, Ws-federation, Information Technology, Sentry, Graphql - **Published:** August 6, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9078559/lead-identity-and-access-management-icam-engineer ## About the Role Be a US Citizen or US Person who has lived in the United States for at least three consecutive years and have the ability to obtain a Public Trust level 4 clearance, * Bachelor's degree in computer science, Information Technology, or equivalent and 12 years of general experience, preferably supporting system engineering. 6 years of additional experience is equivalent to a Bachelor's degree. With a Master's degree, 10 years of general experience is required. * 8+ years of progressive experience focusing on identity and access management. * 5+ years in a senior/lead or SME capacity, with demonstrated ownership of enterprise-scale IAM architecture. * Hands-on experience with at least two of the following IAM platform categories: - IGA: Microsoft Identity Manager - PAM: CyberArk, Beyond Trust - SSO/Federation: Okta, Microsoft Entra ID, Ping Identity - Directory Services: Active Directory, Azure AD/Entra ID, LDAP * Experience supporting federal, defense, or highly regulated environments preferred (especially for government/contractor roles). * Experience with cloud IAM services (Azure Entra ID, AWS IAM/SSO, GCP IAM). * Deep understanding of authentication and authorization protocols: SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), SCIM, Kerberos. * Extensive hands-on experience with Microsoft identity solutions (Entra ID, AD FS, Microsoft 365, MIM). * Proven experience in large-scale, multi-forest Active Directory and Entra ID architectures. * Advanced knowledge of identity protocols (SAML, OAuth 2.0, OpenID Connect, WS-Federation, CBA). * Strong experience with Entra B2B and B2C for external identity management. * Experience with Entra AD Connect, including custom synchronization rules. * Strong proficiency in PowerShell and Graph API for identity management automation. * Familiarity with Zero Trust architecture and identity-related security best practices. Preferred Qualifications: * Relevant certifications, hold at least one or two of the following, aligned to seniority: + CIAM (Certified Identity and Access Manager) or CIGE (Certified Identity Governance Expert) + Microsoft Certified: Identity and Access Administrator Associate (SC-300) + CyberArk Defender/Sentry/Guardian + Okta Certified Professional/Consultant/Administrator + Ping Identity Certified Professional + CompTIA Security+ * Knowledge of identity-related compliance standards (e.g., NIST, FISMA, SOC, FedRamp). * Experience with Azure AD Verifiable Credentials and decentralized identity concepts. * Understanding of biometric authentication methods and their Azure AD integration. ## Description Leidos Digital Civilian Agency Solutions division is seeking an expert-level Lead Identity and Access Management Engineer to serve as the senior technical authority for complex enterprise identity management solutions for large-scale government digital transformation initiatives. The ideal candidate will have deep expertise in Microsoft identity technologies and a proven track record of designing, implementing, and maturing IAM architecture and processes across cloud and on-premises environments, ensuring alignment with industry frameworks and regulatory requirements, and provides technical leadership and mentorship to junior and mid-level IAM engineers. advanced enterprise-level identity solutions., * Lead the design, engineering, and continuous improvement of enterprise IAM solutions, including Identity Governance and Administration (IGA), Privileged Access Management (PAM), Single Sign-On (SSO)/Federation, Multi-Factor Authentication (MFA), and directory services. * Serve as the SME for IAM architecture decisions, tool selection, and integration strategy across cloud (Azure, AWS, GCP) and on-premises platforms. * Define and enforce Identity lifecycle management processes (joiner-mover-leaver), role-based/attribute-based access control (RBAC/ABAC), and least-privilege principles. * Lead IAM-related audits, risk assessments, and remediation efforts; ensure compliance with regulatory and contractual obligations. * Partner with security operations, application owners, and compliance teams to integrate applications into enterprise IAM platforms (e.g., Microsoft Entra ID/Azure AD, Okta, Ping Identity, CyberArk). * Provide technical leadership, mentoring, and peer review for IAM engineering staff. * Support incident response and forensic investigations involving identity-related events. * Evaluate emerging IAM technologies (e.g., password less authentication, decentralized identity, Zero Trust architecture) and recommend adoption strategies. * Prepare technical documentation, architecture diagrams, and executive-level reporting on IAM posture and roadmap. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [From Doubt to Confidence: How Sentry Uses Verdaccio to Bulletproof SDK Releases](https://www.wearedevelopers.com/videos/739-from-doubt-to-confidence-how-sentry-uses-verdaccio-to-bulletproof-sdk-releases) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)