Lead Identity and Access Management Engineer

CareerCircle
Washington, DC, United States
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$131,300.0 - $237,350.0
Working hours
Regular working hours

Tech stack

Microsoft Access Microsoft Windows Active Directory Agile Methodology Artificial Intelligence Amazon Web Services Systems Engineering User Authentication Microsoft Azure Biometrics CompTIA Security+ Cyber Security
+30 more
Computer Literacy Continuous Availability Scientific Data Archiving Digital Forensics Multi-Factor Authentication Identity and Access Management Kerberos (Protocol) Lightweight Directory Access Protocols (LDAP) OAuth OpenID Operational Databases Ping (Networking Utility) Windows PowerShell Role-Based Access Control Openid Connect Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Single Sign-On Google Cloud Okta Cyberark Microsoft InTune SC Clearance Ws-federation Information Technology Sentry Graphql Data Management Mobile Data

Job description

Leidos Digital Civilian Agency Solutions division is seeking an expert-level Lead Identity and Access Management Engineer to serve as the senior technical authority for complex enterprise identity management solutions for large-scale government digital transformation initiatives. The ideal candidate will have deep expertise in Microsoft identity technologies and a proven track record of designing, implementing, and maturing IAM architecture and processes across cloud and on-premises environments, ensuring alignment with industry frameworks and regulatory requirements, and provides technical leadership and mentorship to junior and mid-level IAM engineers. advanced enterprise-level identity solutions., * Lead the design, engineering, and continuous improvement of enterprise IAM solutions, including Identity Governance and Administration (IGA), Privileged Access Management (PAM), Single Sign-On (SSO)/Federation, Multi-Factor Authentication (MFA), and directory services.

  • Serve as the SME for IAM architecture decisions, tool selection, and integration strategy across cloud (Azure, AWS, GCP) and on-premises platforms.
  • Define and enforce Identity lifecycle management processes (joiner-mover-leaver), role-based/attribute-based access control (RBAC/ABAC), and least-privilege principles.
  • Lead IAM-related audits, risk assessments, and remediation efforts; ensure compliance with regulatory and contractual obligations.
  • Partner with security operations, application owners, and compliance teams to integrate applications into enterprise IAM platforms (e.g., Microsoft Entra ID/Azure AD, Okta, Ping Identity, CyberArk).
  • Provide technical leadership, mentoring, and peer review for IAM engineering staff.
  • Support incident response and forensic investigations involving identity-related events.
  • Evaluate emerging IAM technologies (e.g., password less authentication, decentralized identity, Zero Trust architecture) and recommend adoption strategies.
  • Prepare technical documentation, architecture diagrams, and executive-level reporting on IAM posture and roadmap., Microsoft Intune (Mobile Device Management Software) +0 Research Technician Actalent

Rockville, MD*On-Site

Biology Research Visionary Innovation Sanitation Autoclaves Animal Care Coordinating Laminar Flow Animal Health Record Keeping Animal Science Detail Oriented Data Collection Animal Husbandry Computer Literacy Agile Methodology Fine Motor Skills Biopharmaceuticals Facility Operations Veterinary Medicine Biological Engineering Artificial Intelligence Continuous Availability Engineering Design Process Standard Operating Procedure Ethical Standards And Conduct Ability To Distinguish Colors Technical Procedure Compliance Assistant Laboratory Animal Technician Irrigation (Landscaping And Agriculture) American Association For Laboratory Animal Science (AALAS) Certification +0 Powder Processor Aerotek

Adamstown, MD*On-Site

Aviation Machinery Lubrication Construction Detail Oriented Health Advocacy Material Handling Machine Operation Lock Out / Tag Out Advanced Materials Workflow Management Mechanical Aptitude Industrial Equipment Production Equipment Operational Databases Artificial Intelligence Discounts And Allowances Manufacturing Operations Employee Assistance Programs Troubleshooting (Problem Solving) +0 Login | JoinContact

Requirements

Mentorship Governance Peer Review Market Data Investigation Risk Analysis Microsoft 365 Authentications Microsoft Azure Access Controls Law Enforcement Ancient History Computer Science Active Directory Incident Response Digital Forensics Directory Service Windows PowerShell Facebook Graph API Systems Engineering Amazon Web Services Technical Authority Single Sign-On (SSO) Business To Business Lifecycle Management Technical Leadership Business-To-Consumer Integration Strategy Information Technology Azure Active Directory Digital Transformation Technical Documentation Authorization (Computing) Multi-Factor Authentication Privileged Access Management Zero Trust Architecture (ZTA) Continuous Improvement Process Identity And Access Management Microsoft Certified Professional Role-Based Access Control (RBAC) AWS Identity And Access Management (IAM) Security Assertion Markup Language (SAML) Cloud Identity and Access Management (IAM), Be a US Citizen or US Person who has lived in the United States for at least three consecutive years and have the ability to obtain a Public Trust level 4 clearance, * Bachelor’s degree in computer science, Information Technology, or equivalent and 12 years of general experience, preferably supporting system engineering. 6 years of additional experience is equivalent to a Bachelor’s degree. With a Master’s degree, 10 years of general experience is required.

  • 8+ years of progressive experience focusing on identity and access management.
  • 5+ years in a senior/lead or SME capacity, with demonstrated ownership of enterprise-scale IAM architecture.
  • Hands-on experience with at least two of the following IAM platform categories:

  • IGA: Microsoft Identity Manager
  • PAM: CyberArk, Beyond Trust
  • SSO/Federation: Okta, Microsoft Entra ID, Ping Identity
  • Directory Services: Active Directory, Azure AD/Entra ID, LDAP
  • Experience supporting federal, defense, or highly regulated environments preferred (especially for government/contractor roles).

  • Experience with cloud IAM services (Azure Entra ID, AWS IAM/SSO, GCP IAM).
  • Deep understanding of authentication and authorization protocols: SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), SCIM, Kerberos.
  • Extensive hands-on experience with Microsoft identity solutions (Entra ID, AD FS, Microsoft 365, MIM).
  • Proven experience in large-scale, multi-forest Active Directory and Entra ID architectures.
  • Advanced knowledge of identity protocols (SAML, OAuth 2.0, OpenID Connect, WS-Federation, CBA).
  • Strong experience with Entra B2B and B2C for external identity management.
  • Experience with Entra AD Connect, including custom synchronization rules.
  • Strong proficiency in PowerShell and Graph API for identity management automation.
  • Familiarity with Zero Trust architecture and identity-related security best practices.

Preferred Qualifications:

  • Relevant certifications, hold at least one or two of the following, aligned to seniority:
  • CIAM (Certified Identity and Access Manager) or CIGE (Certified Identity Governance Expert)
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • CyberArk Defender/Sentry/Guardian
  • Okta Certified Professional/Consultant/Administrator
  • Ping Identity Certified Professional
  • CompTIA Security+
  • Knowledge of identity-related compliance standards (e.g., NIST, FISMA, SOC, FedRamp).
  • Experience with Azure AD Verifiable Credentials and decentralized identity concepts.
  • Understanding of biometric authentication methods and their Azure AD integration.

If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 - and moving faster than anyone else dares., Apple IPad Mobile Data Coordinating Communication Team Oriented Data Archives Prioritization Detail Oriented Self-Motivation Problem Solving Data Management Customer Service Asset Management Secret Clearance Command Controls CompTIA Security+ Business Valuation Incident Management Service Fulfillment Lifecycle Management Smartphone Operation Full Stack Development Master Data Management Artificial Intelligence Wireless Communications Business Transformation Scientific Data Archiving Laurentz Contact Resonance Interpersonal Communications Troubleshooting (Problem Solving) Apple Certified Support Professional

Benefits & conditions

Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits .

About the company

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careercircle.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

1:22 min

Overview of the Sentry error and performance monitoring platform

Priscila Oliveira · WWC 2023

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

Videos

See all

Related articles

See all