Identity and Access Management Lead
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Everforth ECS is seeking an Identity and Access Management Lead to work in our Arlington, VA office/remote.
The Lead IAM Engineer will serve as the primary subject matter expert for Identity and Access Management within the CDM program’s Security Engineering team. This individual will be responsible for designing, implementing, and maturing IAM capabilities across the CDM BETSIE environment, with a focus on access governance, least privilege enforcement, privileged access management, and federal compliance alignment.
Key Responsibilities
-
Design and implement a formal RBAC framework across CDM BETSIE and associated environments, including EntraID and AWS
-
Establish and enforce least privilege policies in alignment with Zero Trust Architecture principles and federal directives
-
Develop and manage identity lifecycle processes for joiners, movers, and leavers across the program, ensuring timely provisioning and deprovisioning
-
Implement and manage a Privileged Access Management (PAM) program including identification, governance, and monitoring of privileged accounts
-
Lead access review and audit processes to support PAR/RAR reporting requirements and ongoing compliance obligations
-
Develop and maintain role-to-privilege mappings and job function definitions across the program to eliminate access ambiguity
-
Collaborate with program leadership, system owners, and HR to ensure IAM policies align with organizational changes and personnel transitions
-
Produce IAM metrics, reports, and dashboards to communicate access risk and governance posture to program leadership
-
Serve as the IAM subject matter expert for CDM program compliance activities, audits, and government stakeholder engagements
Requirements
-
5+ years of experience in Identity and Access Management in a complex enterprise or federal environment
-
Demonstrated expertise with Microsoft EntraID (Azure AD) including conditional access, role assignments, and identity governance
-
Hands-on experience with AWS IAM , including policies, roles, permission boundaries, and access analysis tools
-
Strong knowledge of RBAC design , least privilege principles, and Zero Trust Architecture frameworks
-
Experience supporting or implementing PAM solutions and privileged account governance
-
Familiarity with CDM program requirements , PAR/RAR processes, and federal ICAM policies
-
Experience conducting access reviews, audits, and compliance reporting
-
Strong documentation and communication skills with the ability to present complex IAM concepts to both technical and non-technical stakeholders
Benefits & conditions
Salary: $126,000 - $189,000
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production
Everything a Developer Needs to Know About MCP with Neo4j
Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters