> Markdown version of [/jobs/ext/2281726-identity-and-access-management-lead](https://www.wearedevelopers.com/jobs/ext/2281726-identity-and-access-management-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity and Access Management Lead - **Company:** ECS Corporate Services, LLC - **Location:** Arlington, VA, United States - **Experience:** Expert - **Salary:** $126,000.0 - $189,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Identity and Access Management, Role-Based Access Control, Azure Active Directory, Zero Trust Network Access - **Published:** August 28, 2026 - **Apply:** https://www.jofdav.com/jobs/59437671-identity-and-access-management-lead ## About the Role * 5+ years of experience in Identity and Access Management in a complex enterprise or federal environment * Demonstrated expertise with Microsoft EntraID (Azure AD) including conditional access, role assignments, and identity governance * Hands-on experience with AWS IAM , including policies, roles, permission boundaries, and access analysis tools * Strong knowledge of RBAC design , least privilege principles, and Zero Trust Architecture frameworks * Experience supporting or implementing PAM solutions and privileged account governance * Familiarity with CDM program requirements , PAR/RAR processes, and federal ICAM policies * Experience conducting access reviews, audits, and compliance reporting * Strong documentation and communication skills with the ability to present complex IAM concepts to both technical and non-technical stakeholders ## Description Everforth ECS is seeking an Identity and Access Management Lead to work in our Arlington, VA office/remote. The Lead IAM Engineer will serve as the primary subject matter expert for Identity and Access Management within the CDM program's Security Engineering team. This individual will be responsible for designing, implementing, and maturing IAM capabilities across the CDM BETSIE environment, with a focus on access governance, least privilege enforcement, privileged access management, and federal compliance alignment. Key Responsibilities * Design and implement a formal RBAC framework across CDM BETSIE and associated environments, including EntraID and AWS * Establish and enforce least privilege policies in alignment with Zero Trust Architecture principles and federal directives * Develop and manage identity lifecycle processes for joiners, movers, and leavers across the program, ensuring timely provisioning and deprovisioning * Implement and manage a Privileged Access Management (PAM) program including identification, governance, and monitoring of privileged accounts * Lead access review and audit processes to support PAR/RAR reporting requirements and ongoing compliance obligations * Develop and maintain role-to-privilege mappings and job function definitions across the program to eliminate access ambiguity * Collaborate with program leadership, system owners, and HR to ensure IAM policies align with organizational changes and personnel transitions * Produce IAM metrics, reports, and dashboards to communicate access risk and governance posture to program leadership * Serve as the IAM subject matter expert for CDM program compliance activities, audits, and government stakeholder engagements ## Related Videos - [Full-stack role-based authorization in 45 minutes](https://www.wearedevelopers.com/videos/312-full-stack-role-based-authorization-in-45-minutes) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Containers in the cloud - State of the Art in 2022](https://www.wearedevelopers.com/videos/410-containers-in-the-cloud-state-of-the-art-in-2022) - [Backstage in Practice: Offloading Developer Operational Work Through Platform Self-Service](https://www.wearedevelopers.com/videos/1922-backstage-in-practice-offloading-developer-operational-work-through-platform-self-service) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Un-complicate authorization maintenance](https://www.wearedevelopers.com/videos/889-un-complicate-authorization-maintenance) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)