ICAM Identity Provider (IdP) Engineer - Enterprise Authentication Services

General Dynamics Information Technology
Falls Church, VA, United States
29 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$170,000.0 - $230,000.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory Active Directory Federation Services Application Programming Interfaces (APIs) Agile Methodology Application Integration Architecture User Authentication Cloud Computing CompTIA Security+ Cyber Security Linux Disaster Recovery Multi-Factor Authentication
+24 more
Monitoring of Systems Identity and Access Management Lightweight Directory Access Protocols (LDAP) Windows Servers OAuth OpenID Performance Tuning Public Key Infrastructure Windows PowerShell Openid Connect Azure Active Directory Phishing Zero Trust Network Access Security Assertion Markup Language (SAML) Single Sign-On Smart Cards Web Applications Enterprise Software Applications Load Balancing Okta Ws-federation Containerization Pingfederate Docker

Job description

  • Design, develop, configure, and maintain enterprise Identity Provider (IdP) services supporting over 4 million enterprise identities.
  • Engineer, administer, and sustain Microsoft Active Directory Federation Services (ADFS) infrastructure supporting enterprise authentication and federation.
  • Configure and maintain federation trust relationships with internal and external Identity Providers (IdPs), Service Providers (SPs), and mission partners.
  • Design, implement, and troubleshoot authentication solutions utilizing SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication.
  • Support onboarding and integration of enterprise applications into the authentication and federation ecosystem.
  • Develop authentication policies, claims rules, attribute mappings, token issuance policies, and authorization workflows.
  • Support enterprise Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, and phishing-resistant authentication capabilities.
  • Collaborate with cybersecurity, Active Directory, cloud, infrastructure, and application teams to implement secure authentication services.
  • Support implementation of Zero Trust Architecture through modern authentication, federation, and identity assurance capabilities.
  • Monitor, troubleshoot, and resolve complex authentication, federation, trust, certificate, token, and identity assertion issues.
  • Engineer highly available and resilient authentication services supporting mission-critical enterprise applications.
  • Develop technical documentation including architecture diagrams, integration guides, SOPs, TTPs, operational procedures, and onboarding documentation.
  • Participate in Agile development activities and continuous service improvement initiatives.
  • Actively manage technical risks and contribute to enterprise identity modernization efforts.

Requirements

The ideal candidate is a senior hands-on identity engineer with expertise in Microsoft Active Directory Federation Services (ADFS), enterprise authentication, federation technologies, and modern identity protocols. This role focuses on delivering highly available authentication services, federation trust management, single sign-on (SSO), multi-factor authentication (MFA), and secure application integration across a large-scale enterprise environment.., * Active Secret Clearance at minimum. Interim Secret Clearances are not allowed.

  • Bachelor’s Degree in a related technical discipline, or the equivalent combination of education, technical certifications or training, or work experience.
  • DoD 8570/8140 IAT Level II certification (Security+ CE or higher), * Minimum of 8 years of experience supporting Identity and Access Management (IAM), Authentication, Federation, or ICAM solutions within government or regulated environments
  • Strong experience designing, implementing, and supporting Microsoft Active Directory Federation Services (ADFS).
  • Extensive experience implementing enterprise Identity Provider (IdP) services supporting large user populations.
  • Strong understanding of authentication, authorization, federation, and identity assurance concepts
  • Experience implementing and troubleshooting SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and JWT technologies
  • Experience supporting PKI, certificate-based authentication, smart card authentication, and MFA solutions
  • Experience integrating applications, APIs, and enterprise services with federation platforms
  • Experience with Active Directory, LDAP directories, and enterprise identity repositories
  • Experience configuring claims, attribute mappings, policy enforcement, token transformations, and federation workflows
  • Experience supporting Linux and/or Windows Server environments
  • Experience deploying and supporting enterprise COTS products in secure customer environments
  • Experience working in Agile development environments and utilizing associated tools
  • Strong written and verbal communication skills
  • Self-starter capable of driving complex technical efforts to completion

Desired Skills/Knowledge:

  • Experience designing and supporting highly available ADFS farms with Web Application Proxy (WAP), load balancing, and disaster recovery architectures.
  • Experience with Microsoft Entra ID (Azure AD), PingFederate, PingAccess, PingDirectory, Okta, Keycloak, or similar enterprise authentication platforms.
  • Experience supporting DoD Enterprise ICAM, Federation Hub, or mission partner federation initiatives
  • Experience implementing federation solutions for coalition, partner, or cross-organizational environments
  • Experience supporting NIST 800-63 Identity Assurance Levels (IAL), Authenticator Assurance Levels (AAL), and Federation Assurance Levels (FAL)
  • Experience implementing phishing-resistant authentication technologies and passwordless authentication solutions.
  • Experience supporting Zero Trust Architecture and identity-centric security initiatives.
  • Familiarity with PowerShell scripting and automation for ADFS administration.
  • Experience supporting enterprise monitoring, performance tuning, and capacity planning for authentication services supporting millions of identities.
  • Experience with Active Directory Certificate Services (AD CS) and enterprise PKI.
  • Familiarity with container technologies such as Docker and Kubernetes.
  • Familiarity with DoD PKI, CAC authentication, derived credentials, and certificate lifecycle management.
  • Experience supporting highly available, mission-critical enterprise authentication environments., 8 + years of related experience
  • may vary based on technical training, certification(s), or degree

Certification

CompTIA Security+ CE | CompTIA - CompTIA Travel Required

Less than 10% Citizenship

Benefits & conditions

(part of General Dynamics) 3.73.7 out of 5 stars Falls Church, VA Remote $170,000 - $230,000 a year, Pulled from the full job description

  • 401(k) matching
  • Paid time off
  • Internal mobility program, At GDIT, the mission is our purpose, and our people are at the center of everything we do.
  • Growth: AI-powered career tool that identifies career steps and learning opportunities
  • Support: An internal mobility team focused on helping you achieve your career goals
  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
  • Flexibility: Full-flex work week to own your priorities at work and at home
  • Community: Award-winning culture of innovation and a military-friendly workplace, The likely salary range for this position is $170,000 - $230,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

About the company

Own your opportunity to support our nation’s defense. Make an impact by connecting and securing critical operations across the globe, keeping our country safe and secure., GDIT has an opportunity for an ICAM Engineer supporting a large line of business that delivers enterprise-scale Identity, Credential, and Access Management (ICAM) capabilities. This role supports the DoD ICAM mission by designing, developing, integrating, and maintaining enterprise Identity Provider (IdP) services that provide secure authentication and federation for more than 4 million enterprise identities across the Department of Defense., We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:24 min

Securing cloud deployments by utilizing OpenID Connect mapping

Chris Ayers · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all