> Markdown version of [/jobs/ext/2583239-senior-icam-engineer](https://www.wearedevelopers.com/jobs/ext/2583239-senior-icam-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior ICAM Engineer - **Company:** Capgemini - **Location:** San Antonio, TX, United States - **Experience:** Expert - **Salary:** $110,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Active Directory, Application Programming Interfaces (APIs), Systems Engineering, Bash Shell, CompTIA Security+, Cyber Security, Databases, Data Validation, Data Synchronization, Relational Databases, Query Languages, Disaster Recovery, Identity and Access Management, Python (Programming Language), Lightweight Directory Access Protocols (LDAP), PostgreSQL, Microsoft SQL Server, OAuth, OpenID, Oracle (Applications), Performance Tuning, Ping (Networking Utility), Windows PowerShell, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), SQL Databases, Systems Integration, Virtual Directory, Web Services, Scripting, Load Balancing, Okta, Cyberark, SOAPAPI, SC Clearance, Information Technology, SailPoint, Restful APIs - **Published:** August 14, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18008737?backUrl=%2Fcareer%2F18008737%2FSenior-Icam-Engineer-Texas-San-Antonio ## About the Role * Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, Systems Engineering, or a related technical discipline. * Minimum of six (6) years of professional experience in Identity, Credential, and Access Management (ICAM), with at least three (3) years dedicated to hands-on engineering and administration of Radiant Logic RadiantOne (FID/VDS) platforms. * Must possess an active (Secret clearance required). * Active IAT Level II Baseline Certification in accordance with DoD 8570.01-M / DoD 8140 (e.g., CompTIA Security+ CE, CySA+, GSEC, CCNA Security, or higher level certifications like CISSP or CASP+). Technical Expertise: * Deep understanding of directory technologies, schema structures, and protocols: LDAP, Active Directory, Azure AD/Entra ID, SAML, OAuth, OIDC, and REST/SOAP web services. * Practical experience designing complex joins, user unions, auto-generated attributes, and complex hierarchy transformations in Radiant Logic. * Solid working knowledge of relational database structures and query languages (SQL Server, Oracle, PostgreSQL). * Familiarity with scripting languages (PowerShell, Bash, Python) for operational automation and data validation. * Exceptional analytical problem-solving skills, precision in data modeling, and the ability to articulate identity infrastructure concepts to both technical leads and program managers. * Direct experience supporting Federal ICAM (FICAM), DoD ICAM, or enterprise Zero Trust Architecture (ZTA) implementations. * Integration experience connecting Radiant Logic to IGA platforms (e.g., SailPoint), Access Managers (e.g., Ping, Okta, ForgeRock), or PAM solutions (e.g., CyberArk). ## Description The Senior ICAM Engineer specializes in designing, deploying, and maintaining Master Entitlement Records (MER) and authoritative identity pipelines using the Radiant Logic RadiantOne Virtual Directory Server (VDS) / FID platform. This role is responsible for virtualizing, unifying, and correlating disparate identity, group, and access entitlement data across heterogeneous enterprise data stores, directories, databases, and cloud environments. The engineer ensures the creation of a centralized, real-time "single source of identity truth" (Master Entitlement Record) to support fine-grained access control, Attribute-Based Access Control (ABAC), Identity Governance and Administration (IGA), and Zero Trust Architecture (ZTA) initiatives., * Design, build, configure, and maintain Radiant Logic RadiantOne FID/VDS instances across complex hybrid environments (on-premises and cloud). * Develop, manage, and optimize unified identity views, object mapping, schema extensions, and entitlement aggregation models to support downstream authorization and governance engines. * Connect, join, translate, and synthesize identity data from disparate sources including Active Directory, Microsoft Entra ID, LDAP directories, relational databases (SQL, Oracle), web services/APIs, and flat files. * Write and maintain advanced mapping, join logic, cascading rules, computed attributes, and real-time synchronization pipelines using Radiant Logic native tools and custom scripting. * Implement dynamic context and attribute feeds to power Policy Decision Points (PDP) and Policy Enforcement Points (PEP) across the enterprise identity mesh. * Perform load balancing, context caching, indexing optimization, cluster synchronization, and performance tuning for Radiant Logic clusters to maintain low-latency response times for high-volume authentication/authorization queries. * Manage platform upgrades, version migrations, cluster health checks, backup/disaster recovery procedures, and security hardings (STIG compliance). * Serve as the senior technical escalation point for data synchronization failures, identity resolution edge cases, schema inconsistencies, and directory performance degradation. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)