> Markdown version of [/jobs/ext/2643986-icam-identity-provider-idp-engineer-enterprise-authentication-services](https://www.wearedevelopers.com/jobs/ext/2643986-icam-identity-provider-idp-engineer-enterprise-authentication-services). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ICAM Identity Provider (IdP) Engineer - Enterprise Authentication Services - **Company:** General Dynamics Information Technology - **Location:** Fort Meade, MD, United States - **Experience:** Experienced - **Salary:** $140,250.0 - $189,750.0 - **Contract:** Contract - **Skills:** Microsoft Windows, Active Directory, Active Directory Federation Services, Agile Methodology, Application Integration Architecture, User Authentication, Authentication Protocols, Cloud Computing, CompTIA Security+, Cyber Security, Disaster Recovery, Multi-Factor Authentication, Identity and Access Management, Lightweight Directory Access Protocols (LDAP), Linux Servers, OAuth, OpenID, Performance Tuning, Public Key Infrastructure, Windows PowerShell, Openid Connect, Azure Active Directory, Phishing, Zero Trust Network Access, Security Assertion Markup Language (SAML), Single Sign-On, Smart Cards, Web Applications, Load Balancing, Okta, Ws-federation, Pingfederate, Kubernetes, Api Management, Docker - **Published:** August 16, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3356004609&tx=FK906PFK&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role Authentication Protocols,Secure Authentication,Single Sign-On (SSO) Certifications: CompTIA Security+ CE | CompTIA - CompTIA Experience: 3 + years of related experience, The ideal candidate has at least 3 years of hands-on experience supporting authentication or identity systems and is eager to grow deeper into enterprise ICAM technologies. Strong foundational skills in Microsoft Active Directory Federation Services (ADFS), authentication protocols, and troubleshooting are essential. This role provides opportunities to work with senior engineers, contribute to mission-critical authentication services, and expand your technical skillset across large-scale identity platforms., * Active Secret Clearance (Interim Secret not allowed). * Bachelor's degree in a related technical field, or equivalent combination of education, certifications, and experience. * DoD 8570/8140 IAT Level II certification (Security+ CE or higher). Required Skills & Knowledge * Minimum 3 years of experience supporting Identity and Access Management (IAM), Authentication, Federation, or ICAM-related technologies. * Experience supporting or implementing Microsoft ADFS in enterprise environments. * Strong understanding of authentication, authorization, and federation concepts. * Familiarity with SAML, OAuth, OIDC, WS-Federation, and related identity technologies. * Experience with PKI, certificate-based authentication, smart cards, or MFA. * Experience supporting application or API integrations with identity/federation platforms. * Familiarity with Active Directory, LDAP, and enterprise identity repositories. * Ability to configure or support claims rules, attribute mappings, or token policies. * Experience working with Windows or Linux server environments. * Ability to document technical findings and communicate effectively. * Self-starter with a desire to learn and grow in enterprise identity operations. Desired Skills & Knowledge * Experience with ADFS farms, Web Application Proxy (WAP), load balancers, or disaster recovery setups. * Exposure to modern identity platforms such as Microsoft Entra ID, PingFederate, PingAccess, Okta, or Keycloak. * Familiarity with DoD ICAM or federation initiatives. * Understanding of NIST 800-63 Identity Assurance models. * Exposure to phishing-resistant authentication or passwordless technologies. * Experience supporting Zero Trust concepts. * Basic PowerShell scripting for ADFS or identity operations. * Experience with monitoring, performance tuning, or troubleshooting authentication issues at scale. * Familiarity with PKI/certificate services, CAC authentication, or DoD credentialing. * Awareness of container technologies (Docker, Kubernetes). ## Description * Support the design, configuration, and sustainment of enterprise Identity Provider (IdP) services used by millions of DoD users. * Assist in administering and maintaining Microsoft Active Directory Federation Services (ADFS) infrastructure supporting authentication and federation. * Help configure federation trust relationships with internal and external Identity Providers (IdPs), Service Providers (SPs), and mission partners. * Implement and troubleshoot authentication solutions using SAML, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication. * Collaborate in onboarding and integrating applications into the authentication and federation ecosystem. * Help develop and maintain authentication policies, claims rules, attribute mappings, and token issuance configurations. * Support enterprise Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, and phishing-resistant authentication mechanisms. * Work with cybersecurity, Active Directory, cloud, infrastructure, and application teams to deliver secure authentication services. * Contribute to Zero Trust Architecture objectives through modern authentication and federation capabilities. * Assist in monitoring, troubleshooting, and resolving authentication, federation, trust, certificate, and token issues. * Support the development of resilient, highly available authentication services for mission-critical workloads. * Help create technical documentation including architecture diagrams, SOPs, integration guides, and operational procedures. * Participate in Agile development activities and continuous improvement efforts. * Identify technical risks and contribute to identity modernization initiatives. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)