> Markdown version of [/jobs/ext/2832950-sme-systems-engineer-icam-architect](https://www.wearedevelopers.com/jobs/ext/2832950-sme-systems-engineer-icam-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SME Systems Engineer (ICAM Architect) - **Company:** GovCIO - **Location:** Alexandria, VA, United States - **Experience:** Expert - **Salary:** $172,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Active Directory, Domain Controllers, Systems Engineering, Cyber Security, Data Integration, Federated Identity Management, Identity and Access Management, Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Performance Tuning, Ping (Networking Utility), Public Key Infrastructure, Power BI, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Smart Cards, Data Streaming, User Provisioning Software, Okta, SC Clearance, SailPoint, Restful APIs - **Published:** September 10, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9152587/sme-systems-engineer-icam-architect ## About the Role High School with 10+ years (or commensurate experience), * Certifications: DoD 8570 IAT Level II or higher (e.g., Security+ CE, CySA+, or vendor-specific identity certifications). * Deep technical understanding of federated identity concepts, including SAML, OAuth, OIDC, and Active Directory / LDAP architecture. * Hands-on engineering experience managing Smart Card / Common Access Card (CAC) authentication and PKI certificate validation. * Proven experience designing and applying federal Zero Trust identity guidelines (NIST SP 800-207) within enterprise networks. Clearance required: Must have an active Secret clearance Preferred Skills & Experience * Prior experience supporting U.S. Coast Guard (USCG) or Department of Homeland Security (DHS) identity management programs. * Familiarity with integrating data governance frameworks with ICAM solutions to enforce data-level access controls. * Direct experience with enterprise identity tools such as SailPoint, Okta, Microsoft Entra ID, Ping Identity, DigiCert, or Power BI. * Advanced knowledge of RESTful API authorization protocols, secure gateways, and data schema security standards. ## Description The SME Systems Engineer / ICAM Engineer will serve as a primary technical authority for the enterprise identity management and access control framework. Core responsibilities include: * Lead Modernize legacy access controls into robust, secure ICAM solutions. * Manage enterprise directories, federation, authentication, authorization, and SSO protocols. * Architect identity lifecycles, user provisioning workflows, and privilege management controls. * Design and deploy strict Zero Trust identity principles (NIST SP 800-207) across network hubs. * Configure and manage enterprise-grade PKI systems, credentials, and authenticators. * Implement logical and physical access control systems, including MFA, SSO, and PAM. * Build federated identity services to enable secure interoperability with mission partners. * Conduct technical root cause analysis, privilege audits, and system performance tuning. * Develop custom technical interfaces, architectures, data flows, and compliance documentation. * Provide advanced engineering and architecture ownership across the following specialization: + ICAM Enterprise Architecture (Primary Product Area: Cross-cutting support for all product lines): Serve as the chief technical architect for the consolidated ICAM enterprise. Own the overarching hybrid identity strategy, ensuring the on-premises Active Directory and the Entra ID tenant are designed to function as a seamless, secure, and integrated system. Own the architectural design, placement, and lifecycle strategy for all Domain Controllers (DCs). Ensure that solutions designed by the other SMEs are interoperable and aligned with overall enterprise architecture standards. Lead the technical design for large-scale, cross-product initiatives and act as the primary technical liaison between the ICAM team and other enterprise architecture groups. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)