SME Systems Engineer (Governance Analytics)

GovCIO
Alexandria, VA, United States
18 days ago
Apply on find.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours
Job source

Tech stack

Computer-Aided Design Active Directory Cyber Security Data Integration Federated Identity Management Identity and Access Management OAuth OpenID Performance Tuning Ping (Networking Utility) Public Key Infrastructure Power BI
+11 more
Azure Active Directory Kusto Query Language Zero Trust Network Access Security Assertion Markup Language (SAML) Smart Cards Data Streaming User Provisioning Software Okta SC Clearance SailPoint Restful APIs

Job description

The SME Systems Engineer / ICAM Engineer will serve as a primary technical authority for the enterprise identity management and access control framework. Core responsibilities include:

  • Lead Modernize legacy access controls into robust, secure ICAM solutions.
  • Manage enterprise directories, federation, authentication, authorization, and SSO protocols.
  • Architect identity lifecycles, user provisioning workflows, and privilege management controls.
  • Design and deploy strict Zero Trust identity principles (NIST SP 800-207) across network hubs.
  • Configure and manage enterprise-grade PKI systems, credentials, and authenticators.
  • Implement logical and physical access control systems, including MFA, SSO, and PAM.
  • Build federated identity services to enable secure interoperability with mission partners.
  • Conduct technical root cause analysis, privilege audits, and system performance tuning.
  • Develop custom technical interfaces, architectures, data flows, and compliance documentation.
  • Provide advanced engineering and architecture ownership across the following specialization:
  • Governance, Reporting & Analytics (Primary Product Area: Access Governance (AG)): Architect and build the enterprise ICAM reporting solution using Power BI and other data sources. Engineer the data integrations required to provide comprehensive dashboards on service health, compliance, and access patterns. Develop advanced KQL queries and analytics to support audits and proactive threat hunting.

Requirements

High School with 10+ years (or commensurate experience), * Certifications: DoD 8570 IAT Level II or higher (e.g., Security+ CE, CySA+, or vendor-specific identity certifications).

  • Deep technical understanding of federated identity concepts, including SAML, OAuth, OIDC, and Active Directory / LDAP architecture.
  • Hands-on engineering experience managing Smart Card / Common Access Card (CAC) authentication and PKI certificate validation.
  • Proven experience designing and applying federal Zero Trust identity guidelines (NIST SP 800-207) within enterprise networks.

Clearance Level: Must have an active Secret clearance

Preferred Skills & Experience

  • Prior experience supporting U.S. Coast Guard (USCG) or Department of Homeland Security (DHS) identity management programs.
  • Familiarity with integrating data governance frameworks with ICAM solutions to enforce data-level access controls.
  • Direct experience with enterprise identity tools such as SailPoint, Okta, Microsoft Entra ID, Ping Identity, DigiCert, or Power BI.
  • Advanced knowledge of RESTful API authorization protocols, secure gateways, and data schema security standards.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on find.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann Chris Heilmann +2 · LIVE

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:24 min

Securing cloud deployments by utilizing OpenID Connect mapping

Chris Ayers · LIVE

Videos

See all

Related articles

See all