ICAM/IAM Security Engineer (REMOTE)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+16 more
Job description
We are seeking an Identity and Access Management Engineer to support a growing federal cybersecurity program. This position will help design, implement, and operationalize enterprise Identity, Credential, and Access Management solutions across cloud and on-premises environments.
The ideal candidate is a hands-on identity engineer who has participated in ICAM implementations from planning through deployment and application onboarding. This is not a governance, audit, or purely advisory position. The team needs someone who understands identity architecture but is also comfortable configuring platforms, integrating applications, troubleshooting technical issues, and working directly with stakeholders.
Responsibilities Support the design, implementation, deployment, and ongoing management of enterprise ICAM solutions Configure and integrate identity platforms such as Okta, SailPoint, Ping Identity, CyberArk, or comparable IAM technologies Participate in full lifecycle ICAM implementations, from requirements gathering and solution design through deployment, testing, and operational support Lead or support the onboarding of applications into identity management, governance, and access management platforms Work directly with application owners and stakeholders to collect requirements, identify technical dependencies, resolve onboarding challenges, and drive adoption Implement identity lifecycle processes, including: User provisioning and deprovisioning Joiner, mover, and leaver workflows Access requests and approvals Entitlement management Periodic access reviews and recertification Configure and troubleshoot Single Sign-On, Multi-Factor Authentication, identity federation, authentication, authorization, and directory services Integrate ICAM solutions with enterprise applications, APIs, directories, cloud platforms, and on-premises infrastructure Develop and enforce access control policies and technical standards aligned with federal ICAM requirements and Zero Trust principles Support identity services across IaaS, PaaS, SaaS, and traditional data center environments Identify and resolve technical or organizational friction points that affect application onboarding and identity program adoption Translate federal mission and security requirements into practical identity solutions and implementation plans Collaborate with cybersecurity engineers, architects, application teams, infrastructure teams, and client stakeholders Document technical designs, configurations, integration requirements, implementation procedures, and operational processes Provide technical guidance to junior engineers and support the review of implementation work, The position may be performed primarily remotely, with occasional travel for client meetings or project-specific requirements Candidates located in the National Capital Region or St. Louis area may receive additional consideration based on current and future program needs Candidates supporting the program from St. Louis should be comfortable with periodic onsite client support, potentially up to three days per week based on project needs Onsite expectations may remain flexible depending on the individual, location, and client requirements
Requirements
Approximately four or more years of cybersecurity, identity engineering, or related technical experience Hands-on experience implementing, configuring, integrating, or supporting enterprise identity and access management solutions Experience with at least one enterprise identity platform, such as: Okta SailPoint IdentityIQ or IdentityNow Ping Identity CyberArk A comparable IAM, IGA, access management, or PAM platform Experience supporting one or more of the following: Identity Governance and Administration Access Management Single Sign-On Multi-Factor Authentication Identity federation Privileged Access Management Identity lifecycle management Demonstrated experience participating in a technical implementation rather than only auditing, assessing, or providing governance oversight Experience integrating identity platforms with applications, directories, APIs, or enterprise infrastructure Understanding of identity architecture and the processes required to operationalize an enterprise identity program Experience gathering requirements and working with application owners or business stakeholders during application onboarding Strong troubleshooting and problem-solving skills Ability to clearly communicate technical concepts to both technical and non-technical stakeholders Bachelor’s degree from an accredited college or university Active U.S. Government Secret clearance, Experience supporting U.S. federal government clients or federal cybersecurity programs Knowledge of federal identity standards and frameworks, including: Federal Identity, Credential, and Access Management HSPD-12 PIV and CAC authentication NIST SP 800-53 NIST SP 800-63 Digital Identity Guidelines Experience implementing identity capabilities within a broader Zero Trust security model Experience with identity services in AWS, Microsoft Azure, or Google Cloud Platform Experience onboarding multiple applications into an IAM, IGA, or access management platform Experience working across both cloud and on-premises environments Platform-specific certifications from Okta, SailPoint, Ping Identity, or CyberArk Cybersecurity certifications such as CISSP, GSEC, or GCED, · This position requires an active DoD Clearance (Secret, Top Secret, Top Secret/SCI) or the ability to be obtain an (Interim Secret, Interim Top Secret) · Because an active or interim DoD clearance is required, U.S. Citizenship is required
Benefits & conditions
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following:
- Medical, dental & vision
- Critical Illness, Accident, and Hospital
- 401(k) Retirement Plan - Pre-tax and Roth post-tax contributions available
- Life Insurance (Voluntary Life & AD&D for the employee and dependents)
- Short and long-term disability
- Health Spending Account (HSA)
- Transportation benefits
- Employee Assistance Program
- Time Off/Leave (PTO, Vacation or Sick Leave)
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Fully Remote Software Engineer Jobs
Dev Digest 134 - Where pixels sing?
Best Paying Jobs in Technology
Is Software Engineering Over-Saturated?