ICAM / Identity Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+13 more
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field with 4+ years of relevant experience.(additional experience, education and training may be considered in lieu of degree)\n
- Hands-on experience with OAuth 2.0 and OpenID Connect, including token validation, introspection, and claims mapping.\n
- Experience with enterprise identity providers and federation such as Keycloak, Okta, Ping, Microsoft Entra ID, or equivalent.\n
- Experience implementing RBAC and/or ABAC within distributed applications.\n
- Working knowledge of PKI, certificate lifecycle management, mutual TLS (mTLS), and/or service mesh identity.\n
- Understanding of Zero Trust principles, including per-session authorization and default-deny service communication.\n
- Experience implementing audit logging for access and authorization events.\n
- Proficiency in Java, Python, Go, or a comparable programming/scripting language.\n
- Working knowledge of NIST SP 800-53 Access Control (AC) and Audit and Accountability (AU) controls.\n
- Experience with Kubernetes and containerized service deployments.\n
- U.S. citizenship required, with the ability to obtain and maintain a Public Trust and successfully complete required government background investigations.\n
- Must meet FAA facility and information system access requirements, including continuous U.S. residency for at least 3 of the previous 5 years.\n, * Security+ CE, CySA+, or equivalent DoD 8570 IAT Level II certification.\n
- Federal ICAM/FICAM experience, including PIV/CAC or agency ICAM integrations.\n
- Experience with SAML 2.0 and SCIM provisioning.\n
- Experience with Kubernetes RBAC and workload identity (SPIFFE/SPIRE).\n
- Experience with service mesh implementation (Istio, Linkerd).\n
- Experience with API gateway authorization policy (Kong, Apigee, or equivalent).\n
- Familiarity with FIPS 140-3 validated cryptographic modules, hardware security modules, or enterprise key management.\n
- Knowledge of privileged access management practices.\n
- Experience in aviation, FAA, or other safety-critical environments.\n
- Experience with SAFe or large-scale Agile delivery.\n
Benefits & conditions
nThis is a hybrid position requiring 3 days onsite and 2 days working from home, if you are located within a commutable distance (Less than 1 hour’s drive one-way during normal traffic) from \nGaithersburg, MD; Eagan, MN; or Egg Harbor Township, NJ. However, if you do not reside within a commutable distance, you may be considered for a 100% remote role. \n \n In this role, you will implement the identity, credential, and access management (ICAM) layer that governs every user and service interaction with L-CAP. You will integrate the platform with government-provided ICAM services, enforce per-session authorization across distributed mission services, and build the access control and audit foundations that operational and support users depend on.\n \n \nWhat You’ll Do:\n \n \n \n
- Integrate L-CAP services with government-provided ICAM services using OAuth 2.0 and OpenID Connect, including token issuance, validation, and claims mapping.\n
- Implement and maintain identity federation and user stores (Keycloak or equivalent), including role-based test account provisioning.\n
- Implement per-session authentication and authorization for user-to-service and service-to-service requests, enforcing default-deny access regardless of network location.\n
- Implement mutual TLS (mTLS), service mesh/workload identity, and certificate lifecycle management, including issuance, rotation, expiration monitoring, and revocation.\n
- Design and implement role-based (RBAC) and attribute-based (ABAC) access controls aligned to operational and support roles.\n
- Implement authentication and session management for operational users, including sign-in/sign-out and time-on-position logging.\n
- Implement authentication and authorization audit logging, including event capture, storage, and retrieval.\n
- Implement API gateway authorization and ensure external-facing endpoints are registered and protected through the API management layer.\n
- Support security authorization and continuous monitoring by producing ICAM control evidence, resolving identity integration issues across distributed services, and leveraging AI-assisted development and automation to improve quality and delivery.\n, You’ll work on systems where performance, precision, and reliability matter - every second. This is not experimental AI for prototypes. This is disciplined, responsible AI applied to mission-critical software that supports national infrastructure.\n \n If you’re excited by solving complex problems in regulated, real-world environments - and using AI as a force multiplier rather than a shortcut - we’d like to talk.\n \n ATMC\n \n If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 - and moving faster than anyone else dares.\n
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Highest Paying Tech Companies for Developers
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms