ICAM / Identity Engineer

Nabout Leidos
United States
3 days ago
Apply on jobs.military.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$87,100.0 - $157,450.0
Working hours
Regular working hours

Tech stack

Java (Programming Language) Audit Trail Cyber Security Information Systems Distributed Systems Federal Information Processing Standards (FIPS) Hardware Security Module Python (Programming Language) Key Management OAuth Ping (Networking Utility) Public Key Infrastructure
+13 more
Role-Based Access Control Openid Connect Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Okta Istio Apigee Kubernetes Information Technology Linkerd (Service Mesh) Api Gateway Golang

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field with 4+ years of relevant experience.(additional experience, education and training may be considered in lieu of degree)\n
  • Hands-on experience with OAuth 2.0 and OpenID Connect, including token validation, introspection, and claims mapping.\n
  • Experience with enterprise identity providers and federation such as Keycloak, Okta, Ping, Microsoft Entra ID, or equivalent.\n
  • Experience implementing RBAC and/or ABAC within distributed applications.\n
  • Working knowledge of PKI, certificate lifecycle management, mutual TLS (mTLS), and/or service mesh identity.\n
  • Understanding of Zero Trust principles, including per-session authorization and default-deny service communication.\n
  • Experience implementing audit logging for access and authorization events.\n
  • Proficiency in Java, Python, Go, or a comparable programming/scripting language.\n
  • Working knowledge of NIST SP 800-53 Access Control (AC) and Audit and Accountability (AU) controls.\n
  • Experience with Kubernetes and containerized service deployments.\n
  • U.S. citizenship required, with the ability to obtain and maintain a Public Trust and successfully complete required government background investigations.\n
  • Must meet FAA facility and information system access requirements, including continuous U.S. residency for at least 3 of the previous 5 years.\n, * Security+ CE, CySA+, or equivalent DoD 8570 IAT Level II certification.\n
  • Federal ICAM/FICAM experience, including PIV/CAC or agency ICAM integrations.\n
  • Experience with SAML 2.0 and SCIM provisioning.\n
  • Experience with Kubernetes RBAC and workload identity (SPIFFE/SPIRE).\n
  • Experience with service mesh implementation (Istio, Linkerd).\n
  • Experience with API gateway authorization policy (Kong, Apigee, or equivalent).\n
  • Familiarity with FIPS 140-3 validated cryptographic modules, hardware security modules, or enterprise key management.\n
  • Knowledge of privileged access management practices.\n
  • Experience in aviation, FAA, or other safety-critical environments.\n
  • Experience with SAFe or large-scale Agile delivery.\n

Benefits & conditions

nThis is a hybrid position requiring 3 days onsite and 2 days working from home, if you are located within a commutable distance (Less than 1 hour’s drive one-way during normal traffic) from \nGaithersburg, MD; Eagan, MN; or Egg Harbor Township, NJ. However, if you do not reside within a commutable distance, you may be considered for a 100% remote role. \n \n In this role, you will implement the identity, credential, and access management (ICAM) layer that governs every user and service interaction with L-CAP. You will integrate the platform with government-provided ICAM services, enforce per-session authorization across distributed mission services, and build the access control and audit foundations that operational and support users depend on.\n \n \nWhat You’ll Do:\n \n \n \n

  • Integrate L-CAP services with government-provided ICAM services using OAuth 2.0 and OpenID Connect, including token issuance, validation, and claims mapping.\n
  • Implement and maintain identity federation and user stores (Keycloak or equivalent), including role-based test account provisioning.\n
  • Implement per-session authentication and authorization for user-to-service and service-to-service requests, enforcing default-deny access regardless of network location.\n
  • Implement mutual TLS (mTLS), service mesh/workload identity, and certificate lifecycle management, including issuance, rotation, expiration monitoring, and revocation.\n
  • Design and implement role-based (RBAC) and attribute-based (ABAC) access controls aligned to operational and support roles.\n
  • Implement authentication and session management for operational users, including sign-in/sign-out and time-on-position logging.\n
  • Implement authentication and authorization audit logging, including event capture, storage, and retrieval.\n
  • Implement API gateway authorization and ensure external-facing endpoints are registered and protected through the API management layer.\n
  • Support security authorization and continuous monitoring by producing ICAM control evidence, resolving identity integration issues across distributed services, and leveraging AI-assisted development and automation to improve quality and delivery.\n, You’ll work on systems where performance, precision, and reliability matter - every second. This is not experimental AI for prototypes. This is disciplined, responsible AI applied to mission-critical software that supports national infrastructure.\n \n If you’re excited by solving complex problems in regulated, real-world environments - and using AI as a force multiplier rather than a shortcut - we’d like to talk.\n \n ATMC\n \n If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 - and moving faster than anyone else dares.\n

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.military.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:24 min

Securing cloud deployments by utilizing OpenID Connect mapping

Chris Ayers · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · World Congress 2026 Europe

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

7:15 min

Installing Istio programmatically with bash scripts

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all