> Markdown version of [/jobs/ext/3027524-icam-identity-engineer](https://www.wearedevelopers.com/jobs/ext/3027524-icam-identity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ICAM / Identity Engineer - **Company:** Nabout Leidos - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $87,100.0 - $157,450.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Audit Trail, Cyber Security, Information Systems, Distributed Systems, Federal Information Processing Standards (FIPS), Hardware Security Module, Python (Programming Language), Key Management, OAuth, Ping (Networking Utility), Public Key Infrastructure, Role-Based Access Control, Openid Connect, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Okta, Istio, Apigee, Kubernetes, Information Technology, Linkerd (Service Mesh), Api Gateway, Golang - **Published:** September 22, 2026 - **Apply:** https://jobs.military.com/career/344133/icam-security-engineer-maryland-md-gaithersburg ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field with 4+ years of relevant experience.(additional experience, education and training may be considered in lieu of degree)\n * Hands-on experience with OAuth 2.0 and OpenID Connect, including token validation, introspection, and claims mapping.\n * Experience with enterprise identity providers and federation such as Keycloak, Okta, Ping, Microsoft Entra ID, or equivalent.\n * Experience implementing RBAC and/or ABAC within distributed applications.\n * Working knowledge of PKI, certificate lifecycle management, mutual TLS (mTLS), and/or service mesh identity.\n * Understanding of Zero Trust principles, including per-session authorization and default-deny service communication.\n * Experience implementing audit logging for access and authorization events.\n * Proficiency in Java, Python, Go, or a comparable programming/scripting language.\n * Working knowledge of NIST SP 800-53 Access Control (AC) and Audit and Accountability (AU) controls.\n * Experience with Kubernetes and containerized service deployments.\n * U.S. citizenship required, with the ability to obtain and maintain a Public Trust and successfully complete required government background investigations.\n * Must meet FAA facility and information system access requirements, including continuous U.S. residency for at least 3 of the previous 5 years.\n, * Security+ CE, CySA+, or equivalent DoD 8570 IAT Level II certification.\n * Federal ICAM/FICAM experience, including PIV/CAC or agency ICAM integrations.\n * Experience with SAML 2.0 and SCIM provisioning.\n * Experience with Kubernetes RBAC and workload identity (SPIFFE/SPIRE).\n * Experience with service mesh implementation (Istio, Linkerd).\n * Experience with API gateway authorization policy (Kong, Apigee, or equivalent).\n * Familiarity with FIPS 140-3 validated cryptographic modules, hardware security modules, or enterprise key management.\n * Knowledge of privileged access management practices.\n * Experience in aviation, FAA, or other safety-critical environments.\n * Experience with SAFe or large-scale Agile delivery.\n ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms](https://www.wearedevelopers.com/magazine/635-dev-digest-188-cfp-time-the-risks-of-npm-and-ikea-algorithms) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)