> Markdown version of [/jobs/ext/3034432-comptia-cybersecurity-analyst-cysa-systems-security-certified-practitioner](https://www.wearedevelopers.com/jobs/ext/3034432-comptia-cybersecurity-analyst-cysa-systems-security-certified-practitioner). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # CompTIA Cybersecurity Analyst (CySA+) Systems Security Certified Practitioner - **Company:** CareerCircle - **Location:** Pittsburgh, PA, United States (Remote available) - **Experience:** Experienced - **Salary:** $87,100.0 - $157,450.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Microsoft Excel, Microsoft Windows, Access Network, Application Programming Interfaces (APIs), Agile Methodology, Artificial Intelligence, Antivirus Softwares, Software System Penetration Testing, Audit Trail, User Authentication, Microsoft Azure, Microsoft Outlook, Cloud Computing, Software Quality, CompTIA Security+, Cyber Security, Information Systems, Digital Forensics, Distributed Systems, Federal Information Processing Standards (FIPS), Hardware Security Module, Network Topologies, Identity and Access Management, Networking Hardware, Intrusion Detection and Prevention, Virtual Private Networks (VPN), Python (Programming Language), Key Management, Network Security, Nagios, Network Monitoring, Network Segmentation, Network Protocols, Open Shortest Path First (OSPF), OAuth, OpenID, Performance Tuning, Ping (Networking Utility), Public Key Infrastructure, Role-Based Access Control, Openid Connect, Azure Active Directory, Cloud Services, Ansible, Zero Trust Network Access, Security Assertion Markup Language (SAML), Session Management, Microsoft SharePoint, VMware Infrastructure, Software Vulnerability Management, Zabbix, Data Logging, Network Switches, Network Routing, Scripting, Transport Layer Security, Okta, Istio, Cyber Threat Analysis, HybridCloud, Apigee, Firewalls (Computer Science), Build Management, Kubernetes, Infrastructure Automation Frameworks, Information Technology, Low Latency, SolarWinds (Software), Linkerd (Service Mesh), Api Gateway, Terraform, Open Network Automation Platform, Api Management, Vulnerability Analysis, Golang, Programming Languages - **Published:** September 23, 2026 - **Apply:** https://www.careercircle.com/jobs/all/all/usa/nj/egg-harbor-township/b8074fcd-7d1a-4529-a924-9ca660f7dd2c ## About the Role Management Automation Kubernetes SAFe Agile Market Data NIST 800-53 API Gateway Cryptography ANSYS Meshing Accountability Cyber Security API Management Responsible AI Authentications Access Controls Computer Science Agile Methodology CompTIA Security+ Lifecycle Management Continuous Monitoring Information Technology Hybrid Cloud Computing Air Traffic Management Education and Training Hardware Security Module Authorization (Computing) Go (Programming Language) Public Key Infrastructure Software Quality (SQA/SQC) IAT Level II Certification Session (Computer Science) Java (Programming Language) Privileged Access Management Python (Programming Language) Federal Aviation Administration Role-Based Access Control (RBAC) CompTIA Cybersecurity Analyst (CySA+) Security Assertion Markup Language (SAML) Federal Information Processing Standards (FIPS), * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field with 4+ years of relevant experience. (additional experience, education and training may be considered in lieu of degree) * Hands-on experience with OAuth 2.0 and OpenID Connect, including token validation, introspection, and claims mapping. * Experience with enterprise identity providers and federation such as Keycloak, Okta, Ping, Microsoft Entra ID, or equivalent. * Experience implementing RBAC and/or ABAC within distributed applications. * Working knowledge of PKI, certificate lifecycle management, mutual TLS (mTLS), and/or service mesh identity. * Understanding of Zero Trust principles, including per-session authorization and default-deny service communication. * Experience implementing audit logging for access and authorization events. * Proficiency in Java, Python, Go, or a comparable programming/scripting language. * Working knowledge of NIST SP 800-53 Access Control (AC) and Audit and Accountability (AU) controls. * Experience with Kubernetes and containerized service deployments. * U.S. citizenship required, with the ability to obtain and maintain a Public Trust and successfully complete required government background investigations. * Must meet FAA facility and information system access requirements, including continuous U.S. residency for at least 3 of the previous 5 years. Preferred / Desired Qualifications: * Security+ CE, CySA+, or equivalent DoD 8570 IAT Level II certification. * Federal ICAM/FICAM experience, including PIV/CAC or agency ICAM integrations. * Experience with SAML 2.0 and SCIM provisioning. * Experience with Kubernetes RBAC and workload identity (SPIFFE/SPIRE). * Experience with service mesh implementation (Istio, Linkerd). * Experience with API gateway authorization policy (Kong, Apigee, or equivalent). * Familiarity with FIPS 140-3 validated cryptographic modules, hardware security modules, or enterprise key management. * Knowledge of privileged access management practices. * Experience in aviation, FAA, or other safety-critical environments. * Experience with SAFe or large-scale Agile delivery. Why Leidos? You'll work on systems where performance, precision, and reliability matter - every second. This is not experimental AI for prototypes. This is disciplined, responsible AI applied to mission-critical software that supports national infrastructure. If you're excited by solving complex problems in regulated, real-world environments - and using AI as a force multiplier rather than a shortcut - we'd like to talk., Leadership Governance Positivity Communication Investigation Cyber Security Cloud Services Risk Management Problem Solving Customer Service Network Security Threat Detection Security Controls Incident Response Digital Forensics Business Valuation Penetration Testing Security Technology GIAC Certifications Time Off Management Security Engineering Cyber Threat Hunting CompTIA Certification Full Stack Development Business Transformation Vulnerability Management Vulnerability Assessments Cyber Threat Intelligence Microsoft Defender Antivirus Continuous Improvement Process Virtual Private Networks (VPN) Transport Layer Security (TLS) Endpoint Detection And Response, Nagios Zabbix Ansible Firewall Textiles NIST 800 Scripting Telemetry Terraform AI Agents Operations Automation Governance Innovation SolarWinds Scalability Low Latency Cisco Meraki Communication Observability Microsoft 365 Cyber Security Access Network Professionalism Microsoft Excel Microsoft Azure Network Routing Computer Science Network Switches Network Security Network Topology Microsoft Outlook Analytical Skills Network Protocols Policy Management Performance Tuning Telecommunications Security Clearance Network Monitoring Network Automation Workflow Management Networking Hardware Network Engineering Time Off Management Microsoft SharePoint Network Segmentation VMware Infrastructure, Python (Programming Language) Zero Trust Architecture (ZTA) Network Performance Management Identity And Access Management Open Shortest Path First (OSPF) Network Quality Of Service (QoS) Troubleshooting (Problem Solving) Application Programming Interface (API) Cloud Access Security Broker Tools (CASBs) +0 ## Description OAuth Istio OpenID Apigee Auditing Aviation Equities, Leidos is seeking an ICAM / Identity Engineer to join the Air Traffic Business Area within the Homeland Sector, supporting the development of the Leidos Common Automation Platform (L-CAP). L-CAP is a mission-critical, future-ready automation platform built on a hybrid cloud data mesh architecture, enabling next-generation air traffic management capabilities. We are building with an AI-first engineering mindset, embracing emerging AI capabilities and modern development practices to accelerate delivery, improve software quality, and continuously evolve how we design and build mission-critical systems. This role operates within a SAFe/Agile framework as part of an Agile Release Train (ART) delivering iterative value across the program. This position supports government programs and requires the ability to obtain and maintain a favorable Public Trust investigation. This is a hybrid position requiring 3 days onsite and 2 days working from home, if you are located within a commutable distance (Less than 1 hour's drive one-way during normal traffic) from Gaithersburg, MD; Eagan, MN; or Egg Harbor Township, NJ. However, if you do not reside within a commutable distance, you may be considered for a 100% remote role. In this role, you will implement the identity, credential, and access management (ICAM) layer that governs every user and service interaction with L-CAP. You will integrate the platform with government-provided ICAM services, enforce per-session authorization across distributed mission services, and build the access control and audit foundations that operational and support users depend on. What You'll Do: * Integrate L-CAP services with government-provided ICAM services using OAuth 2.0 and OpenID Connect, including token issuance, validation, and claims mapping. * Implement and maintain identity federation and user stores (Keycloak or equivalent), including role-based test account provisioning. * Implement per-session authentication and authorization for user-to-service and service-to-service requests, enforcing default-deny access regardless of network location. * Implement mutual TLS (mTLS), service mesh/workload identity, and certificate lifecycle management, including issuance, rotation, expiration monitoring, and revocation. * Design and implement role-based (RBAC) and attribute-based (ABAC) access controls aligned to operational and support roles. * Implement authentication and session management for operational users, including sign-in/sign-out and time-on-position logging. * Implement authentication and authorization audit logging, including event capture, storage, and retrieval. * Implement API gateway authorization and ensure external-facing endpoints are registered and protected through the API management layer. * Support security authorization and continuous monitoring by producing ICAM control evidence, resolving identity integration issues across distributed services, and leveraging AI-assisted development and automation to improve quality and delivery., Operations Automation Encryption Cryptography Key Management Risk Management Business Valuation Enterprise Security Quantum Cryptography Full Stack Development Business Transformation Public Key Infrastructure Application Programming Interface (API) Federal Information Processing Standards (FIPS) +0 Information Security Engineer ONSITE In Fort Collins, CO TEKsystems Fort Collins, CO*Remote ## Related Videos - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)