TS/SCI Identity Provider Engineer

Insight Global
Reston, VA, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Active Directory Active Directory Federation Services Amazon Web Services User Authentication Microsoft Azure Bash Shell Cloud Engineering Multi-Factor Authentication Federated Identity Management Identity and Access Management Python (Programming Language) Lightweight Directory Access Protocols (LDAP)
+16 more
OAuth OpenID Ping (Networking Utility) Windows PowerShell Role-Based Access Control Openid Connect Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) Single Sign-On User Provisioning Software Scripting Google Cloud Cloud Platform System Okta Connectivity Problems

Job description

An employer in the Reston, Virginia area is seeking a TS/SCI Identity Provider Engineer for a direct hire opportunity. In this role, the selected candidate will support large scale Identity and Access Management (IAM) initiatives, helping clients securely manage user access and protect mission critical systems. The engineer will work closely with stakeholders and engineering teams to understand user roles, access requirements, and identity lifecycle needs, and will design, deploy, and support IAM solutions that manage authentication, authorization, and credentials, including single sign on and privileged access. This position will also contribute to the implementation of zero trust and identity based security solutions to prevent unauthorized access and safeguard sensitive data. An active Top Secret clearance with SCI eligibility is required, along with a willingness to complete a CI polygraph. This role requires on site presence five days per week. Can sit in Reston, VA

Requirements

Active TS/SCI clearance (must be willing to take a polygraph)

5+ years of experience with Ping Federate, Okta, Entra ID, or ADFS

Experience with SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC)

Experience with Identity federation and Single Sign-On (SSO)

Experience with access control models such as RBAC and ABAC

Experience integrating IdPs with directory services such as Active Directory (AD) and LDAP, including synchronization and authentication workflows

Knowledge of Zero Trust architectures and implementation of password-less authentication or multifactor authentication (MFA) within the IdP environment

Ability to resolve complex identity and federation issues, including token validation errors, assertion mismatches, and connectivity problems

Ability to design and operate IdP solutions across on-premises, hybrid, and cloud infrastructures, including AWS, Azure, or Google Cloud Experience implementing System for Cross-domain Identity Management (SCIM) protocols for automated user provisioning and lifecycle management between identity providers and applications

Experience with advanced platform features such as Okta Workflows, Ping Identity Suite advanced policy scripting, adaptive authentication, and the development of custom login pages

Experience with scripting languages such as Python, PowerShell, or Bash to automate IdP configuration, monitoring, and remediation tasks

Knowledge of cloud-native IAM services, including Azure Active Directory, AWS IAM, or Google Cloud Identity

TS/SCI clearance with a polygraph

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:24 min

Securing cloud deployments by utilizing OpenID Connect mapping

Chris Ayers · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all