> Markdown version of [/jobs/ext/512629-ts-sci-identity-provider-engineer](https://www.wearedevelopers.com/jobs/ext/512629-ts-sci-identity-provider-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # TS/SCI Identity Provider Engineer - **Company:** Insight Global - **Location:** Reston, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Active Directory Federation Services, Amazon Web Services, User Authentication, Microsoft Azure, Bash Shell, Cloud Engineering, Multi-Factor Authentication, Federated Identity Management, Identity and Access Management, Python (Programming Language), Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Ping (Networking Utility), Windows PowerShell, Role-Based Access Control, Openid Connect, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Single Sign-On, User Provisioning Software, Scripting, Google Cloud, Cloud Platform System, Okta, Connectivity Problems - **Published:** June 11, 2026 - **Apply:** https://www.juju.com/job/00000000g7enlw ## About the Role Active TS/SCI clearance (must be willing to take a polygraph) 5+ years of experience with Ping Federate, Okta, Entra ID, or ADFS Experience with SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC) Experience with Identity federation and Single Sign-On (SSO) Experience with access control models such as RBAC and ABAC Experience integrating IdPs with directory services such as Active Directory (AD) and LDAP, including synchronization and authentication workflows Knowledge of Zero Trust architectures and implementation of password-less authentication or multifactor authentication (MFA) within the IdP environment Ability to resolve complex identity and federation issues, including token validation errors, assertion mismatches, and connectivity problems Ability to design and operate IdP solutions across on-premises, hybrid, and cloud infrastructures, including AWS, Azure, or Google Cloud Experience implementing System for Cross-domain Identity Management (SCIM) protocols for automated user provisioning and lifecycle management between identity providers and applications Experience with advanced platform features such as Okta Workflows, Ping Identity Suite advanced policy scripting, adaptive authentication, and the development of custom login pages Experience with scripting languages such as Python, PowerShell, or Bash to automate IdP configuration, monitoring, and remediation tasks Knowledge of cloud-native IAM services, including Azure Active Directory, AWS IAM, or Google Cloud Identity TS/SCI clearance with a polygraph ## Description An employer in the Reston, Virginia area is seeking a TS/SCI Identity Provider Engineer for a direct hire opportunity. In this role, the selected candidate will support large scale Identity and Access Management (IAM) initiatives, helping clients securely manage user access and protect mission critical systems. The engineer will work closely with stakeholders and engineering teams to understand user roles, access requirements, and identity lifecycle needs, and will design, deploy, and support IAM solutions that manage authentication, authorization, and credentials, including single sign on and privileged access. This position will also contribute to the implementation of zero trust and identity based security solutions to prevent unauthorized access and safeguard sensitive data. An active Top Secret clearance with SCI eligibility is required, along with a willingness to complete a CI polygraph. This role requires on site presence five days per week. Can sit in Reston, VA ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [No More Post-its: Boost your login security with APIs](https://www.wearedevelopers.com/videos/1043-no-more-post-its-boost-your-login-security-with-apis) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers)