> Markdown version of [/jobs/ext/527670-icam-authentication-federation-engineer](https://www.wearedevelopers.com/jobs/ext/527670-icam-authentication-federation-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ICAM Authentication & Federation Engineer - **Company:** General Dynamics Information Technology - **Location:** Fort Meade, MD, United States - **Experience:** Expert - **Salary:** $144,500.0 - $195,500.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Active Directory Federation Services, Application Programming Interfaces (APIs), Agile Methodology, Artificial Intelligence, Application Integration Architecture, User Authentication, Cyber Security, Linux, Identity and Access Management, Lightweight Directory Access Protocols (LDAP), Windows Servers, OAuth, OpenID, Public Key Infrastructure, Openid Connect, Phishing, Zero Trust Network Access, Security Assertion Markup Language (SAML), Single Sign-On, Smart Cards, Systems Integration, Okta, System Availability, Ws-federation, Containerization, Pingfederate, Multiaccess Edge Computing, Docker - **Published:** June 5, 2026 - **Apply:** https://www.gdit.com/careers/job/8d680dfa6/icam-authentication-federation-engineer-edge-services/ ## About the Role WHAT YOU'LL NEED TO SUCCEED (Required):Education: Bachelor's Degree. An additional 4 years of experience mat be substituted in lieu of degree.Clearance: Minimum of an active Secret security clearance.Certification: 8570/8140 IAT Level II certification (Security+ CE or higher).Experience: 10+ years' experience supporting Identity and Access Management (IAM), Authentication, Federation, or ICAM solutions within government or regulated environments.Technical Skills: * Strong experience with PingFederate or equivalent federation technologies. * Experience implementing and supporting enterprise Identity Provider (IdP) and federation services. * Strong understanding of authentication, authorization, federation, and identity assurance concepts. * Experience implementing and troubleshooting SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and JWT technologies. * Experience supporting PKI, certificate-based authentication, smart card authentication, and MFA solutions. * Experience integrating applications, APIs, and enterprise services with federation platforms. * Experience with Active Directory, LDAP directories, and enterprise identity repositories. * Experience configuring claims, attribute mappings, policy enforcement, token transformations, and federation workflows. * Experience supporting Linux and/or Windows Server environments. * Experience deploying and supporting enterprise COTS products in secure customer environments. * Experience working in Agile development environments and utilizing associated tools. Desired Skills (Preferred): * Experience with PingFederate clustering, high availability, and large-scale federation deployments. * Experience with PingAccess, PingDirectory, PingOne, Okta, Entra ID, ADFS, Keycloak, or similar authentication platforms. * Experience supporting DoW Enterprise ICAM, Federation Hub, or mission partner federation initiatives. * Experience implementing federation solutions for coalition, partner, or cross-organizational environments. * Experience supporting NIST 800-63 Identity Assurance Levels (IAL), Authenticator Assurance Levels (AAL), and Federation Assurance Levels (FAL). * Experience with phishing-resistant authentication technologies and passwordless authentication solutions. * Experience supporting disconnected, intermittent, low-bandwidth (DDIL) operational environments. * Experience implementing federation solutions supporting tactical, expeditionary, or edge-computing use cases. * Experience supporting Zero Trust Architecture and identity-centric security initiatives. * Experience with container technologies such as Docker and Kubernetes. * Familiarity with DoW PKI, CAC authentication, derived credentials, and certificate lifecycle management. * Experience supporting FVEY, NATO, coalition, or mission partner federation architectures., 8 + years of related experience * may vary based on technical training, certification(s), or degree Certification CompTIA Security+ CE | CompTIA - CompTIA Travel Required ## Description GDIT has an opportunity for an ICAM Engineer supporting a large line of business that delivers enterprise-scale Identity, Credential, and Access Management (ICAM) capabilities. This role supports the DoW ICAM mission by designing, developing, integrating, and maintaining Authentication and Federation services that enable secure access across enterprise, mission partner, coalition, tactical, and edge computing environments.The ideal candidate is a senior hands-on identity engineer with expertise in PingFederate, enterprise Identity Providers (IdPs), federation services, and modern authentication technologies. This role focuses on authentication, federation, trust management, single sign-on (SSO), multi-factor authentication (MFA), and extending enterprise identity services to support distributed and disconnected operational environments.This position is a Hybrid role with an estimated 25% of time expected on-site at our Fort Meade, MD facility.HOW YOU WILL MAKE AN IMPACT: * Design, develop, configure, and maintain enterprise authentication and federation services supporting both enterprise and edge ICAM architectures. * Support PingFederate and related identity platforms used to provide authentication, federation, single sign-on (SSO), and trust management services. * Engineer federation solutions that extend secure identity services to mission partners, coalition organizations, tactical users, and edge computing environments. * Configure and maintain trust relationships with internal and external Identity Providers (IdPs), Service Providers (SPs), and federation partners. * Develop and maintain integrations utilizing SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and PKI-based authentication technologies. * Support onboarding and integration of applications, mission partners, and external organizations into enterprise federation ecosystems. * Design and implement authentication flows, token services, claims transformation, attribute mapping, and policy enforcement mechanisms. * Support MFA, phishing-resistant authentication, certificate-based authentication, and emerging identity assurance capabilities. * Collaborate with cybersecurity, cloud, infrastructure, and application teams to implement secure authentication and federation solutions. * Support implementation of Zero Trust Architecture through modern authentication, federation, and identity assurance services. * Troubleshoot and resolve complex issues involving authentication, federation, trust relationships, certificates, tokens, and identity assertions. * Support deployment and sustainment of identity services operating in disconnected, intermittent, low-bandwidth (DDIL), and edge environments. * Develop technical documentation including architecture diagrams, integration guides, SOPs, TTPs, and onboarding documentation. * Participate in Agile development activities and support continuous improvement initiatives. * Actively manage technical risks and contribute to mission readiness objectives. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [MFA? Game over! Watch your protection collapse – live](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [The best of two worlds - Bringing enterprise-grade Linux to the vehicle](https://www.wearedevelopers.com/videos/67-the-best-of-two-worlds-bringing-enterprise-grade-linux-to-the-vehicle) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [5 Reasons Why Attending Conferences in 2026 Matters More Than You Think](https://www.wearedevelopers.com/magazine/692-5-reasons-why-attending-conferences-in-2026-matters-more-than-you-think) - [What Makes WeAreDevelopers World Congress Different From Every Other Tech Event?](https://www.wearedevelopers.com/magazine/701-what-makes-wearedevelopers-world-congress-different-from-every-other-tech-event) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)