> Markdown version of [/jobs/ext/577003-aws-cloud-infrastructure-engineer-keycloak-specialty](https://www.wearedevelopers.com/jobs/ext/577003-aws-cloud-infrastructure-engineer-keycloak-specialty). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AWS Cloud Infrastructure Engineer (Keycloak Specialty) - **Company:** General Dynamics Information Technology - **Location:** Indianapolis, IN, United States (Remote available) - **Experience:** Expert - **Salary:** $153,000.0 - $207,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Access, Adobe InDesign, Application Programming Interfaces (APIs), Agile Methodology, Amazon Web Services, Software System Penetration Testing, Confluence, JIRA, User Authentication, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Information Systems, Federated Identity Management, Identity and Access Management, Information Security Management, Information Systems Security Architecture Professional, Network Security, Microsoft Visio, OAuth, OpenID, Public Key Infrastructure, Role-Based Access Control, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Microsoft SharePoint, Single Sign-On, Statistical Process Control (SPC), Software Vulnerability Management, SSL Certificate Management, Data Logging, Okta, Cyberark, Apigee, Customer Identity Access Management, Infrastructure Automation Frameworks, Hashicorp, Api Gateway, SailPoint, Splunk, Devsecops, Api Management, Microservices - **Published:** June 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=965427b8c291d940 ## About the Role Do you have experience in Zero Trust security?, Do you have a Master's degree?, * Education: Bachelor's Degree in Cybersecurity, Information Systems, or equivalent experience required; Master's Degree preferred * Experience: 10+ years of experience in identity and access management, including 8+ years in cloud-based environments required; 12+ years of experience in information systems preferred * Hands-on experience with KeyCloak and AWS IAM Identity Center for SSO and MFA implementations. (IBM Verify a plus) * Strong knowledge of identity federation protocols (SAML, OAuth2.0, OIDC, SCIM) and modern authentication flows * Expertise with RBAC/ABAC frameworks, policy-based access control, and least-privilege enforcement * Familiarity with NIST 800-63, FISMA, FedRAMP, and ZTA standards and compliance frameworks * Experience implementing ICAM solutions in Agile and DevSecOps environments * Working knowledge of PKI, digital certificates, and encryption technologies * Strong analytical and troubleshooting skills with ability to resolve identity integration issues * Experience with AWS Container Security and Network Security (preferred, not required) * Expert in designing logging and monitoring system by correlating events from several AWS and ICAM system * Experience supporting digital modernization or judiciary IT programs * Familiarity with Zero Trust Architecture and micro segmentation principles * Exposure to API gateway authentication (Kong, Apigee, AWS API Gateway). * Experience integrating identity governance tools (SailPoint, Saviynt) * Excellent presentation and communication skills * Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationship * Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies * Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement * Demonstrated ability to work effectively, independently, and as part of a team Certification(s): * AWS Certified Solutions Architect - Associate or Professional - preferred * Certified Information Systems Security Professional (CISSP) - preferred * AWS Certified Security - Specialty or Azure Identity & Access Administrator - preferred * Certified Identity and Access Manager (CIAM) or Certified Identity Professional (CIP) - beneficial * SAFe Practitioner (SPC/SSM) - a plus Security Clearance Level: Ability to pass a background check to obtain and maintain a position of Public Trust with the Administrative Office of the US Courts. Must be a US Person (Green Card Holder, US Permanent Resident Alien, Refugee, Asylee, US Citizen)., Years of Experience 10 + years of related experience * may vary based on technical training, certification(s), or degree Certification AWS Certified Solutions Architect - Professional | Amazon Web Services (AWS) - Amazon Web Services (AWS) AWS Certified Solutions Architect - Associate | Amazon Web Services (AWS) - Amazon Web Services (AWS) Certified Information Systems Security Professional (CISSP) | International Information System Security Certification Consortium (ISC2) - International Information System Security Certification Consortium (ISC2) Travel Required Less than 10% ## Description The AWS Cloud Infrastructure Engineer (Keycloak Specialty) supports the Case Management Modernization (CMM) Program for the Administrative Office of the U.S. Courts (AO) by designing, implementing, and managing secure authentication and authorization frameworks across modernized cloud-based applications. This role ensures compliance with federal identity governance, FedRAMP, and Zero Trust Architecture (ZTA) principles within an AWS environment. The Engineer collaborates with architecture, security, and DevSecOps teams to ensure access control, identity federation, and credential management are integrated seamlessly across all layers of the CMM application ecosystem., * Design and maintain the identity architecture utilizing Keycloak * Implement federated identity and single sign-on (SSO) solutions using modern protocols (SAML, OAuth2.0, OIDC) * Collaborate with Cloud and Security Architects to enforce Zero Trust Architecture (ZTA) across microservices and APIs * Configure and maintain directory services and identity providers (e.g., AWS Cognito, AWS IAM Identity Center, Azure AD, IBM Verify , KeyCloak) * Deep experience integrating KeyCloak as a broker IdP federating upstream enterprise IdPs while issuing downstream OIDC token to application * Design identity solutions and support compliance assessments, ensuring adherence to FISMA, NIST 800-63, and FedRAMP security controls * Develop and document identity lifecycle management processes-provisioning, deprovisioning, and access reviews * Design and implement least privileged roles, groups, functionalities based on ZTA for both privileged and non-privileged users for a FedRAMP High system * Experience defining workflow, rules, policies within ICAM tools particularly IBM Verify and KeyCloak * Conduct access audits, user entitlement reviews, and anomaly detection to ensure least-privilege compliance * Provide subject matter expertise in identity federation, PKI, certificate management, and secure API authorization * Design strategies for logging, monitoring and auditing authentication and authorization related events in combination with other AWS event logs * Design and implement storage level, microservice level Authentication and Authorization * Support ATO process by providing solutions to all security controls, document implementation plan, maintain Visio diagrams * Participate in design sessions and work closely with the security lead * Collaborate with DevSecOps teams to embed ICAM policies within CI/CD pipelines and Infrastructure-as-Code (IaC) templates * Direct and lead Pen testing, Review architecture diagrams produced by different teams * Independently lead design and implement of vulnerability management * Lead and direct engineering team Deliverable Alignment & Performance Outcomes: * Architecture Diagrams: Depicting identity flow, federation, and integration points with AWS and CMM systems * Access Control Documentation: Policies, RBAC models, and credential management workflows * Compliance Verification Reports: Audit results aligned to NIST 800-63, FedRAMP, and FISMA standards * Zero Trust Implementation Artifacts: Documentation and verification of ZTA enforcement within system components * Performance Outcomes: + 100% of CMM applications integrated with SSO and MFA. + Zero unauthorized access incidents attributable to configuration error + 100% compliance with NIST and FedRAMP ICAM control requirements Reduced account provisioning time by + 30% through automation Tools & Technologies: * IAM & Federation: KeyCloak, Okta * Access & Compliance: SailPoint, CyberArk, HashiCorp Vault * Cloud: AWS IAM, KMS, CloudTrail, Lambda * Protocols: SAML, OAuth2.0, OIDC, SCIM * Monitoring & Audit: Splunk * Collaboration: Jira, Confluence, SharePoint, MS Teams ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [30 powerful AWS hacks in just 30 minutes: Boost your developer productivity](https://www.wearedevelopers.com/videos/1624-30-powerful-aws-hacks-in-just-30-minutes-boost-your-developer-productivity) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud)