> Markdown version of [/jobs/ext/659862-senior-system-engineer](https://www.wearedevelopers.com/jobs/ext/659862-senior-system-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior System Engineer - **Company:** Belay Technologies, Inc - **Location:** Annapolis Junction, MD, United States - **Experience:** Expert - **Salary:** $168,000.0 - $240,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Agile Methodology, Amazon Web Services, Systems Engineering, Confluence, JIRA, Microsoft Azure, Cyber Security, Computer Engineering, Software Design Documents, Federated Identity Management, Identity and Access Management, JSON, OAuth, OpenID, Package Development Process, Public Key Infrastructure, Scrum Methodology, Release Management, Openid Connect, Zero Trust Network Access, Security Assertion Markup Language (SAML), Single Sign-On, Software Engineering, Systems Integration, Software Vulnerability Management, Extensible Markup Language (XML), Cloud Platform System, Containerization, Kubernetes, Information Technology, Restful APIs, Docker, Vulnerability Analysis - **Published:** June 26, 2026 - **Apply:** https://www.juju.com/job/00000000gaxrfe ## About the Role + TS/SCI with polygraph is required. + Bachelor's Degree or higher in computer engineering or in a field related to the computer engineering or computer science disciplines + 10 years of System Engineering experience. An additional 4+ years of System Engineering experience may be substituted for the degree for a total of 14 years. Candidates are required to have the following skills: + Experience supporting systems engineering activities within federal, Department of Defense, Intelligence Community, or similarly regulated environments. + Understanding of Identity, Credential, and Access Management (ICAM) concepts and Zero Trust Architecture principles. + Experience supporting system integration, configuration, testing, validation, or deployment activities. + Experience developing technical documentation including architecture products, design documents, deployment guides, implementation procedures, SOPs, or engineering plans. + Knowledge of authentication, authorization, identity federation, access control, and policy enforcement concepts. + Experience supporting requirements analysis, system design, architecture development, or engineering assessments. Candidates are desired to have the following skills: + Experience supporting Zero Trust implementation initiatives. + Experience with OAuth, OpenID Connect (OIDC), SAML, federation services, or Single Sign-On technologies. + Experience with Identity Providers (IdP), Policy Administration Points (PAP), Policy Decision Points (PDP), Policy Enforcement Points (PEP), or related ICAM technologies. + Familiarity with Public Key Infrastructure (PKI), certificate lifecycle management, and credential management solutions. + Experience with Kubernetes, Helm, Docker, containerized applications, or cloud-native deployment architectures. + Experience supporting deployment package development and release management activities. + Familiarity with AWS, Azure, or other cloud environments supporting government workloads. + Experience with REST APIs, JSON, XML, and system-to-system integrations. + Experience with software supply chain security practices including vulnerability management, artifact validation, SBOMs, dependency analysis, container security, or release integrity verification. + Experience with vulnerability assessment tools, security testing, STIG compliance reviews, or remediation tracking + Experience supporting Assessment and Authorization (A&A) activities, SSP development, POA&M management, or NIST 800-53 compliance efforts. + Familiarity with Agile development methodologies, Jira, and Confluence. + Experience developing architecture diagrams, trust boundary diagrams, implementation roadmaps, or technical briefings. + Knowledge of scalability, resiliency, and high-availability deployment architectures . ## Description Belay Technologies is seeking a System Engineer to join our intel team. The Zero Trust Identity, Credential, and Access Management (ICAM) System Engineer provides systems engineering, integration, testing, and deployment support for Department of Defense Zero Trust initiatives. The engineer will work with multiple ICAM product teams to integrate externally developed capabilities and support the development of internally developed services into a cohesive ICAM solution that can be deployed across diverse mission environments. The selected candidate will support the integration, configuration, validation, packaging, and release of ICAM capabilities, including identity services, policy decision services, access control components, and supporting infrastructure. Responsibilities include systems engineering, architecture development, technical assessments, requirements analysis, deployment package development, Kubernetes-based deployment support, software supply chain security activities, and release validation. This position serves as a technical bridge between ICAM product teams, software developers, cybersecurity engineers, test teams, and system integrators to ensure capabilities are properly integrated, tested, documented, and prepared for enterprise deployment. The engineer will help ensure delivered solutions align with Zero Trust principles, cybersecurity requirements, and operational deployment objectives. Responsibilities Include: + I ntegrate externally developed ICAM capabilities and internally developed services into a unified Zero Trust ICAM solution. + Support development, integration, configuration, and testing of ICAM capabilities including identity services, access management services, policy decision services, and supporting infrastructure components. + Participate in requirements analysis, functional decomposition, system design, and architecture development activities. + Develop and maintain architecture documentation, design products, deployment guides, release notes, user guides, implementation procedures, SOPs, and technical plans. + Support development and maintenance of Kubernetes-based deployment packages and associated configuration artifacts used to deploy ICAM capabilities across multiple environments. + Perform system integration, configuration validation, troubleshooting, and technical assessments of ICAM capabilities and supporting technologies. + Conduct functional, integration, and operational testing to validate system performance and readiness for release. + Support secure software integration and release activities, including artifact validation, vulnerability assessment, container security review, and deployment package integrity verification. + Participate in software supply chain security activities supporting secure delivery and release of ICAM capabilities. + Research emerging technologies, industry standards, federal policies, and DoD guidance to identify capability improvements and integration opportunities. + Support risk assessments, security reviews, and mitigation planning activities associated with ICAM and Zero Trust initiatives. + Collaborate with software development, cybersecurity, system administration, platform engineering, and test teams to establish capabilities that satisfy mission and security requirements. + Support Agile development activities including sprint planning, backlog refinement, requirements discussions, and release planning. + Develop technical recommendations and briefings for government and contractor leadership. + Coordinate with system integrators and deployment stakeholders to support successful field implementation of delivered capabilities. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)