Identity & Access Management (ICAM) Engineer (TS/SCI Clearance Required)
Role details
Job location
Tech stack
Job description
This position implements ICAM modernization designs for PEP/PIP, EMS, and RPMS components, aligning with established architectural patterns and guiding the transition from the legacy PDP to JBlocks. Duties include developing and integrating microservices that support identity, attributes, authorization, resource registration, and policy distribution; working with the Architect to translate high-level designs into detailed engineering tasks and system interfaces; supporting the Technical Lead during Program Increment (PI) planning, backlog refinement, estimation, and risk identification; building new PEP/PIP patterns such as enforcement endpoints, policy decision integrations, and attribute retrieval mechanisms; enhancing EMS and RPMS with automation for resource and role lifecycle management, attribute orchestration, and policy ingestion; collaborating with DevOps engineers on CI/CD, containerization, and deployment to Kubernetes or the government's installed application platform; troubleshooting complex identity, authentication, authorization, and policy issues; contributing to design specifications, data flow diagrams, and interface definitions; participating in integration, operational readiness, and deployment validation across multiple environments and security domains; and mentoring junior engineers in secure coding and ICAM integration best practices. This is a short-term assignment with an expected duration of six months.
Requirements
- Hands-on experience developing or integrating systems related to identity, authentication, authorization, or enterprise security
- Experience implementing distributed systems or microservices architectures on modern platforms
- Experience supporting Agile teams and contributing to iterative delivery of new capabilities
Preferred Skills/Experience:
- Experience with Kubernetes or OpenShift for deployment and container orchestration
- Programming experience with Java and/or Python
- Familiarity with GitOps tools
- Experience with Amazon Web Services (AWS), Linux, or containerization technologies
- Knowledge of identity and access standards (X.509, SAML, OAuth2, OIDC, LDAP)
- Experience with Oracle products or similar ICAM vendor technologies
- Experience implementing ABAC/RBAC models, policy-based access controls, and Zero Trust-aligned authorization patterns
- Experience supporting Intelligence Community (IC) or Department of War (DoW) systems, particularly authorization and identity-centric services, * Active Top Secret security clearance; SCI eligibility required
- Ability to obtain a CI polygraph after hire
- Ability to obtain a DoD 8570-compliant certification (e.g., Security+) within 90 days of hire