Sr ICAM Engineer

Fantom Corporation
Chantilly, United States of America
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Chantilly, United States of America

Tech stack

Java
Agile Methodologies
User Authentication
CompTIA Security+
Computer Programming
Continuous Integration
DevOps
Distributed Systems
Identity and Access Management
Python
Lightweight Directory Access Protocols (LDAP)
Linux System Administration
OAuth
OpenID
Openshift
Oracle Applications
X.509
Role-Based Access Control
Openid Connect
Cloud Services
Zero Trust Network Access
Security Assertion Markup Language (SAML)
Secure Coding
Software Deployment
Integration Testing
Systems Integration
Policy as Code
Enterprise Software Applications
Reliability of Systems
Containerization
Kubernetes
Infrastructure Automation Frameworks
Information Technology
Devsecops
Docker
Microservices

Job description

Fantom Corporation is a mission-focused organization supporting critical programs across the defense and intelligence community. We partner with our customers to deliver high-impact technical solutions while fostering a culture built on trust, expertise, and long-term career growth.

We are seeking an experienced Senior ICAM Engineer to support a major Identity, Credential, and Access Management (ICAM) modernization initiative. This role is responsible for designing, developing, integrating, testing, and supporting modernized ICAM capabilities using cloud-native technologies, microservices, automation, and DevSecOps best practices.

Working closely with technical leadership and solution architects, you will implement enterprise identity, authentication, authorization, and policy management solutions that improve scalability, security, maintainability, and operational efficiency across mission-critical environments.

Responsibilities

  • Design, develop, and implement modern Identity, Credential, and Access Management (ICAM) capabilities supporting Policy Enforcement Points (PEP), Policy Information Points (PIP), Enterprise Management Services (EMS), and Resource & Policy Management Services (RPMS)
  • Support the transition from legacy Policy Decision Point (PDP) technologies to modern authorization frameworks
  • Develop and integrate microservices supporting identity services, authorization, attribute management, resource registration, and policy distribution
  • Translate architectural designs into scalable, maintainable engineering solutions and technical implementation plans
  • Collaborate with technical leadership during Agile planning activities, including Program Increment (PI) Planning, backlog refinement, work estimation, and technical risk assessments
  • Develop modern authorization services supporting Attribute-Based Access Control (ABAC), policy decision integrations, and dynamic attribute retrieval
  • Implement automation supporting resource lifecycle management, policy ingestion, attribute orchestration, and enterprise authorization workflows
  • Partner with DevOps engineers to support CI/CD pipelines, infrastructure automation, containerization, and application deployment within Kubernetes, OpenShift, or similar platforms
  • Troubleshoot complex identity, authentication, authorization, and policy-related issues across both legacy and modernized environments
  • Develop and maintain engineering documentation including design specifications, interface definitions, configuration standards, and data flow diagrams
  • Participate in system integration testing, operational readiness testing, deployment validation, and production support activities
  • Improve system reliability, scalability, observability, and operational efficiency through automation and engineering best practices
  • Mentor junior engineers and promote secure coding standards, microservices development, and ICAM engineering best practices

Requirements

  • Must posses an active Top Secret Security Clearance
  • Must be willing to obtain a polygraph upon hire
  • Bachelor's degree in Computer Science, Engineering, Information Technology, or another STEM discipline with 8+ years of relevant experience, or equivalent combination of education and experience
  • Hands-on experience developing or integrating enterprise identity, authentication, authorization, or security solutions
  • Experience designing and implementing distributed systems or microservices-based architectures
  • Experience developing secure enterprise applications within Agile software development environments
  • Experience translating architectural guidance into high-quality engineering solutions
  • Strong troubleshooting and problem-solving skills
  • Excellent written and verbal communication skills
  • Ability to obtain CompTIA Security+ certification within 90 days of hire

Desired Qualifications

  • Experience deploying applications using Kubernetes, OpenShift, or other container orchestration platforms
  • Programming experience with Java and/or Python
  • Experience with GitOps workflows and modern DevSecOps practices
  • Experience with AWS cloud services, Linux environments, Docker, or other containerization technologies
  • Knowledge of enterprise identity and authorization standards including X.509, SAML, OAuth2, OpenID Connect (OIDC), and LDAP
  • Experience with Oracle Identity Management or other enterprise ICAM platforms
  • Experience implementing Attribute-Based Access Control (ABAC), Role-Based Access Control (RBAC), Policy-as-Code, and Zero Trust authorization models
  • Experience supporting Department of Defense or Intelligence Community identity and authorization systems

Apply for this position