ICAM Engineer - Identity, Credential, and Access Management
Listed on 2026-07-28
-
IT/Tech
Cybersecurity, Systems Engineer
Description
Leidos' Digital sector is seeking a Systems Engineer with strong Dev Sec Ops , identity security, and systems integration expertise to support the Defense Information Systems Agency (DISA) Compartmented Enterprise Services Office (CESO). This role will contribute to the engineering, deployment, automation, and sustainment of an Identity Credential and Access Management platform that underpins CESO's Zero Trust Architecture and cross-domain capabilities.
The engineer will work hands‑on with Ping Identity components, enterprise directory services, automated pipelines, and scale ICAM integration across secure environments.
This position is 100% on‑site in Arlington, VA.
Primary Responsibilities- Engineering & Deployment: Engineer, deploy, secure, and maintain complex, mission‑critical identity systems – specifically Forge Rock IdP/ICAM platforms – across Linux‑based environments to meet DoD, DISA, and federal standards.
- Integration & Federation: Integrate enterprise applications and directories (LDAP, Active Directory) with ICAM platforms using robust federation protocols (SAML, OAuth2, APIs) across cross‑domain workflows and secure enclaves.
- Lifecycle & Access Control: Manage the complete identity and credential lifecycle (issuing, renewing, revoking, and automating workflows) to enforce strict Zero Trust access controls.
- Security & Compliance: Conduct system hardening, log analysis, and vulnerability management to support compliance with the Risk Management Framework (RMF) and participate in architectural and risk reviews.
- Operations & Troubleshooting: Diagnose and resolve escalated ICAM and Forge Rock issues within defined SLAs, conduct root cause analysis, performance tuning, and active monitoring.
- Documentation & Metrics: Create and version‑control key engineering artifacts (CONOPS, SOPs, API documentation, and workflow diagrams) while maintaining ICAM performance metrics and dashboards.
- BS in Computer Science, IT, or related discipline and 8+ years of systems engineering experience (or equivalent experience in lieu of a degree).
- Active TS clearance with SCI eligibility.
- Ability to obtain and maintain a CI Poly and Special Program Access.
- IAT Level II certification or higher (e.g., Security+ CE, CySA+, SSCP, CISSP).
- Hands‑on experience with federation technologies (SAML, OAuth2) and Zero Trust identity principles.
- Experience engineering or administering the Forge Rock platform (AM, IDM, DS).
- Strong understanding of ICAM concepts, identity lifecycle management, and enterprise access controls.
- Experience with Windows and Linux systems administration, shell scripting, and troubleshooting.
- Experience supporting DISA or DoD mission partners.
- Active TS/SCI with CI Poly preferred.
- Experience with any of the following:
- JISG Access Controls
- AWS cloud engineering, IAM, and security services
- Ansible playbooks and automated configuration management
- CI/CD pipelines (Git Lab, Jenkins, etc.)
For U.S. Positions:
While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date.
Pay Range: $ – $. The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary.
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).