×
Register Here to Apply for Jobs or Post Jobs. X

DevOps Engineer; IDP​/Keycloak SME

Job in Chicago, Cook County, Illinois, 60290, USA
Listing for: Tetra Tech
Full Time position
Listed on 2026-10-02
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer
Salary/Wage Range or Industry Benchmark: 130000 - 150000 USD Yearly USD 130000.00 150000.00 YEAR
Job Description & How to Apply Below
Position: DevOps Engineer (IDP/Keycloak SME)

Job Description

The Federal Aviation Administration (FAA) is seeking a highly skilled System Engineer to serve as an Identity Provider (IDP) Subject Matter Expert (SME) by providing advanced engineering, implementation, integration, and operational support for enterprise identity and access management (IAM) services. The engineer will serve as a subject matter expert for Keycloak, IDP technologies, and Login.gov integrations, helping design, deploy, secure, automate, and maintain identity services supporting cloud-hosted applications and platforms.

Salary is based on relative years of experience:

$130,000 - $150,000

Job Duties & Responsibilities

Essential Job Functions may include (but are not limited to) the following:
The following duties are considered essential to the role. Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions

  • Serve as a technical SME for Keycloak, Identity Provider (IdP), IAM, and Login.gov solutions supporting FAA cloud applications and services.
  • Design, deploy, configure, upgrade, and maintain Keycloak environments across development, test, staging, and production environments.
  • Configure and manage Keycloak realms, clients, roles, groups, users, service accounts, identity providers, authentication flows, and authorization policies.
  • Implement and support OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, and JWT-based authentication.
  • Design and implement secure integrations between FAA applications and Login.gov for authentication and identity verification use cases.
  • Support applications integrating with Login.gov using OpenID Connect/OAuth 2.0 patterns.
  • Configure and troubleshoot Login.gov identity provider integrations, including client registration, redirect/return URLs, scopes, claims, authentication flows, and token handling.
  • Support integration between Login.gov, Keycloak, and FAA applications where federated identity or identity brokering is required.
  • Troubleshoot authentication issues involving Login.gov, Keycloak, application clients, tokens, claims, certificates, redirects, and federation.
  • Apply Login.gov integration and security requirements to application onboarding and deployment activities.
  • Support testing and validation of Login.gov integrations across development, test, staging, and production environments.
  • Coordinate with application teams and identity/security stakeholders to resolve Login.gov integration issues and ensure proper authentication flows.
  • Implement and support Single Sign-On (SSO) capabilities across cloud applications and enterprise services.
  • Support federation with enterprise directories and identity services, including LDAP/Active Directory and other authoritative identity sources.
  • Configure and manage identity federation, identity brokering, token exchange, identity mapping, claims, scopes, and protocol mappers.
  • Develop and maintain secure authentication and authorization patterns for applications operating within FAA cloud environments.
  • Implement role-based access control (RBAC) and least privilege access patterns.
  • Develop automated processes for Keycloak provisioning, configuration, deployment, and lifecycle management.
  • Use Terraform and Infrastructure as Code (IaC) to automate cloud infrastructure and identity platform configurations.
  • Integrate Keycloak and identity-related deployments into CI/CD pipelines and Dev Sec Ops  workflows.
  • Support containerized Keycloak deployments using Red Hat Open Shift/Kubernetes and cloud-native technologies.
  • Configure Keycloak for high availability, scalability, resilience, backup/recovery, and disaster recovery requirements.
  • Monitor identity platform performance, authentication activity, availability, logs, and system health.
  • Support certificate and key…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary