Senior IdAM Engineer IRES - SSFB/HSV/FBEL
Listed on 2026-09-30
-
IT/Tech
Cybersecurity
Senior IdAM Engineer
Location:
Schriever Space Force Base, Colorado Springs, CO, Redstone Arsenal, Huntsville, AL or Fort Belvoir, VA
Relocation Assistance:
None available at this time
Remote/Telework: NO - Not available for this position
Clearance Type:
DoW Secret
Shift: Day shift
Travel Required:
Up to 10% of the time
Description of Duties
As a Senior IdAM Engineer supporting the Next Generation Environment (NGE) on the Integrated Research and Development for Enterprise Solutions (IRES) contract, you will serve as a senior technical contributor responsible for engineering, deploying, automating, securing, and sustaining the Identity, Credential, and Access Management (IdAM / ICAM) ecosystem underpinning the Missile Defense Agency’s (MDA) unified digital environment.
In this role, you will help advance NGE’s hybrid and multi-cloud identity modernization strategy by implementing robust Identity Governance and Administration (IGA) workflows, federation and Single Sign-On (SSO) services, enterprise directory integrations, and DoD/NSS Public Key Infrastructure (PKI) aligned with the Zero Trust Security Model. You will work across engineering, cybersecurity, hybrid cloud, infrastructure, contract consortium performers, and Government stakeholder teams to deliver resilient identity services across on-premises and cloud-hosted mission environments.
You will play a key role in standardizing identity lifecycle automation, enhancing authentication security, eliminating credential risks, strengthening access controls, and ensuring continuous compliance with DoD, DISA, and MDA security requirements.
Description of DutiesIdentity Governance & Administration (IGA)
- Implement, deploy, configure, and sustain SailPoint Identity IQ (IIQ) solutions, including Operations & Maintenance (O&M), platform upgrades, capability enhancements, and enterprise application onboarding.
- Design and customize identity lifecycle management workflows (joiner, mover, leaver), certification campaigns, role-based/attribute-based access controls (RBAC/ABAC), custom Java rules, and compliance reporting.
- Engineer, deploy, and maintain Ping Identity Ping Federate services to enable secure, federated Single Sign-On (SSO) across enterprise and mission partner applications.
- Lead application onboarding and integration utilizing modern authentication and authorization protocols, including SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), and phishing-resistant Multi-Factor Authentication (MFA).
- Implement and sustain secure identity and access architectures across hybrid multi-cloud environments, including Microsoft Entra (Azure AD) and Amazon Web Services (AWS IAM and AWS IAM Identity Center) operating within DoD IL5/IL6 boundaries.
- Ensure secure synchronization, conditional access policy enforcement, and seamless identity interoperability between on-premises domains and cloud service providers.
- Configure, optimize, and administer Microsoft Directory Services, including Active Directory Domain Services (AD DS) and Active Directory Federation Services (AD FS), maintaining high availability and schema integrity.
- Maintain Kerberos, LDAP/S, and federated trust configurations across complex multi-forest and segmented enterprise environments.
- Deploy, maintain, and support DoD and National Security Systems (NSS) Public Key Infrastructure (PKI) components, including Certificate Authorities (CAs), hardware tokens (CAC/PIV/SIPR tokens), Certificate Validation services (OCSP/CRL), and certificate lifecycle management.
- Ensure cryptographic enforcement and certificate-based authentication across all network…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).