ICAM Authentication & Federation Engineer - Edge Services
Listed on 2026-08-02
-
Security
Cybersecurity
GDIT has an opportunity for an ICAM Engineer supporting a large line of business that delivers enterprise-scale Identity, Credential, and Access Management (ICAM) capabilities. This role supports the DoW ICAM mission by designing, developing, integrating, and maintaining Authentication and Federation services that enable secure access across enterprise, mission partner, coalition, tactical, and edge computing environments. The ideal candidate is a senior hands-on identity engineer with expertise in Ping Federate, enterprise Identity Providers (IdPs), federation services, and modern authentication technologies.
This role focuses on authentication, federation, trust management, single sign-on (SSO), multi-factor authentication (MFA), and extending enterprise identity services to support distributed and disconnected operational environments. This position is a Hybrid role with an estimated 25% of time expected on-site at our Fort Meade, MD facility.
- Design, develop, configure, and maintain enterprise authentication and federation services supporting both enterprise and edge ICAM architectures.
- Support Ping Federate and related identity platforms used to provide authentication, federation, single sign-on (SSO), and trust management services.
- Engineer federation solutions that extend secure identity services to mission partners, coalition organizations, tactical users, and edge computing environments.
- Configure and maintain trust relationships with internal and external Identity Providers (IdPs), Service Providers (SPs), and federation partners.
- Develop and maintain integrations utilizing SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and PKI-based authentication technologies.
- Support onboarding and integration of applications, mission partners, and external organizations into enterprise federation ecosystems.
- Design and implement authentication flows, token services, claims transformation, attribute mapping, and policy enforcement mechanisms.
- Support MFA, phishing-resistant authentication, certificate-based authentication, and emerging identity assurance capabilities.
- Collaborate with cybersecurity, cloud, infrastructure, and application teams to implement secure authentication and federation solutions.
- Support implementation of Zero Trust Architecture through modern authentication, federation, and identity assurance services.
- Troubleshoot and resolve complex issues involving authentication, federation, trust relationships, certificates, tokens, and identity assertions.
- Support deployment and sustainment of identity services operating in disconnected, intermittent, low-bandwidth (DDIL), and edge environments.
- Develop technical documentation including architecture diagrams, integration guides, SOPs, TTPs, and onboarding documentation.
- Participate in Agile development activities and support continuous improvement initiatives.
- Actively manage technical risks and contribute to mission readiness objectives.
- Education:
Bachelor’s Degree. An additional 4 years of experience may be substituted in lieu of degree. - Clearance:
Minimum of an active Secret security clearance. - Certification: 8570/8140 IAT Level II certification (Security+ CE or higher).
- Experience:
10+ years’ experience supporting Identity and Access Management (IAM), Authentication, Federation, or ICAM solutions within government or regulated environments.
Skills:
- Strong experience with Ping Federate or equivalent federation technologies.
- Experience implementing and supporting enterprise Identity Provider (IdP) and federation services.
- Strong understanding of authentication, authorization, federation, and identity assurance concepts.
- Experience implementing and troubleshooting SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and JWT technologies.
- Experience supporting PKI, certificate-based authentication, smart card authentication, and MFA solutions.
- Experience integrating applications, APIs, and enterprise services with federation platforms.
- Experience with Active Directory, LDAP directories, and enterprise identity repositories.
- Experience configuring claims, attribute…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).