External Title ICAM Sustainment Analyst
Listed on 2026-09-20
-
IT/Tech
Cybersecurity, Systems Administrator
Responsibilities
ICAM Sustainment Analyst
The Identity, Credential, and Access Management (ICAM) Sustainment Analyst is responsible for ensuring the operational health, reliability, security, and continuous maintenance of enterprise ICAM systems and infrastructure. Operating at the intersection of operations, system engineering, and tier-3 technical support, this role oversees routine software updates, system patches, incident response, performance monitoring, and capacity management across core identity components. The ICAM Sustainment Analyst minimizes operational downtime, resolves complex escalated incidents, and implements continuous service improvements to maintain seamless, secure identity services across the enterprise.
Key Responsibilities
- Oversee daily operations, maintenance, patch management, version upgrades, and health checks for production and non-production ICAM components across on-premises, cloud, and hybrid environments.
- Provide high-tier technical troubleshooting, root-cause analysis, and issue remediation for critical service outages, identity synchronization failures, authentication disruptions, and certificate lifecycle issues.
- Maintain operational availability for key identity services, including Directory Services (Active Directory, Entra , LDAP), Single Sign-On (SSO) gateways, Federated Identity providers (SAML, OIDC), Privileged Access Management (PAM) vaults, and Identity Governance and Administration (IGA) platforms.
- Manage operational Public Key Infrastructure (PKI) processes, including Smart Card/CAC/PIV authentication integrations, SSL/TLS certificate renewals, trust store updates, and Key Management infrastructure.
- Monitor system performance, availability, latency, and resource utilization. Establish proactive alerting rules, metrics dashboards, and SLA tracking to ensure high availability and operational scalability.
- Author, update, and validate operational runbooks, disaster recovery (DR) plans, failover procedures, and sustainment SOPs to ensure operational continuity and team standardization.
- Collaborate with cybersecurity teams to track, analyze, and remediate technical vulnerabilities (IAVMs, CVEs, security baseline drift) across ICAM servers, databases, and application endpoints.
Required Qualifications
- Bachelor’s Degree in Cybersecurity, Computer Science, Information Technology, Systems Engineering, or a related technical discipline.
5 years with BS/BA; or 9 years of experience with a high school diploma.
- Ability to obtain public trust with successful T3 investigation
- CompTIA Security+ CE or IAT Level II baseline certification.
- Exceptional technical troubleshooting, analytical problem-solving, and communication skills under high-pressure, incident-driven environments.
- Local and onsite in San Antonio, Texas
- US Citizen
Technical Expertise (Preferred):
- Demonstrated experience sustaining core identity systems (e.g., SailPoint, Ping Identity, Beyond Trust, Radiant Logic Radiant One, Microsoft Entra , or Active Directory/ADFS).
- Practical understanding of identity protocols and standards: SAML 2.0, OIDC, OAuth 2.0, LDAP, and PKI/X.509 certificates.
- Hands-on experience with server administration (Windows Server, Red Hat Enterprise Linux) and web server operations (IIS, Apache, Nginx).
- Familiarity with database operations (Oracle, SQL Server, PostgreSQL) as they relate to identity stores and transaction logging.
- Direct experience in Federal ICAM (FICAM) or DoD ICAM operational environments.
- Scripting capability (Power Shell, Bash, Python) for operational automation, log parsing, and task orchestration.
- Experience maintaining identity components in AWS, Azure, or Google Cloud environments, including containerized deployments (Docker, Kubernetes).
- Hands-on…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).