×
Register Here to Apply for Jobs or Post Jobs. X

ICAM Security Engineer

Remote / Online - Candidates ideally in
Eagan, Dakota County, Minnesota, USA
Listing for: Leidos
Full Time, Remote/Work from Home position
Listed on 2026-09-24
Job specializations:
  • Software Development
    Backend Developer, DevOps
Salary/Wage Range or Industry Benchmark: 87100 - 157450 USD Yearly USD 87100.00 157450.00 YEAR
Job Description & How to Apply Below

Description

Leidos is seeking an ICAM / Identity Engineer to join the Air Traffic Business Area within the Homeland Sector, supporting the development of the Leidos Common Automation Platform (L-CAP). L-CAP is a mission-critical, future-ready automation platform built on a hybrid cloud data mesh architecture, enabling next-generation air traffic management capabilities. We are building with an AI-first engineering mindset, embracing emerging AI capabilities and modern development practices to accelerate delivery, improve software quality, and continuously evolve how we design and build mission-critical systems.

This role operates within a SAFe/Agile framework as part of an Agile Release Train (ART) delivering iterative value across the program. This position supports government programs and requires the ability to obtain and maintain a favorable Public Trust investigation.

This is a hybrid position requiring 3 days onsite and 2 days working from home, if you are located within a commutable distance (Less than 1 hour's drive one-way during normal traffic) from Gaithersburg, MD;
Eagan, MN; or Egg Harbor Township, NJ. However, if you do not reside within a commutable distance, you may be considered for a 100% remote role.

In this role, you will implement the identity, credential, and access management (ICAM) layer that governs every user and service interaction with L-CAP. You will integrate the platform with government-provided ICAM services, enforce per-session authorization across distributed mission services, and build the access control and audit foundations that operational and support users depend on.

What You’ll Do:
  • Integrate L-CAP services with government-provided ICAM services using OAuth 2.0 and OpenID Connect
    , including token issuance, validation, and claims mapping.
  • Implement and maintain identity federation and user stores (Keycloak or equivalent), including role-based test account provisioning.
  • Implement per-session authentication and authorization for user-to-service and service-to-service requests, enforcing default-deny access regardless of network location.
  • Implement mutual TLS (mTLS), service mesh/workload identity, and certificate lifecycle management
    , including issuance, rotation, expiration monitoring, and revocation.
  • Design and implement role-based (RBAC) and attribute-based (ABAC) access controls aligned to operational and support roles.
  • Implement authentication and session management for operational users, including sign-in/sign-out and time-on-position logging.
  • Implement authentication and authorization audit logging
    , including event capture, storage, and retrieval.
  • Implement API gateway authorization and ensure external-facing endpoints are registered and protected through the API management layer.
  • Support security authorization and continuous monitoring by producing ICAM control evidence
    , resolving identity integration issues across distributed services, and leveraging AI-assisted development and automation to improve quality and delivery.
Core Technical

Qualifications:
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology
    , or related field with 4+ years of relevant experience
    . (additional experience, education and training may be considered in lieu of degree)
  • Hands-on experience with OAuth 2.0 and OpenID Connect
    , including token validation, introspection, and claims mapping.
  • Experience with enterprise identity providers and federation such as Keycloak, Okta, Ping, Microsoft Entra , or equivalent.
  • Experience implementing RBAC and/or ABAC within distributed applications.
  • Working knowledge of PKI, certificate lifecycle management, mutual TLS (mTLS), and/or service mesh identity
    .
  • Understanding of Zero Trust principles
    , including per-session authorization and default-deny service communication.
  • Experience implementing audit logging for access and authorization events.
  • Proficiency in Java, Python, Go
    , or a comparable programming/scripting language.
  • Working knowledge of NIST SP 800-53 Access Control (AC) and Audit and Accountability (AU) controls.
  • Experience with Kubernetes and containerized service deployments
    .
  • U.S. citizenship required
    , with the ability to obtain and maintain a Public Trust and successfully complete required government background investigations.
  • Must meet FAA facility and information system access requirements
    , including continuous U.S. residency for at least 3 of the previous 5 years
    .
Preferred / Desired

Qualifications:
  • Security+ CE, CySA+, or equivalent DoD 8570 IAT Level II…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary