More jobs:
ICAM Solution Architect
Job in
Reston, Fairfax County, Virginia, 22096, USA
Listed on 2026-07-26
Listing for:
CACI International
Full Time
position Listed on 2026-07-26
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing: Infrastructure & Operations, Information Security & Data Protection
Job Description & How to Apply Below
ICAM Solution Architect
Job Category:
Information Technology
Time Type:
Full time
Minimum Clearance Required to Start:
Secret
Employee Type:
Regular
Percentage of
Travel Required:
Up to 10%
Type of Travel:
Continental US
* *
* *
* The Opportunity:
*
* The
** ICAM Solutions Architect
** provides technical leadership across identity, credential, and access services by shaping ICAM strategy, defining and governing architecture, aligning roadmaps with mission and security priorities, and ensuring seamless integration of ICAM capabilities across the agency. This role partners with engineering, cybersecurity, governance bodies, and mission stakeholders to deliver a secure, modern, and scalable ICAM ecosystem in alignment with federal mandates and Zero Trust principles.
** Responsibilities:*
* ** ICAM Strategy & Enterprise Architecture*
* + Develop and maintain the enterprise ICAM strategy and future state architecture across identity, credential, authentication, and access services.
+ Define modernization roadmaps aligned with Zero Trust, cloud identity patterns, and federal ICAM guidance (M 19 17, A 130, NIST 800 63, 800 53).
+ Conduct architectural assessments across ICAM service towers (IdMAX, NED, NCAD, Entra , NAMS/SNAMS, Credentialing Services, eAuth, EPACS, PKI).
** Governance, Compliance & Risk Alignment*
* + Lead architectural alignment with federal identity requirements, including OMB, FISMA, NIST, CDM, and agency wide cybersecurity strategies.
+ Support ICAM governance bodies by preparing architecture artifacts, decision briefs, risk assessments, and compliance evaluations.
+ Establish technical guardrails, standards, and reference architectures for identity lifecycle, access provisioning, credentialing, and authentication services.
** ICAM Integration, Interoperability & Data Flows*
* + Define and manage integration patterns across identity stores, directories, authentication services, access workflows, and credential platforms.
+ Architect enterprise data flows between IdMAX → NED → NCAD/Entra → NAMS/SNAMS → apps and mission systems.
+ Ensure interoperability with federal shared services (FPKI, Idemia, DHS, GSA) and enterprise solutions (Microsoft, Service Now, cloud platforms).
** Technical Leadership & Roadmap Execution*
* + Provide technical oversight to ICAM engineering teams responsible for implementing and operating identity, credentialing, PKI, authentication, and access tools.
+ Review and approve solution designs, data models, integrations, and changes to ICAM platforms.
- + Monitor emerging identity trends (phishing-resistant MFA, passwordless, FIDO2, device identity, behavioral analytics).
+ Participate in sprint reviews, backlog prioritization, and cross-functional planning to ensure architectural alignment.
- + Performance, Metrics & Continuous Improvement
+ Define ICAM architectural performance metrics and KPIs (identity assurance, provisioning times, certificate lifecycle health, authentication quality, account hygiene).
+ Guide continuous improvement initiatives, addressing technical debt, legacy dependencies, and modernization blockers.
*
* Qualifications:
*
* _
Required:
_
+ 10+ years of experience in Identity, Credential, and Access Management architecture or enterprise security architecture.
+ Deep knowledge of identity lifecycle workflows, identity stores, directory services, authentication protocols (SAML, OIDC/OAuth, Kerberos), PKI.
- + Hands on experience with one or more NASA-relevant systems:
Active Directory/Entra , ADFS, IdMAX, PIV/PKI, NAMS/SNAMS, Siteminder/eAuth, Credentialing systems, EPACS.
- + Strong familiarity with federal ICAM guidance: OMB A 130, M 19 17, Zero Trust (M 22 09), NIST SP 800 63, 800 53, FIPS 201.
- + Demonstrated ability to create technical architecture artifacts (diagrams, data flows, models, standards).
- + Experience leading technical teams or influencing engineers in a large enterprise environment.
+
- _Desired:_
+
Experience with cloud identity governance (Azure AD/Entra , AWS IAM, GCP IAM).
+ Advanced understanding of Zero Trust identity, authentication patterns.
- + Background integrating ICAM into CI/CD pipelines, automation frameworks.
- ** What You Can Expect:*
*…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×