Lead Identity and Access Management (ICAM) Engineer
Listed on 2026-08-13
-
IT/Tech
Cybersecurity
Leidos Digital Civilian Agency Solutions division is seeking an expert-level Lead Identity and Access Management Engineer to serve as the senior technical authority for complex enterprise identity management solutions for large-scale government digital transformation initiatives. The ideal candidate will have deep expertise in Microsoft identity technologies and a proven track record of designing, implementing, and maturing IAM architecture and processes across cloud and on-premises environments, ensuring alignment with industry frameworks and regulatory requirements, and provides technical leadership and mentorship to junior and mid-level IAM engineers.
advanced enterprise-level identity solutions.
Be a US Citizen or US Person who has lived in the United States for at least three consecutive years and have the ability to obtain a Public Trust level 4 clearance
Primary Responsibilities:- Lead the design, engineering, and continuous improvement of enterprise IAM solutions, including Identity Governance and Administration (IGA), Privileged Access Management (PAM), Single Sign-On (SSO)/Federation, Multi-Factor Authentication (MFA), and directory services.
- Serve as the SME for IAM architecture decisions, tool selection, and integration strategy across cloud (Azure, AWS, GCP) and on-premises platforms.
- Define and enforce Identity lifecycle management processes (joiner-mover-leaver), role-based/attribute-based access control (RBAC/ABAC), and least-privilege principles.
- Lead IAM-related audits, risk assessments, and remediation efforts; ensure compliance with regulatory and contractual obligations.
- Partner with security operations, application owners, and compliance teams to integrate applications into enterprise IAM platforms (e.g., Microsoft Entra /Azure AD, Okta, Ping Identity, Cyber Ark).
- Provide technical leadership, mentoring, and peer review for IAM engineering staff.
- Support incident response and forensic investigations involving identity-related events.
- Evaluate emerging IAM technologies (e.g., password less authentication, decentralized identity, Zero Trust architecture) and recommend adoption strategies.
- Prepare technical documentation, architecture diagrams, and executive-level reporting on IAM posture and roadmap.
- Bachelor’s degree in computer science, Information Technology, or equivalent and 12 years of general experience, preferably supporting system engineering. 6 years of additional experience is equivalent to a Bachelor’s degree. With a Master’s degree, 10 years of general experience is required.
- 8+ years of progressive experience focusing on identity and access management.
- 5+ years in a senior/lead or SME capacity, with demonstrated ownership of enterprise-scale IAM architecture.
- Hands-on experience with at least two of the following IAM platform categories:
- IGA:
Microsoft Identity Manager - PAM:
Cyber Ark, Beyond Trust - SSO/Federation:
Okta, Microsoft Entra , Ping Identity - Directory Services:
Active Directory, Azure AD/Entra , LDAP
- IGA:
- Experience supporting federal, defense, or highly regulated environments preferred (especially for government/contractor roles).
- Experience with cloud IAM services (Azure Entra , AWS IAM/SSO, GCP IAM).
- Deep understanding of authentication and authorization protocols: SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), SCIM, Kerberos.
- Extensive hands-on experience with Microsoft identity solutions (Entra , AD FS, Microsoft 365, MIM).
- Proven experience in large-scale, multi-forest Active Directory and Entra .
- Advanced knowledge of identity protocols (SAML, OAuth 2.0, OpenID Connect, WS-Federation, CBA).
- Strong experience with Entra B2B and B2C for external identity management.
- Experience with Entra AD Connect, including custom synchronization rules.
- Strong proficiency in Power Shell and Graph API for identity management automation.
- Familiarity with Zero Trust architecture and identity-related security best practices.
- Relevant certifications, hold at least one or two of the following, aligned to seniority:
- CIAM (Certified Identity and Access Manager) or CIGE (Certified Identity Governance Expert)
- Microsoft Certified:
Identity and Access Administrator Associate (SC-300) - Cyber Ark Defender/Sentry/Guardian
- Okta Certified Professional/Consultant/Administrator
- Ping Identity Certified Professional
- CompTIA Security+
- Knowledge of identity-related compliance standards (e.g., NIST, FISMA, SOC, Fed Ramp).
- Experience with Azure AD Verifiable Credentials and decentralized identity concepts.
- Understanding of biometric authentication methods and their Azure AD integration.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.
Pay Range:Pay Range $ - $
About LeidosLeidos is an industry and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).