Senior Cloud DevOps Engineer - Identity Management
Listed on 2025-12-03
-
IT/Tech
Systems Engineer, Cybersecurity, Cloud Computing
The Opportunity
Join a forward-thinking cloud engineering team responsible for designing, securing, and maintaining enterprise identity and access management systems.
Lead the integration and automation of identity services across hybrid cloud and on‑premises infrastructures.
- Drive the modernization of authentication, authorization, and secrets management capabilities using Keycloak, Hashi Corp Vault, and related technologies.
- Collaborate with cybersecurity, Dev Sec Ops , and infrastructure teams to enhance security posture and streamline identity workflows.
- Play a critical role in ensuring seamless, secure, and scalable access to secure multi‑cloud and on‑prem systems across the organization.
- Architect, deploy, and maintain Keycloak identity management systems in hybrid and multi‑cloud environments.
- Implement and manage secrets management solutions using Hashi Corp Vault, including dynamic secrets, PKI, and access policies.
- Integrate cloud-native and on‑prem identity stores (e.g., AWS IAM, Azure AD, LDAP, Active Directory) into unified ICAM architectures.
- Develop and automate CI/CD pipelines for deploying and maintaining ICAM‑related infrastructure as code (IaC).
- Define and enforce security policies for authentication, authorization, and token management across distributed systems.
- Collaborate with security teams to implement Zero Trust and least‑privilege access principles.
- Configure and maintain high availability, backup, and recovery strategies for Keycloak and Vault services.
- Monitor, troubleshoot, and optimize performance and reliability of identity systems and associated integrations.
- Maintain documentation of configurations, operational procedures, and identity management standards.
- Support compliance initiatives by ensuring alignment with NIST, FedRAMP, and organizational security frameworks.
- Bachelor’s degree in Computer Science, Information Systems, or related technical field.
- 5+ years of experience in Dev Ops, Cloud Engineering, or Infrastructure Automation roles.
- Hands‑on experience managing Keycloak, Hashi Corp Vault, or comparable IAM and secrets‑management tools.
- Strong understanding of identity federation (SAML, OIDC, OAuth2) and directory integration concepts.
- Proficiency with infrastructure‑as‑code (Terraform, Ansible, or Cloud Formation).
- Experience with at least one major cloud provider (AWS, Azure, or GCP) and hybrid integration patterns.
- Strong scripting skills in Bash, Python, or Go for automation and operational tasks.
- Solid understanding of networking, PKI, TLS, and secure service‑to‑service communication.
- Demonstrated ability to troubleshoot complex system and identity‑related issues in production environments.
- Must be located in San Antonio, TX or willing to relocate.
- Experience implementing Zero Trust architectures or enterprise ICAM modernization initiatives.
- Knowledge of Kubernetes, containerized deployments, and service‑mesh identity integration.
- Familiarity with regulatory compliance frameworks (FedRAMP, DoD RMF, ISO 27001).
- Experience with Git Ops workflows and CI/CD tools such as Git Lab CI, Jenkins, or ArgoCD.
- Relevant certifications such as Hashi Corp Certified Vault Associate, Certified Kubernetes Administrator (CKA), or AWS Certified Dev Ops Engineer.
Mid‑Senior level
Employment typeFull‑time
Job functionEngineering and Information Technology
IndustriesIT Services and IT Consulting
Pay RangeThe Proposed Salary Range for This Position Is $85,800 - $180,200
.
For more details on pay, benefits, and opportunities to balance work and personal life, learn more at CACI.
Equal Opportunity EmployerCACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).