Remotery

ICAM Identity Provider Engineer – Enterprise Authentication Services

Posted 1 day ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Design, develop, configure, and maintain enterprise Identity Provider (IdP) services for over 4 million enterprise identities.

• Engineer, administer, and sustain the Microsoft Active Directory Federation Services (ADFS) infrastructure.

• Configure and uphold federation trust relationships with both internal and external IdPs, SPs, and mission partners.

• Design, implement, and troubleshoot authentication solutions utilizing SAML 2.0, OAuth 2.0, OpenID Connect, WS-Federation, and certificate-based authentication.

• Assist in onboarding and integrating enterprise applications into the authentication and federation ecosystem.

• Develop authentication policies, claims rules, attribute mappings, token issuance policies, and authorization workflows.

• Support enterprise SSO, MFA, Conditional Access, and phishing-resistant authentication mechanisms.

• Collaborate with teams in cybersecurity, Active Directory, cloud, infrastructure, and application domains.

• Enhance Zero Trust Architecture through modern authentication, federation, and identity assurance capabilities.

• Monitor, troubleshoot, and resolve intricate authentication, federation, trust, certificate, token, and identity assertion challenges.

• Engineer highly available and resilient authentication services for mission-critical enterprise applications.

• Create architecture diagrams, integration guides, SOPs, TTPs, operational procedures, and onboarding documentation.

• Engage in Agile development and continuous service improvement initiatives.

• Manage technical risks and contribute to efforts aimed at modernizing enterprise identity.


⛳️ Requirements

• Active Secret Clearance at minimum; interim Secret Clearances are not permitted.

• U.S. citizenship is mandatory.

• Bachelor’s Degree in a related technical field, or an equivalent combination of education, technical certifications or training, or work experience.

• DoD 8570/8140 IAT Level II certification, such as Security+ CE or higher.

• At least 8 years of experience in supporting IAM, authentication, federation, or ICAM solutions within government or regulated settings.

• Strong expertise in designing, implementing, and supporting Microsoft ADFS.

• Extensive experience in implementing enterprise IdP services for large user populations.

• Profound understanding of authentication, authorization, federation, and identity assurance.

• Familiarity with SAML 2.0, OAuth 2.0, OpenID Connect, WS-Federation, and JWT.

• Experience with PKI, certificate-based authentication, smart card authentication, and MFA.

• Proven experience in integrating applications, APIs, and enterprise services with federation platforms.

• Knowledge of Active Directory, LDAP directories, and enterprise identity repositories.

• Experience in configuring claims, attribute mappings, policy enforcement, token transformations, and federation workflows.

• Experience supporting Linux and/or Windows Server environments.

• Experience deploying and maintaining enterprise COTS products in secure customer environments.

• Familiarity with Agile development environments and associated tools.

• Excellent written and verbal communication skills.

• Ability to independently steer complex technical initiatives to completion.

• Desired: experience with highly available ADFS farms, WAP, load balancing, and disaster recovery.

• Desired: experience with Microsoft Entra ID, PingFederate, PingAccess, PingDirectory, Okta, Keycloak, or similar platforms.

• Desired: experience with DoD Enterprise ICAM, Federation Hub, or mission partner federation.

• Desired: coalition, partner, or cross-organizational federation experience.

• Desired: NIST 800-63 IAL, AAL, and FAL experience.

• Desired: experience with phishing-resistant and passwordless authentication.

• Desired: experience with Zero Trust Architecture and identity-centric security.

• Desired: familiarity with PowerShell scripting and automation.

• Desired: experience in enterprise monitoring, performance tuning, and capacity planning.

• Desired: expertise in Active Directory Certificate Services and enterprise PKI.

• Desired: familiarity with Docker and Kubernetes.

• Desired: familiarity with DoD PKI, CAC authentication, derived credentials, and certificate lifecycle management.

• Desired: experience with highly available, mission-critical enterprise authentication.


🏝️ Benefits

• AI-powered career tool identifying career steps and learning opportunities.

• Internal mobility team focused on advancing career goals.

• Comprehensive benefits and wellness packages.

• 401(k) with company match.

• Competitive salary.

• Paid time off.

• Full-flex work weeks.

• Medical plan options, some with Health Savings Accounts.

• Dental plan options.

• Vision plan.

• Opportunity to contribute pre- and post-tax dollars to 401(k) up to IRS annual limits.

• Vacation, sick, personal, holiday, paid parental, military, bereavement, and jury duty leave.

• 15 days of paid leave per calendar year for new employees.

• 10 paid holidays annually.

• Up to 160 hours of paid family leave within a rolling 12-month period for eligible employees.

• Short- and long-term disability benefits.

• Life insurance.

• Accidental death and dismemberment insurance.

• Personal accident insurance.

• Critical illness insurance.

• Business travel and accident insurance.

• Award-winning culture of innovation.

• Military-friendly workplace.

• Remote work options available.

People also viewed

Highland Electric Fleets6 hours ago

Energy Storage Project Engineer

US flagMassachusetts OnlyFull-timeEngineer$90k – $105k/year
ApplyView job
Falconwood, Incorporated7 hours ago

Endpoint Engineer

US flagUnited States OnlyFull-timeEngineer$130k – $140k/year
ApplyView job
Aira7 hours ago

Plumbing and Heating Engineer

GB flagUnited Kingdom OnlyFull-timeEngineer£36.1k/year
ApplyView job
Pragmatike7 hours ago

Forward Deployed Engineer, YC Experience

US flagCalifornia, +3 more statesFull-timeEngineer$200k – $350k/year
ApplyView job
Pragmatike7 hours ago

Lead Forward Deployed Engineer

US flagCalifornia, +2 more statesFull-timeEngineer$200k – $350k/year
ApplyView job
Pragmatike7 hours ago

Senior Forward Deployed Engineer

US flagCalifornia, +3 more statesFull-timeEngineer$200k – $350k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers