
ICAM Identity Provider Engineer – Enterprise Authentication Services
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in United States.
• Design, develop, configure, and maintain enterprise Identity Provider (IdP) services that support over 4 million enterprise identities.
• Engineer, administer, and sustain the infrastructure for Microsoft Active Directory Federation Services (ADFS).
• Configure and manage federation trust relationships with internal and external IdPs, SPs, and mission partners.
• Design, implement, and troubleshoot authentication solutions utilizing SAML 2.0, OAuth 2.0, OpenID Connect, WS-Federation, and certificate-based authentication.
• Assist in the onboarding and integration of enterprise applications within the authentication and federation ecosystem.
• Develop authentication policies, claims rules, attribute mappings, token issuance policies, and authorization workflows.
• Provide support for SSO, MFA, Conditional Access, and phishing-resistant authentication capabilities.
• Collaborate with teams in cybersecurity, Active Directory, cloud, infrastructure, and application sectors.
• Promote Zero Trust Architecture through modern authentication, federation, and identity assurance capabilities.
• Monitor, troubleshoot, and resolve complex issues related to authentication, federation, trust, certificates, tokens, and identity assertions.
• Engineer high-availability and resilient authentication services for critical enterprise applications.
• Create architecture diagrams, integration guides, SOPs, TTPs, operational procedures, and onboarding documentation.
• Engage in Agile development activities and continuous service improvement initiatives.
• Manage technical risks and contribute to efforts for enterprise identity modernization.
• Active Secret Clearance is required; interim Secret Clearances will not be accepted.
• U.S. citizenship is mandatory.
• Bachelor’s Degree in a relevant technical field, or equivalent combination of education, technical certifications, training, or work experience.
• DoD 8570/8140 IAT Level II certification, Security+ CE or higher is required.
• A minimum of 8 years of experience supporting IAM, authentication, federation, or ICAM solutions in government or regulated settings.
• Strong background in designing, implementing, and supporting Microsoft ADFS.
• Extensive experience in implementing enterprise IdP services for large user bases.
• Solid understanding of authentication, authorization, federation, and identity assurance.
• Familiarity with SAML 2.0, OAuth 2.0, OIDC, WS-Federation, and JWT.
• Experience with PKI, certificate-based authentication, smart card authentication, and MFA is essential.
• Proven experience integrating applications, APIs, and enterprise services with federation platforms.
• Knowledge of Active Directory, LDAP directories, and enterprise identity repositories.
• Experience configuring claims, attribute mappings, policy enforcement, token transformations, and federation workflows.
• Experience supporting Linux and/or Windows Server environments.
• Experience deploying and maintaining enterprise COTS products in secure customer environments.
• Familiarity with Agile development environments and associated tools.
• Strong written and verbal communication skills are a must.
• Ability to drive complex technical projects to completion.
• Desired: experience with highly available ADFS farms that include WAP, load balancing, and disaster recovery.
• Desired: familiarity with Microsoft Entra ID, PingFederate, PingAccess, PingDirectory, Okta, Keycloak, or similar platforms.
• Desired: experience with DoD Enterprise ICAM, Federation Hub, or mission partner federation.
• Desired: coalition, partner, or cross-organizational federation experience.
• Desired: knowledge of NIST 800-63 IAL, AAL, and FAL.
• Desired: experience with phishing-resistant and passwordless authentication.
• Desired: familiarity with Zero Trust Architecture and identity-centric security.
• Desired: experience in PowerShell scripting and automation.
• Desired: expertise in enterprise monitoring, performance tuning, and capacity planning.
• Desired: knowledge of Active Directory Certificate Services and enterprise PKI.
• Desired: familiarity with Docker and Kubernetes.
• Desired: experience with DoD PKI, CAC authentication, derived credentials, and certificate lifecycle management.
• AI-powered career tool that identifies career paths and learning opportunities.
• Internal mobility team dedicated to helping employees reach their career aspirations.
• Comprehensive benefits and wellness packages available.
• 401K with company matching contributions.
• Competitive salary.
• Paid time off offered.
• Full-flex work week options.
• Award-winning culture of innovation.
• Military-friendly workplace environment.
• Medical plan options, including some with Health Savings Accounts.
• Dental plan options provided.
• Vision plan available.
• 401(k) plan with pre-tax and post-tax contribution options and company match.
• Vacation, sick, and personal time offered.
• Paid holidays included.
• Paid parental leave policy.
• Military leave provisions available.
• Bereavement leave offered.
• Jury duty leave provisions available.
• Typically, 15 days of paid leave per calendar year for new employees.
• 10 additional paid holidays each year.
• Paid Family Leave of up to 160 hours in a rolling 12-month period for eligible employees.
• Short- and long-term disability benefits included.
• Life insurance coverage provided.
• Accidental death and dismemberment insurance available.
• Personal accident insurance options offered.
• Critical illness insurance available.
• Business travel and accident insurance provided.
Highland Electric Fleets
Falconwood, Incorporated
Aira
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.