
ICAM Identity Provider Engineer – Enterprise Authentication Services
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Design, develop, configure, and maintain enterprise Identity Provider (IdP) services for over 4 million enterprise identities.
• Engineer, administer, and maintain Microsoft Active Directory Federation Services (ADFS) infrastructure.
• Configure and uphold federation trust relationships with both internal and external IdPs, SPs, and mission partners.
• Design, implement, and troubleshoot authentication solutions utilizing SAML 2.0, OAuth 2.0, OpenID Connect, WS-Federation, and certificate-based authentication.
• Assist in onboarding and integrating enterprise applications into the authentication and federation ecosystem.
• Develop authentication policies, claims rules, attribute mappings, token issuance policies, and authorization workflows.
• Support SSO, MFA, Conditional Access, and phishing-resistant authentication capabilities.
• Collaborate with teams in cybersecurity, Active Directory, cloud, infrastructure, and application management.
• Facilitate the implementation of Zero Trust Architecture.
• Monitor, troubleshoot, and resolve issues related to authentication, federation, trust, certificates, tokens, and identity assertions.
• Engineer highly available and resilient authentication services for mission-critical applications.
• Create architecture diagrams, integration guides, SOPs, TTPs, operational procedures, and onboarding documentation.
• Engage in Agile development and continuous service improvement processes.
• Manage technical risks and contribute to efforts for enterprise identity modernization.
• Active Secret Clearance is mandatory; interim Secret Clearances are not permitted.
• U.S. citizenship is required.
• Bachelor’s Degree in a relevant technical field, or an equivalent combination of education, technical certifications, training, or work experience.
• DoD 8570/8140 IAT Level II certification, Security+ CE or higher, is essential.
• At least 8 years of experience in supporting IAM, authentication, federation, or ICAM solutions within government or regulated environments.
• Robust experience in designing, implementing, and supporting Microsoft ADFS.
• Extensive experience in implementing enterprise IdP services for large user bases.
• Strong knowledge of authentication, authorization, federation, and identity assurance principles.
• Familiarity with SAML 2.0, OAuth 2.0, OpenID Connect, WS-Federation, and JWT.
• Experience with PKI, certificate-based authentication, smart cards, and MFA solutions.
• Proficient in integrating applications, APIs, and enterprise services with federation platforms.
• Background in Active Directory, LDAP directories, and enterprise identity repositories.
• Experience in configuring claims, attribute mappings, policy enforcement, token transformations, and federation workflows.
• Exposure to supporting Linux and/or Windows Server environments.
• Experience in deploying and supporting enterprise COTS products within secure customer environments.
• Familiarity with Agile development environments and related tools.
• Excellent written and verbal communication skills.
• Capability to drive complex technical projects to completion.
• Desired: experience with highly available ADFS farms featuring WAP, load balancing, and disaster recovery.
• Desired: familiarity with Microsoft Entra ID, PingFederate, PingAccess, PingDirectory, Okta, Keycloak, or similar platforms.
• Desired: knowledge of DoD Enterprise ICAM, Federation Hub, or mission partner federation.
• Desired: experience with coalition, partner, or cross-organizational federation.
• Desired: understanding of NIST 800-63 IAL, AAL, and FAL.
• Desired: expertise in phishing-resistant and passwordless authentication methods.
• Desired: familiarity with Zero Trust Architecture and identity-centric security.
• Desired: experience in PowerShell scripting and automation.
• Desired: skills in monitoring, performance tuning, and capacity planning for services that support millions of identities.
• Desired: knowledge of Active Directory Certificate Services and enterprise PKI.
• Desired: experience with Docker and Kubernetes.
• Desired: understanding of DoD PKI, CAC authentication, derived credentials, and certificate lifecycle management.
• Desired: experience in maintaining highly available mission-critical authentication environments.
• Comprehensive benefits and wellness packages.
• 401(k) with company match.
• Competitive compensation.
• Paid time off.
• AI-powered career tool that identifies career steps and learning opportunities.
• An internal mobility team focused on achieving career aspirations.
• Full-flex work week.
• Various medical plan options, some including Health Savings Accounts.
• Dental plan alternatives.
• Vision plan options available.
• Ability to contribute both pre-tax and post-tax to 401(k) up to IRS annual limits.
• Vacation, sick leave, and personal time off.
• Paid holidays.
• Paid parental leave.
• Military leave provisions.
• Bereavement leave.
• Jury duty leave.
• 15 days of paid leave per calendar year for new employees.
• 10 paid holidays each year.
• Up to 160 hours of paid family leave within a rolling 12-month period for eligible employees.
• Short- and long-term disability benefits.
• Life insurance coverage.
• Accidental death and dismemberment insurance.
• Personal accident insurance.
• Critical illness insurance.
• Business travel and accident insurance.
• An award-winning culture of innovation.
• A military-friendly workplace.
Highland Electric Fleets
Falconwood, Incorporated
Aira
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.