
ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in United States.
• Design, develop, configure, and oversee enterprise Identity Provider services catering to over 4 million identities.
• Engineer, administer, and maintain the Microsoft Active Directory Federation Services infrastructure.
• Establish and manage federation trust relationships with Identity Providers, Service Providers, and mission partners.
• Create, implement, and troubleshoot SAML 2.0, OAuth 2.0, OpenID Connect, WS-Federation, and certificate-based authentication solutions.
• Aid in the onboarding and integration of enterprise applications.
• Formulate authentication policies, claims rules, attribute mappings, token issuance policies, and authorization workflows.
• Support Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, and phishing-resistant authentication measures.
• Collaborate with cybersecurity, Active Directory, cloud, infrastructure, and application teams.
• Assist in the implementation of Zero Trust Architecture.
• Monitor, troubleshoot, and resolve issues related to authentication, federation, trust, certificates, tokens, and identity assertions.
• Engineer highly available and resilient authentication services.
• Develop architecture diagrams, integration guides, Standard Operating Procedures (SOPs), Technical Task Plans (TTPs), operational procedures, and onboarding documentation.
• Engage in Agile development processes and continuous service enhancement.
• Manage technical risks and contribute to identity modernization initiatives.
• Active Secret Clearance is mandatory; interim Secret Clearances are not acceptable.
• US Citizenship is required.
• Bachelor’s Degree in a relevant technical field, or an equivalent combination of education, technical certifications or training, or work experience.
• DoD 8570/8140 IAT Level II certification, Security+ CE or higher, is required.
• A minimum of 8 years of experience in supporting IAM, authentication, federation, or ICAM solutions within government or regulated settings.
• Strong proficiency with Microsoft Active Directory Federation Services.
• Extensive experience in implementing enterprise IdP services for large user groups.
• Understanding of authentication, authorization, federation, and identity assurance concepts.
• Experience with SAML 2.0, OAuth 2.0, OpenID Connect, WS-Federation, and JWT.
• Familiarity with PKI, certificate-based authentication, smart card authentication, and MFA.
• Experience in integrating applications, APIs, and enterprise services with federation platforms.
• Proficiency with Active Directory, LDAP directories, and enterprise identity repositories.
• Knowledge in configuring claims, attribute mappings, policy enforcement, token transformations, and federation workflows.
• Experience supporting Linux and/or Windows Server environments.
• Background in deploying and supporting enterprise COTS products in secure customer environments.
• Experience working within Agile development environments and using associated tools.
• Strong written and verbal communication skills.
• Ability to drive complex technical projects to completion.
• Desired: experience with highly available ADFS farms, WAP, load balancing, disaster recovery, Microsoft Entra ID, Ping platforms, Okta, Keycloak, DoD ICAM, NIST 800-63, phishing-resistant/passwordless authentication, Zero Trust, PowerShell, enterprise monitoring, AD CS, Docker, Kubernetes, DoD PKI, CAC, derived credentials, and certificate lifecycle management.
• AI-powered career tool that identifies career steps and learning opportunities.
• Dedicated internal mobility team focused on achieving career goals.
• Comprehensive benefits and wellness packages.
• 401(k) plan with company matching.
• Competitive salary.
• Paid time off.
• Full-flex work week.
• Vacation, sick, and personal time off.
• Paid holidays.
• Paid parental, military, bereavement, and jury duty leave.
• Up to 160 hours of paid family leave over a rolling 12-month period for eligible employees.
• Medical plan options, with some featuring Health Savings Accounts.
• Dental plan options available.
• Vision plan options.
• Short- and long-term disability benefits.
• Life insurance coverage.
• Accidental death and dismemberment insurance.
• Personal accident insurance.
• Critical illness insurance.
• Business travel and accident insurance.
• An award-winning culture of innovation.
• A military-friendly workplace.
Highland Electric Fleets
Falconwood, Incorporated
Aira
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.