Remotery

ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services

Posted 57 min ago

This is a fully remote position, open to applicants in Virginia.

📋 Description

• Act as the primary technical leader and architect for Identity Provider services within the Department of Defense.

• Lead the formulation of long-term ICAM strategy, modernization efforts, and architectural governance.

• Design, construct, and advance large-scale ADFS and modern IdP platforms.

• Establish enterprise trust architectures, federation models, and identity integration patterns across boundaries.

• Oversee the design and architecture of authentication solutions utilizing SAML, OAuth, OIDC, WS-Federation, JWT, and certificate-based technologies.

• Determine the technical direction for the integration of applications, APIs, and enterprise services into the authentication framework.

• Create enterprise-wide policies, claims rule frameworks, token issuance patterns, identity assurance levels, and authorization logic.

• Provide principal-level oversight for Multi-Factor Authentication (MFA), phishing-resistant authentication, Conditional Access, and passwordless identity technologies.

• Serve as a senior escalation point for intricate trust, certificate, federation, and token-related challenges.

• Design highly available and fault-tolerant authentication platforms incorporating load balancing, multi-region resilience, failover, and operational continuity.

• Develop architecture roadmaps, engineering standards, reference architectures, integration guides, and operational frameworks.

• Guide and mentor engineering teams throughout Agile development cycles.

• Detect enterprise risks, implement mitigation strategies, and counsel senior leadership on authentication posture, ICAM modernization, and Zero Trust advancements.


⛳️ Requirements

• Active Secret Clearance is mandatory; interim Secret Clearances will not be accepted.

• U.S. citizenship is required.

• Bachelor’s Degree in a relevant technical field, or an equivalent combination of education, technical certifications, training, or professional experience.

• DoD 8570/8140 IAT Level II certification, Security+ CE or higher is required.

• Over 15 years of experience in enterprise identity architecture, ICAM engineering, authentication platforms, or federation technologies.

• Extensive expertise in designing and leading enterprise-scale ADFS and IdP solutions.

• Experience in architecting identity systems for large regulated environments that support millions of users.

• In-depth understanding of authentication, authorization, identity assurance, federation protocols, and the pillars of Zero Trust identity.

• Strong background with SAML, OAuth, OIDC, WS-Federation, JWT, PKI, smart card authentication, and MFA architectures.

• Architecture-level experience in integrating mission applications and APIs with enterprise IdP and federation platforms.

• Expert proficiency with Active Directory, LDAP directories, identity repositories, and claims-based identity systems.

• Experience in designing enterprise token rules, claims mappings, federation workflows, and trust policies.

• Proficiency with Windows and Linux server platforms in identity contexts is required.

• Experience in deploying identity COTS products within secure environments.

• Excellent communication abilities and capacity to guide engineers while influencing leadership.

• Proven track record of successfully driving large-scale identity initiatives from architecture to implementation.

• Preferred experience with highly available ADFS farms, Web Application Proxy, load balancing, and disaster recovery strategies.

• Preferred experience with Microsoft Entra ID, PingFederate, PingAccess, PingDirectory, Okta, Keycloak, or similar platforms.

• Preferred experience in supporting DoD Enterprise ICAM, Federation Hub, or mission partner federation initiatives.

• Preferred experience in coalition, partner, or cross-organizational federation environments.

• Preferred experience with NIST 800-63 IAL, AAL, and FAL.

• Preferred experience in implementing phishing-resistant and passwordless authentication.

• Preferred experience in supporting Zero Trust Architecture and identity-centric security initiatives.

• Familiarity with PowerShell scripting, Docker, Kubernetes, enterprise monitoring, performance tuning, capacity planning, AD CS, enterprise PKI, DoD PKI, CAC authentication, derived credentials, and certificate lifecycle management.


🏝️ Benefits

• Comprehensive benefits and wellness packages.

• 401K plan with company matching.

• Competitive compensation.

• Paid time off.

• Flexible work week.

• AI-driven career tool that identifies career progression and learning opportunities.

• An internal mobility team focused on achieving career objectives.

• Options for medical plans, some including Health Savings Accounts.

• Various dental plan options.

• Vision plan options available.

• 401(k) contributions with company match.

• Time off for vacation, sick leave, personal time, holidays, parental leave, military leave, bereavement, and jury duty.

• Typically, 15 days of paid leave per calendar year.

• An additional 10 paid holidays each year.

• Up to 160 hours of paid family leave within a rolling 12-month period for eligible employees.

• Short- and long-term disability benefits.

• Life insurance coverage.

• Accidental death and dismemberment insurance.

• Personal accident insurance.

• Critical illness insurance coverage.

• Business travel and accident insurance.

• An award-winning culture of innovation.

• A workplace that is friendly to military personnel.

People also viewed

OpenLoop50 min ago

Senior Staff IAM Engineer

US flagUnited States OnlyFull-timeEngineer
ApplyView job
Databricks50 min ago

Senior Forward Deployed Engineer – Public Sector

US flagWashington OnlyFull-timeEngineer$182k – $250.2k/year
ApplyView job
ClickHouse50 min ago

Senior Consulting Engineer

AU flagAustralia OnlyFull-timeEngineer
ApplyView job
Tailscale57 min ago

Windows Engineer

US flagUnited States, +1 more stateFull-timeEngineer$143k – $179k/year
ApplyView job
ABB57 min ago

Senior Project Engineer, Turbine

US flagPennsylvania OnlyFull-timeEngineer$91.7k – $146.7k/year
ApplyView job
Guidehouse57 min ago

SailPoint Engineer

US flagUnited States OnlyFull-timeEngineer$113k – $188k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers