
ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services
Posted 57 min ago

Posted 57 min ago
This is a fully remote position, open to applicants in Virginia.
• Act as the primary technical leader and architect for Identity Provider services within the Department of Defense.
• Lead the formulation of long-term ICAM strategy, modernization efforts, and architectural governance.
• Design, construct, and advance large-scale ADFS and modern IdP platforms.
• Establish enterprise trust architectures, federation models, and identity integration patterns across boundaries.
• Oversee the design and architecture of authentication solutions utilizing SAML, OAuth, OIDC, WS-Federation, JWT, and certificate-based technologies.
• Determine the technical direction for the integration of applications, APIs, and enterprise services into the authentication framework.
• Create enterprise-wide policies, claims rule frameworks, token issuance patterns, identity assurance levels, and authorization logic.
• Provide principal-level oversight for Multi-Factor Authentication (MFA), phishing-resistant authentication, Conditional Access, and passwordless identity technologies.
• Serve as a senior escalation point for intricate trust, certificate, federation, and token-related challenges.
• Design highly available and fault-tolerant authentication platforms incorporating load balancing, multi-region resilience, failover, and operational continuity.
• Develop architecture roadmaps, engineering standards, reference architectures, integration guides, and operational frameworks.
• Guide and mentor engineering teams throughout Agile development cycles.
• Detect enterprise risks, implement mitigation strategies, and counsel senior leadership on authentication posture, ICAM modernization, and Zero Trust advancements.
• Active Secret Clearance is mandatory; interim Secret Clearances will not be accepted.
• U.S. citizenship is required.
• Bachelor’s Degree in a relevant technical field, or an equivalent combination of education, technical certifications, training, or professional experience.
• DoD 8570/8140 IAT Level II certification, Security+ CE or higher is required.
• Over 15 years of experience in enterprise identity architecture, ICAM engineering, authentication platforms, or federation technologies.
• Extensive expertise in designing and leading enterprise-scale ADFS and IdP solutions.
• Experience in architecting identity systems for large regulated environments that support millions of users.
• In-depth understanding of authentication, authorization, identity assurance, federation protocols, and the pillars of Zero Trust identity.
• Strong background with SAML, OAuth, OIDC, WS-Federation, JWT, PKI, smart card authentication, and MFA architectures.
• Architecture-level experience in integrating mission applications and APIs with enterprise IdP and federation platforms.
• Expert proficiency with Active Directory, LDAP directories, identity repositories, and claims-based identity systems.
• Experience in designing enterprise token rules, claims mappings, federation workflows, and trust policies.
• Proficiency with Windows and Linux server platforms in identity contexts is required.
• Experience in deploying identity COTS products within secure environments.
• Excellent communication abilities and capacity to guide engineers while influencing leadership.
• Proven track record of successfully driving large-scale identity initiatives from architecture to implementation.
• Preferred experience with highly available ADFS farms, Web Application Proxy, load balancing, and disaster recovery strategies.
• Preferred experience with Microsoft Entra ID, PingFederate, PingAccess, PingDirectory, Okta, Keycloak, or similar platforms.
• Preferred experience in supporting DoD Enterprise ICAM, Federation Hub, or mission partner federation initiatives.
• Preferred experience in coalition, partner, or cross-organizational federation environments.
• Preferred experience with NIST 800-63 IAL, AAL, and FAL.
• Preferred experience in implementing phishing-resistant and passwordless authentication.
• Preferred experience in supporting Zero Trust Architecture and identity-centric security initiatives.
• Familiarity with PowerShell scripting, Docker, Kubernetes, enterprise monitoring, performance tuning, capacity planning, AD CS, enterprise PKI, DoD PKI, CAC authentication, derived credentials, and certificate lifecycle management.
• Comprehensive benefits and wellness packages.
• 401K plan with company matching.
• Competitive compensation.
• Paid time off.
• Flexible work week.
• AI-driven career tool that identifies career progression and learning opportunities.
• An internal mobility team focused on achieving career objectives.
• Options for medical plans, some including Health Savings Accounts.
• Various dental plan options.
• Vision plan options available.
• 401(k) contributions with company match.
• Time off for vacation, sick leave, personal time, holidays, parental leave, military leave, bereavement, and jury duty.
• Typically, 15 days of paid leave per calendar year.
• An additional 10 paid holidays each year.
• Up to 160 hours of paid family leave within a rolling 12-month period for eligible employees.
• Short- and long-term disability benefits.
• Life insurance coverage.
• Accidental death and dismemberment insurance.
• Personal accident insurance.
• Critical illness insurance coverage.
• Business travel and accident insurance.
• An award-winning culture of innovation.
• A workplace that is friendly to military personnel.
Databricks
Tailscale
Get handpicked remote jobs straight to your inbox weekly.