Summary
✨ AI‑Generated
A senior systems engineering role focused on designing secure identity and access management architectures. The position involves enterprise security modernization, authentication systems, and implementing advanced access control frameworks.
Highlights
Strategic technical role focused on enterprise security architecture, identity modernization, and secure access solutions.
Description
Role Summary
A Senior Systems Engineer specializing in Cross-Cutting Support and ICAM Enterprise Architecture is sought to support critical identity, credential, and access management enhancement initiatives.
This technical position involves designing, engineering, and implementing secure, identity-centric access control frameworks across diverse enterprise architectures.
The role provides strategic technical leadership for enterprise identity management systems, ensuring alignment with federal security standards and best practices.
Responsibilities
Serve as the primary technical authority for enterprise identity management and access control frameworks.
Lead the modernization of legacy access controls into secure ICAM solutions.
Manage enterprise directories, federation, authentication, authorization, and single sign-on (SSO) protocols.
Architect identity lifecycles, user provisioning workflows, and privilege management controls.
Design and deploy Zero Trust identity principles based on NIST SP 800-207 across network hubs.
Configure and manage enterprise PKI systems, credentials, and authenticators.
Implement logical and physical access control systems, including MFA, SSO, and privileged access management (PAM).
Build federated identity services for secure interoperability with mission partners.
Conduct root cause analysis, privilege audits, and system performance tuning to optimize security posture.
Develop technical interfaces, architectures, data flows, and compliance documentation to support ICAM initiatives.
Own the overarching hybrid identity strategy and ensure interoperability across enterprise identity systems.
Qualifications
High school diploma with 10+ years of relevant experience or equivalent technical background.
Active DoD 8570 IAT Level II certification or higher (e.g., Security+ CE, CySA+).
Extensive knowledge of federated identity protocols including SAML, OAuth, OIDC, and LDAP/Active Directory architecture.
Hands-on experience managing Smart Card/CAC authentication and PKI certificate validation.
Proven expertise implementing NIST SP 800-207 Zero Trust principles within enterprise networks.
This position requires eligibility for a U.S.
Government security clearance.
In accordance with federal law, U.S.
citizenship is required.
Strong understanding of enterprise identity tools and frameworks, including SailPoint, Okta, Microsoft Entra ID, or Ping Identity.
Familiarity with integrating data governance with ICAM solutions to enforce data access controls.
Experience with RESTful API authorization protocols, secure gateways, and data schema security standards.
Publishing Pay Range: $60.00 – $65.00 hourly
This position offers a hybrid schedule, with time split between the office and remote work.