Identity, PKI & Access Engineer
$185,000–$220,000 year
On-site · Arlington, Virginia, United States
Job Summary
Senior to Staff Identity, PKI and Access Engineer responsible for end-to-end identity engineering across the lifecycle, implementing and modernizing identity, SSO, PKI, certificate lifecycle, federation, access control, and secrets management across TS/SCI environments. Design, implement, and integrate identity platforms (Entra ID, Keycloak, Active Directory) and related technologies (OIDC, OAuth 2.0, SAML, mTLS, cert-manager) to support Zero Trust, service identities, and secure inter-service communication. Coordinate across cybersecurity, application, platform, cloud, network, UC, crypto, and operations teams; develop implementation plans, diagrams, inventories, tests, and operational support materials; support RMF/ATO/STIG compliance and secure service integration. Requires active Top Secret/SCI clearance and US citizenship; primary onsite location in Arlington, VA.
Required Qualifications
- Demonstrated senior-level experience implementing and supporting enterprise identity, PKI, certificate management, SSO, federation, or secrets management capabilities
- Hands-on experience with Entra ID, Keycloak, Active Directory, LDAP/LDAPS, OIDC, OAuth 2.0, SAML, PKI, certificate authorities, cert-manager, or equivalent identity platforms
- Strong practical knowledge of certificate lifecycle management, trust chains, mTLS, service identities, access control, token-based authentication, secrets rotation, and identity troubleshooting
- Experience supporting classified, TS/SCI, multi-enclave, internet-connected, or air-gapped environments
- Ability to coordinate technical dependencies across cybersecurity, application, platform, network, UC, crypto, cloud, and operations teams
- Experience supporting RMF processes, ATO documentation, STIG compliance, security controls, or equivalent cybersecurity compliance activities for identity or platform services
- Ability to produce clear technical documentation, diagrams, implementation guides, test procedures, certificate inventories, and operational support materials
Additional Requirements
- Must be a U.S. Citizen
- Active Top Secret/SCI clearance is required
Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.