Leidos logo
LeidosPosted 3 weeks ago

Lead Identity and Access Management (ICAM) Engineer

$131,300–$237,350 year

On-siteRockville, Maryland, United States

Full TimeSenior LevelMasters DegreeEnterprise

Job Summary

Lead the design, engineering, and continuous improvement of enterprise IAM solutions covering Identity Governance, Privileged Access Management, Single Sign-On, and directory services across Azure, AWS, and on-premises platforms. Serve as the subject matter expert for architecture decisions, tool selection, and integration strategies while defining lifecycle management processes, role-based access controls, and least-privilege principles. Drive IAM-related audits, risk assessments, and remediation efforts to ensure compliance with regulatory obligations, partnering with security operations and application owners to integrate platforms such as Microsoft Entra ID, Okta, and CyberArk. Provide technical leadership, mentoring, and peer review for engineering staff, supporting incident response and forensic investigations involving identity events. Evaluate emerging technologies like passwordless authentication and Zero Trust architecture to recommend adoption strategies, preparing technical documentation and executive reporting on IAM posture and roadmap.

Required Qualifications

  • US Citizen or US Person who has lived in the United States for at least three consecutive years
  • ability to obtain a Public Trust level 4 clearance
  • Bachelor's degree in computer science, Information Technology, or equivalent
  • 12 years of general experience, preferably supporting system engineering
  • 6 years of additional experience is equivalent to a Bachelor's degree
  • With a Master's degree, 10 years of general experience is required
  • 8+ years of progressive experience focusing on identity and access management
  • 5+ years in a senior/lead or SME capacity, with demonstrated ownership of enterprise-scale IAM architecture
  • Hands-on experience with at least two of the following IAM platform categories: IGA: Microsoft Identity Manager, PAM: CyberArk, Beyond Trust, SSO/Federation: Okta, Microsoft Entra ID, Ping Identity, Directory Services: Active Directory, Azure AD/Entra ID, LDAP
  • Experience supporting federal, defense, or highly regulated environments
  • Experience with cloud IAM services (Azure Entra ID, AWS IAM/SSO, GCP IAM)
  • Deep understanding of authentication and authorization protocols: SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), SCIM, Kerberos
  • Extensive hands-on experience with Microsoft identity solutions (Entra ID, AD FS, Microsoft 365, MIM)
  • Proven experience in large-scale, multi-forest Active Directory and Entra ID architectures
  • Advanced knowledge of identity protocols (SAML, OAuth 2.0, OpenID Connect, WS-Federation, CBA)
  • Strong experience with Entra B2B and B2C for external identity management
  • Experience with Entra AD Connect, including custom synchronization rules
  • Strong proficiency in PowerShell and Graph API for identity management automation
  • Familiarity with Zero Trust architecture and identity-related security best practices

Desired Qualifications

  • Relevant certifications, hold at least one or two of the following, aligned to seniority: CIAM (Certified Identity and Access Manager) or CIGE (Certified Identity Governance Expert)
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • CyberArk Defender/Sentry/Guardian
  • Okta Certified Professional/Consultant/Administrator
  • Ping Identity Certified Professional
  • CompTIA Security+
  • Knowledge of identity-related compliance standards (e.g., NIST, FISMA, SOC, FedRamp)
  • Experience with Azure AD Verifiable Credentials and decentralized identity concepts
  • Understanding of biometric authentication methods and their Azure AD integration

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce