About the roleWe are seeking a mid-level Identity Policy Analyst to support a federal government client's identity, credential, and access management (ICAM) program. This role assesses the current identity and access environment, identifies gaps against federal policy and target-state architectures, and delivers actionable recommendations and support that advance the agency's Zero Trust and ICAM modernization goals.
What you'll do- Assess the current-state identity, credential, and access management (ICAM) environment, including systems, processes, and governance, to establish a clear baseline of existing capabilities.
- Identify gaps between current-state ICAM capabilities and target-state requirements, including alignment with Zero Trust principles and maturity models (e.g., CISA Zero Trust Maturity Model, NIST SP 800-207).
- Develop findings, risk-informed recommendations, and prioritized roadmaps to close identified gaps and advance ICAM and Zero Trust maturity.
- Interpret and apply relevant federal policy, guidance, and frameworks, including GSA's Federal Identity, Credential, and Access Management (FICAM) Playbook, NIST SP 800-63 (Digital Identity Guidelines), NIST SP 800-207 (Zero Trust Architecture), OMB M-22-09 (Federal Zero Trust Strategy), HSPD-12, and FISMA.
- Translate policy and framework requirements into practical, actionable guidance for technical teams, program leadership, and agency stakeholders.
- Support development of ICAM strategy documents, implementation plans, and governance artifacts, such as policy briefs, assessment reports, and roadmaps.
- Collaborate with cross-functional teams, including engineering, cybersecurity, and program management, to ensure recommendations are technically sound and operationally feasible.
- Prepare clear, well-organized written products and briefings for both technical and executive audiences.
- Monitor evolving federal identity and Zero Trust policy, guidance, and standards, and assess their impact on the program.
- Support governance and compliance activities related to identity, such as control assessments, audits, and reporting.
Qualifications- Bachelor's degree in Information Technology, Cybersecurity, Public Policy, or a related field, and 4+ years of relevant experience; or 6+ years of relevant experience in lieu of a degree.
- Demonstrated experience with identity, credential, and access management (ICAM) programs, cybersecurity policy, or federal IT policy and compliance.
- Working knowledge of GSA's FICAM Playbook and its application to agency ICAM programs.
- Familiarity with Zero Trust principles and frameworks, including NIST SP 800-207 and OMB's Federal Zero Trust Strategy (M-22-09).
- Understanding of federal identity and security guidance, including NIST SP 800-63, HSPD-12, and FISMA.
- Experience assessing current-state environments, performing gap analyses, and developing practical recommendations and roadmaps.
- Strong analytical, critical-thinking, and problem-solving skills, with the ability to synthesize policy and technical information.
- Excellent written and verbal communication skills, with experience briefing both technical staff and program/agency leadership.
- Ability to work collaboratively with technical, policy, and program stakeholders across a government engagement.
- Must be eligible to obtain a Public Trust government security clearance.
Preferred Qualifications- Prior experience directly supporting a federal ICAM, Zero Trust, or identity governance program.
- Relevant certification such as CAP, CISSP, or CISA.
- Familiarity with NIST SP 800-53 security controls and their intersection with identity and access management.
The salary range for this role is $120,000 to $135,000 annually.