Serco

Cybersecurity Engineer - ISSE/ISSO

Serco$100K — $120K *
Aerospace & Defense
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Active DoD Secret clearance required at time of hire.
  • Bachelor's degree plus 8 years of information systems security experience; or an Associate's degree with 10 years; or a Master's degree with 6 years.
  • DoD 8570 IAT Level II or III certification (e.g., Security+, CySA+, CISSP) required.
  • Extensive knowledge of ICAM solutions beyond specific vendors, covering governance, credentialing, and access management.
  • Practical experience configuring and managing Okta and SailPoint in a production environment.
  • Understanding of NIST SP 800-53, RMF, and A&A processes.
  • Familiarity with SAML, OIDC, SCIM, and federated identity integration.

Responsibilities

  • Design and maintain secure identity and access management architecture with Okta and SailPoint.
  • Configure Okta SSO and adaptive MFA according to security baselines.
  • Engineer SailPoint identity governance workflows and handle provisioning tasks.
  • Integrate identity systems with directory services like Active Directory and PKI authentication.
  • Conduct security control testing and support RMF assessment for identity systems.
  • Address vulnerability remediation and manage secure configuration baselines.
  • Collaborate with engineering teams to implement zero trust and least-privilege principles.

Benefits

  • Opportunity to work on cutting-edge ICAM security solutions.
  • Hands-on experience with leading identity management tools (Okta, SailPoint).
  • Involvement in broad enterprise security architecture and compliance efforts.
  • Opportunity for professional growth and enhancement of technical skills in a critical field.
  • Flexibility in travel within the CONUS, with opportunities to interact directly with clients.
Full Job Description
Position Description & Qualifications

We are seeking aSenior ISSE/ISSO to serve as both the technical security engineer and the officer of record for identity, credential, and access management (ICAM) security across our enterprise and program systems. This role owns the security architecture, implementation, and continuous authorization of identity governance and access control capabilities, with broad expertise across the ICAM discipline - including credentialing, federation, PKI/PIV-based authentication, privileged access management, and identity governance - and deep hands-on expertise in Okta (identity provider, SSO, MFA, lifecycle/adaptive policies) and SailPoint (IdentityNow/IdentityIQ - identity governance, access certification, provisioning, and role-based access control). Okta and SailPoint are this program's primary toolset, but the candidate must understand ICAM as a discipline, not just these two products, and be able to evaluate, integrate, and troubleshoot the broader ICAM ecosystem (directories, PKI, federation protocols, PAM, and governance) that these tools operate within. The ideal candidate blends the risk-management and compliance responsibilities of an ISSO with the hands-on engineering depth of an ISSE, ensuring identity systems are securely designed, properly authorized, and continuously monitored in accordance with RMF/NIST requirements.

This position is contingent upon the ability to maintain/transfer a DoD Secret Security clearance.

In this role, you will:
  • Design, implement, and maintain secure identity and access management architecture leveraging Okta and SailPoint across enterprise and mission systems.
  • Configure and harden Okta SSO, adaptive MFA, lifecycle management, and API access policies in accordance with security baselines.
  • Engineer SailPoint identity governance workflows, including access certifications, role mining, segregation-of-duties (SoD) policies, and automated provisioning/deprovisioning.
  • Integrate Okta/SailPoint with directory services (Active Directory/Azure AD), PKI/CAC authentication, and downstream applications via SCIM, SAML, and OIDC.
  • Conduct security control implementation and testing for identity systems in support of Risk Management Framework (RMF) Assessment & Authorization (A&A) packages.
  • Support vulnerability remediation, patch management, and secure configuration baselines (STIGs/CIS benchmarks) for IAM infrastructure.
  • Partner with application owners and engineering teams to embed zero trust and least-privilege principles into identity workflows.
  • Serve as the ISSO of record for identity management systems, maintaining continuous authorization to operate (ATO) status.
  • Conduct and document risk assessments, POA&Ms, and continuous monitoring activities for assigned systems.
  • Coordinate with the ISSM, AO, and assessment teams during A&A activities, audits, and inspections (NIST SP 800-53, RMF, FedRAMP as applicable).
  • Monitor and report on security events, incidents, and access anomalies related to identity and access systems; support incident response as needed.
  • Maintain audit-ready documentation for access reviews, certification campaigns, and compliance evidence collection.
  • Ensure identity-related controls align with applicable frameworks (NIST 800-53, NIST 800-63, ICD 503, DoD RMF, or agency-specific requirements).
  • Brief leadership and stakeholders on identity security posture, risk, and remediation status.


To be successful in this role, you will have:
  • Active DoD Secret clearance required at time of hire.
  • A Bachelor's degree plus 8 years of information systems security experience, with demonstrated ISSE and/or ISSO responsibilities.
    • OR an Associate's degree and 10 years of information systems security experience, with demonstrated ISSE and/or ISSO responsibilities.
    • OR a Master's degree and 6years of information systems security experience, with demonstrated ISSE and/or ISSO responsibilities.
  • DoD 8570 IAT Level II or III certification (Security+, CySA+, CISSP, or equivalent)
  • Demonstrated subject-matter expertise across Identity, Credential, and Access Management (ICAM) solutions broadly - not limited to any single vendor product - spanning identity governance, credentialing/PKI, federation, directory services, and access management architecture.
  • Hands-on production experience configuring and administering Okta (SSO, MFA, workflows, lifecycle management).
  • Hands-on production experience with SailPoint (IdentityNow or IdentityIQ) for identity governance, certifications, and provisioning.
  • Working knowledge of NIST SP 800-53, RMF, and Assessment & Authorization (A&A) processes.
  • Experience with SAML, OIDC, SCIM, and federated identity integration patterns.
  • Experience with PKI/PIV/CAC-based credentialing and certificate-based authentication as part of an enterprise ICAM strategy.
  • Understanding of adjacent ICAM capabilities such as privileged access management (PAM), directory services (Active Directory/Azure AD/LDAP), and role-based/attribute-based access control (RBAC/ABAC), and how Okta/SailPoint integrate with them.
  • Ability to assess, integrate, and troubleshoot ICAM solutions and architectures beyond the current Okta/SailPoint toolset, including evaluating new or legacy identity platforms as mission needs evolve.
  • Familiarity with STIGs, CIS benchmarks, and secure configuration management.
  • Strong written communication skills for security documentation (SSPs, POA&Ms, risk assessments).
  • Must be able to work Central Time Zone work hours.
  • The ability to travel up to 25% (CONUS).
    • Must be okay traveling to San Antonio, TX on a customer needed basis.


Additional desired experience and skills:
  • CISSP, CISM, or SailPoint/Okta vendor certifications (Okta Certified Administrator, SailPoint IdentityNow Engineer).
  • Broader ICAM platform experience beyond Okta/SailPoint (Ping Identity, ForgeRock, Microsoft Entra ID, CyberArk, or similar IAM/PAM/governance products), demonstrating vendor-agnostic ICAM fluency.
  • Experience integrating IAM platforms with PKI/CAC/PIV authentication.
  • Familiarity with zero trust architecture (ZTA) principles and DoD Zero Trust reference architecture.
  • Scripting/automation experience (PowerShell, Python) for identity workflow automation.

About Serco

Serco Group plc is a British company providing public services. It is listed on the London Stock Exchange and is a constituent of the FTSE 250 Index. The company has four divisions: Health, Justice and Immigration, Transport, and Defence, and operates across the UK and Europe, North America, Asia Pacific and the Middle East. Serco primarily provides public services to governments, including the operation of prisons and hospitals, defence and aerospace services, and transport services. The company also provides IT and consultancy services to the public sector. Serco has been involved in a number of controversies, including allegations of overcharging the UK government and mismanagement of contracts.
Learn more about Serco
Size
50,000 employees
Industry
Founded
1988

Similar Jobs

More Jobs at Serco

More Aerospace & Defense Jobs

Find similar Cybersecurity Engineer - ISSE/ISSO jobs: