Tetra Tech

DevOps Engineer (IDP/Keycloak SME)

Tetra Tech$130K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6-10 years of experience in technology support, DevOps, or system administration roles.
  • Proficiency in Linux/Unix and Windows server administration.
  • Hands-on experience administering, engineering, and troubleshooting Keycloak or comparable enterprise IdP/IAM platforms.
  • Strong understanding of OAuth 2.0, OIDC, SAML, JWT, authentication, authorization, and identity federation.
  • Experience integrating identity services with enterprise applications and APIs.
  • Experience troubleshooting complex authentication and application integration issues.
  • Hands-on experience integrating applications with Login.gov.

Responsibilities

  • Serve as a technical SME for Keycloak, Identity Provider (IdP), IAM, and Login.gov solutions.
  • Design, deploy, configure, and maintain Keycloak environments across multiple stages.
  • Implement and support OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, and JWT-based authentication.
  • Configure and troubleshoot Login.gov identity provider integrations.
  • Support testing and validation of Login.gov integrations across all environments.
  • Monitor identity platform performance and troubleshoot authentication issues.
  • Develop and maintain secure authentication patterns for applications in cloud environments.

Benefits

  • Remote work flexibility.
  • Opportunity to work with cutting-edge IAM technologies and cloud applications.
  • Support for professional development and technical mentorship opportunities.
  • Engagement with high-impact projects in a federal agency setting.
Full Job Description
Job Description
The Federal Aviation Administration (FAA) is seeking a highly skilled System Engineer to serve as an Identity Provider (IDP) Subject Matter Expert (SME) by providing advanced engineering, implementation, integration, and operational support for enterprise identity and access management (IAM) services. The engineer will serve as a subject matter expert for Keycloak, IDP technologies, and Login.gov integrations, helping design, deploy, secure, automate, and maintain identity services supporting cloud-hosted applications and platforms.

Salary is based on relative years of experience: $130,000 - $150,000

Job Duties & Responsibilities - Essential Job Functions may include (but are not limited to) the following:
The following duties are considered essential to the role. Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions
  • Serve as a technical SME for Keycloak, Identity Provider (IdP), IAM, and Login.gov solutions supporting FAA cloud applications and services.
  • Design, deploy, configure, upgrade, and maintain Keycloak environments across development, test, staging, and production environments.
  • Configure and manage Keycloak realms, clients, roles, groups, users, service accounts, identity providers, authentication flows, and authorization policies.
  • Implement and support OAuth 2.0, OpenID Connect (OIDC), SAML 2.0, and JWT-based authentication.
  • Design and implement secure integrations between FAA applications and Login.gov for authentication and identity verification use cases.
  • Support applications integrating with Login.gov using OpenID Connect/OAuth 2.0 patterns.
  • Configure and troubleshoot Login.gov identity provider integrations, including client registration, redirect/return URLs, scopes, claims, authentication flows, and token handling.
  • Support integration between Login.gov, Keycloak, and FAA applications where federated identity or identity brokering is required.
  • Troubleshoot authentication issues involving Login.gov, Keycloak, application clients, tokens, claims, certificates, redirects, and federation.
  • Apply Login.gov integration and security requirements to application onboarding and deployment activities.
  • Support testing and validation of Login.gov integrations across development, test, staging, and production environments.
  • Coordinate with application teams and identity/security stakeholders to resolve Login.gov integration issues and ensure proper authentication flows.
  • Implement and support Single Sign-On (SSO) capabilities across cloud applications and enterprise services.
  • Support federation with enterprise directories and identity services, including LDAP/Active Directory and other authoritative identity sources.
  • Configure and manage identity federation, identity brokering, token exchange, identity mapping, claims, scopes, and protocol mappers.
  • Develop and maintain secure authentication and authorization patterns for applications operating within FAA cloud environments.
  • Implement role-based access control (RBAC) and least privilege access patterns.
  • Develop automated processes for Keycloak provisioning, configuration, deployment, and lifecycle management.
  • Use Terraform and Infrastructure as Code (IaC) to automate cloud infrastructure and identity platform configurations.
  • Integrate Keycloak and identity-related deployments into CI/CD pipelines and DevSecOps workflows.
  • Support containerized Keycloak deployments using Red Hat OpenShift/Kubernetes and cloud-native technologies.
  • Configure Keycloak for high availability, scalability, resilience, backup/recovery, and disaster recovery requirements.
  • Monitor identity platform performance, authentication activity, availability, logs, and system health.
  • Support certificate and key management associated with TLS, signing certificates, encryption, SAML, OIDC, and JWT-based integrations.
  • Implement security hardening for Keycloak and supporting identity infrastructure in accordance with FAA cybersecurity requirements and applicable federal security standards.
  • Support vulnerability remediation, patching, configuration management, and security assessments of identity services.
  • Integrate identity services with cloud security, logging, monitoring, and SIEM platforms.
  • Support cybersecurity teams with audit evidence, security assessments, compliance documentation, and remediation activities.
  • Participate in incident response and root-cause analysis for identity and authentication-related incidents.
  • Support change management activities, including technical analysis, implementation planning, testing, deployment, and validation.
  • Develop and maintain architecture documentation, configuration standards, deployment procedures, and troubleshooting guides.
  • Provide technical mentorship and guidance to junior engineers on IAM, Keycloak, Login.gov, authentication, authorization, and DevSecOps practices.
    Required Qualifications - A successful candidate will have
  • 6-10 years of experience in technology support, DevOps, or system administration roles.
  • Proficiency in Linux/Unix and Windows server administration.
  • Hands-on experience administering, engineering, and troubleshooting Keycloak or comparable enterprise IdP/IAM platforms.
  • Strong understanding of OAuth 2.0, OIDC, SAML, JWT, authentication, authorization, and identity federation.
  • Experience integrating identity services with enterprise applications and APIs.
  • Experience troubleshooting complex authentication and application integration issues.
  • Understanding of cybersecurity principles, secure configuration, vulnerability remediation, and access control.
  • Hands-on experience integrating applications with Login.gov.

Education
  • Bachelor's degree in Information Technology, Computer Science, Engineering, or related field (or equivalent experience).

Work Requirements and Additional Information
  • Work Location: Remote
  • Position is: Remote
  • Work Hours: 40
  • Travel: 0%
  • Background check: Must have the ability to obtain and maintain a public trust clearance, which requires U.S. citizenship.
  • Physical Requirements:
    • Extended Computer Use: Regular and prolonged periods of working at a computer terminal.
    • Mobility: Ability to move around the office environment to access computer hardware, networking equipment, and server rooms.
    • Dexterity: Manual dexterity and visual acuity to operate computer equipment, troubleshoot issues, and perform tasks requiring precision.
    • Sitting/Standing: Both prolonged sitting and occasional standing may be required for troubleshooting and attending to system issues.
  • Work Environment/Environmental Factors
    • Primarily computer-based work; meetings or collaboration may be required.


About Tetra Tech

Tetra Tech, Inc. is an American engineering services company that provides consulting, engineering, program management, and construction management services. The company serves a range of industries, including water, environment, infrastructure, resource management, energy, and international development. Tetra Tech was founded in 1966 and is headquartered in Pasadena, California. The company operates in over 50 countries and has more than 20,000 employees.
Learn more about Tetra Tech
Size
21,000 employees
Market Cap
$7.9 billion
Industry
Net Income
$178.9 million
Founded
1966
5 Year Trend
+6.9%
Revenue
$2.3 billion
NASDAQ

Similar Jobs

More Jobs at Tetra Tech

More Information Technology Jobs

Find similar DevOps Engineer (IDP/Keycloak SME) jobs: