ICAM Architect

Booz Allen Hamilton, Inc.

$86K — $198K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience with Okta or Entra ID and Certificate-based authentication
  • Strong proficiency in SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC)
  • Experience developing and troubleshooting custom integrations for SAML, OAuth, and OIDC
  • Proficient in programming languages like Java, JavaScript, Python, PowerShell, or Groovy for identity development
  • Hands-on experience with RESTful APIs and identity provider integration
  • Knowledge of Active Directory (AD) or LDAP integration and management
  • Understanding of Zero Trust architectures and implementing password-less or MFA authentication
  • HS diploma or GED required

Responsibilities

  • Support large-scale identity and access management (IAM) projects for clients
  • Interface with stakeholders and engineering teams to gather requirements
  • Analyze identity lifecycles and articulate access needs for users
  • Design, deploy, and manage identity verification systems
  • Implement enterprise-class solutions for identity management
  • Resolve complex identity and federation issues, such as token validation and connectivity problems

Benefits

  • Comprehensive health, life, and disability insurance
  • Retirement and financial benefits including tuition assistance
  • Professional development opportunities
  • Paid leave and work-life balance programs
  • Employee recognition awards for outstanding performance
Full Job Description
ICAM Architect
The Opportunity:

As an ICAM Architect at Booz Allen, you'll play a critical role in the world of identity and access management and zero trust. In this role, you'll support large-scale IAM projects for our clients. You'll interface with stakeholders and engineering teams to delve into the details and dependencies of critical processes and users' roles within them.

You'll analyze the identity lifecycle, articulating access requirements and defining enterprise identity records. You'll use your experience in IAM to design, deploy, and support systems that verify appropriate user privileges and manage credentials for accessing the enterprise's most valuable assets. From single sign-on to privileged access systems, you'll have the chance to implement enterprise-class solutions and stop adversaries in their tracks. Due to the nature of work performed within this facility, U.S. citizenship is required.

Join us. The world can't wait.

You Have:
  • Experience with Okta or Entra ID and Certificate-based authentication
  • Experience with SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC)
  • Experience developing custom SAML, OAuth, and OIDC integrations and troubleshooting protocol exchanges
  • Experience with languages used for identity platform development and automation such as Java, JavaScript, Python, PowerShell, or Groovy
  • Experience working with RESTful APIs to integrate identity providers with external applications and automate identity lifecycle processes
  • Experience integrating and synchronizing with Active Directory (AD) or LDAP and AD Management
  • Knowledge of Zero Trust architectures and implementation of password-less authentication or multifactor authentication (MFA) within the IdP environment
  • Ability to resolve complex identity and federation issues, including token validation errors, assertion mismatches, and connectivity problems
  • HS diploma or GED


Nice If You Have:
  • Experience with Okta Provisioning, Entra ID, Entra ID Connect, and Workday integrations
  • Experience with Identity Governance products such as Saviynt, Sailpoint, Omada, or Oracle IAM
  • Experience building or enhancing automated user lifecycle management using System for Cross-domain Identity Management protocols
  • Experience integrating identity provider code and configurations into DevOps and CI/CD pipelines for automated build and deployment workflows
  • Knowledge of advanced Okta development features such as Okta Workflows, Custom Authorization Servers, Inline Hooks, and Okta APIs for enhanced platform customization
  • Knowledge of compliance and regulatory standards such as NIST, FedRAMP, CMMC, or other frameworks relevant to identity management solutions
  • Knowledge of cloud identity platforms such as AWS Cognito, Azure AD B2C, KeyCLoak, or Google Cloud Identity
  • Possession of excellent verbal and written communication skills
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology


Compensation

At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $86,800.00 to $198,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date.

Identity Statement

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Candidate AI Usage Policy

AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided.

Work Model
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.
  • Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
  • Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
  • Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.


Similar Jobs

More Jobs at Booz Allen Hamilton, Inc.

  • Security Manager, Mid
    $69K — $158K *
    Beale Afb, CA 95903 (Yuba County)
    Aerospace & Defense
    In-Person
  • Electrical Engineer
    $77K — $176K *
    Albuquerque, NM 87121 (Bernalillo County)
    Aerospace & Defense
    In-Person
  • Electrical Engineer
    $77K — $176K *
    Kirtland Afb, NM 87117 (Bernalillo County)
    Aerospace & Defense
    In-Person
  • CNO Analyst and Programmer
    $69K — $158K *
    Annapolis, MD 21401 (Anne Arundel County)
    Technical Services
    In-Person
  • CNO Analyst and Programmer
    $69K — $158K *
    Annapolis Junction, MD 20701 (Howard County)
    Technical Services
    In-Person

More Information Technology Jobs

Find similar ICAM Architect jobs: