ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services

General Dynamics Information Technology, Inc.

$170K — $230K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in IAM, Authentication, Federation, ICAM solutions
  • Strong expertise with Microsoft Active Directory Federation Services (ADFS)
  • Experience deploying Identity Provider services for large organizations
  • Proficiency in authentication protocols like SAML 2.0, OAuth 2.0, OpenID Connect
  • CompTIA Security+ or equivalent IAT Level II certification required
  • US Citizenship required
  • Active Secret clearance required.

Responsibilities

  • Design and maintain enterprise IdP services for 4 million identities.
  • Administer ADFS infrastructure for authentication and federation needs.
  • Set up trust relationships with various Identity and Service Providers.
  • Troubleshoot authentication solutions using modern protocols.
  • Support onboarding of enterprise applications within authentication frameworks.
  • Develop policies for claims and authorization workflows.
  • Ensure operational readiness of SSO and MFA capabilities.

Benefits

  • Variety of medical, dental, and vision plans
  • 401(k) plan with company match
  • Flexible work weeks and generous PTO plans
  • Paid Family Leave up to 160 hours annually
  • Short and long-term disability insurance options
  • Life and critical illness insurance coverage
  • Regular reviews of competitive benefits package.
Full Job Description

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

Secret

Clearance Level Must Be Able to Obtain:

Secret

Public Trust/Other Required:

None

Job Family:

IT Infrastructure and Operations

Job Qualifications:

Skills:

Active Directory Domain Services (AD DS), Active Directory Federation Services (AD FS), Authentication Systems, Microsoft Azure

Certifications:

CompTIA Security+ CE | CompTIA - CompTIA

Experience:

8 + years of related experience

US Citizenship Required:

Yes

Job Description:

ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services

GDIT has an opportunity for an ICAM Engineer supporting a large line of business that delivers enterprise-scale Identity, Credential, and Access Management (ICAM) capabilities. This role supports the DoD ICAM mission by designing, developing, integrating, and maintaining enterprise Identity Provider (IdP) services that provide secure authentication and federation for more than 4 million enterprise identities across the Department of Defense.

This is a fully remote position.


MEANINGFUL WORK AND PERSONAL IMPACT
The ideal candidate is a senior hands-on identity engineer with expertise in Microsoft Active Directory Federation Services (ADFS), enterprise authentication, federation technologies, and modern identity protocols. This role focuses on delivering highly available authentication services, federation trust management, single sign-on (SSO), multi-factor authentication (MFA), and secure application integration across a large-scale enterprise environment..

  • Design, develop, configure, and maintain enterprise Identity Provider (IdP) services supporting over 4 million enterprise identities.
  • Engineer, administer, and sustain Microsoft Active Directory Federation Services (ADFS) infrastructure supporting enterprise authentication and federation.
  • Configure and maintain federation trust relationships with internal and external Identity Providers (IdPs), Service Providers (SPs), and mission partners.
  • Design, implement, and troubleshoot authentication solutions utilizing SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication.
  • Support onboarding and integration of enterprise applications into the authentication and federation ecosystem.
  • Develop authentication policies, claims rules, attribute mappings, token issuance policies, and authorization workflows.
  • Support enterprise Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, and phishing-resistant authentication capabilities.
  • Collaborate with cybersecurity, Active Directory, cloud, infrastructure, and application teams to implement secure authentication services.
  • Support implementation of Zero Trust Architecture through modern authentication, federation, and identity assurance capabilities.
  • Monitor, troubleshoot, and resolve complex authentication, federation, trust, certificate, token, and identity assertion issues.
  • Engineer highly available and resilient authentication services supporting mission-critical enterprise applications.
  • Develop technical documentation including architecture diagrams, integration guides, SOPs, TTPs, operational procedures, and onboarding documentation.
  • Participate in Agile development activities and continuous service improvement initiatives.
  • Actively manage technical risks and contribute to enterprise identity modernization efforts.

Basic Qualifications:

  • Active Secret Clearance at minimum. Interim Secret Clearances are not allowed.
  • Bachelors Degree in a related technical discipline, or the equivalent combination of education, technical certifications or training, or work experience.
  • DoD 8570/8140 IAT Level II certification (Security+ CE or higher)

Required Skills/Knowledge:

  • Minimum of 8 years of experience supporting Identity and Access Management (IAM), Authentication, Federation, or ICAM solutions within government or regulated environments
  • Strong experience designing, implementing, and supporting Microsoft Active Directory Federation Services (ADFS).
  • Extensive experience implementing enterprise Identity Provider (IdP) services supporting large user populations.
  • Strong understanding of authentication, authorization, federation, and identity assurance concepts
  • Experience implementing and troubleshooting SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and JWT technologies
  • Experience supporting PKI, certificate-based authentication, smart card authentication, and MFA solutions
  • Experience integrating applications, APIs, and enterprise services with federation platforms
  • Experience with Active Directory, LDAP directories, and enterprise identity repositories
  • Experience configuring claims, attribute mappings, policy enforcement, token transformations, and federation workflows
  • Experience supporting Linux and/or Windows Server environments
  • Experience deploying and supporting enterprise COTS products in secure customer environments
  • Experience working in Agile development environments and utilizing associated tools
  • Strong written and verbal communication skills
  • Self-starter capable of driving complex technical efforts to completion

Desired Skills/Knowledge:

  • Experience designing and supporting highly available ADFS farms with Web Application Proxy (WAP), load balancing, and disaster recovery architectures.
  • Experience with Microsoft Entra ID (Azure AD), PingFederate, PingAccess, PingDirectory, Okta, Keycloak, or similar enterprise authentication platforms.
  • Experience supporting DoD Enterprise ICAM, Federation Hub, or mission partner federation initiatives
  • Experience implementing federation solutions for coalition, partner, or cross-organizational environments
  • Experience supporting NIST 800-63 Identity Assurance Levels (IAL), Authenticator Assurance Levels (AAL), and Federation Assurance Levels (FAL)
  • Experience implementing phishing-resistant authentication technologies and passwordless authentication solutions.
  • Experience supporting Zero Trust Architecture and identity-centric security initiatives.
  • Familiarity with PowerShell scripting and automation for ADFS administration.
  • Experience supporting enterprise monitoring, performance tuning, and capacity planning for authentication services supporting millions of identities.
  • Experience with Active Directory Certificate Services (AD CS) and enterprise PKI.
  • Familiarity with container technologies such as Docker and Kubernetes.
  • Familiarity with DoD PKI, CAC authentication, derived credentials, and certificate lifecycle management.
  • Experience supporting highly available, mission-critical enterprise authentication environments.

The likely salary range for this position is $170,000 - $230,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

Less than 10%

Telecommuting Options:

Remote

Work Location:

Any Location / Remote

Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employees date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.


Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

Similar Jobs

More Jobs at General Dynamics Information Technology, Inc.

More Information Technology Jobs

Find similar ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services jobs: