ICAM Operations Engineer – Enterprise Authentication Services

General Dynamics Information Technology, Inc.

$114K — $155K *
US-AnywhereRemote in United States
Enterprise Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in Identity and Access Management (IAM) or related technologies.
  • 3+ years of hands-on experience with Microsoft ADFS.
  • Strong understanding of authentication and federation concepts.
  • Familiarity with SAML, OAuth, OIDC, and related identity technologies.
  • Ability to document and effectively communicate technical issues.

Responsibilities

  • Provide Tier III support for Identity Provider (IdP) services used by millions of DoD users.
  • Monitor and troubleshoot Microsoft ADFS infrastructure for authentication and federation.
  • Resolve complex incidents involving authentication, certificates, and claims rules.
  • Manage ITSM tickets in coordination with engineering and cybersecurity teams.
  • Support enterprise onboarding by validating application configurations and federation behavior.
  • Troubleshoot identity protocol issues and perform operational sustainment activities.
  • Contribute to Zero Trust operational readiness and continuous improvement efforts.

Benefits

  • Variety of medical plan options including some with Health Savings Accounts.
  • 401(k) plan with company matching and flexibility for pre/post-tax contributions.
  • Paid time off including vacation, sick leave, and parental leave.
  • Up to 160 hours of paid family leave within a rolling 12 month period.
  • Comprehensive disability and life insurance options.
Full Job Description

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

Secret

Clearance Level Must Be Able to Obtain:

Secret

Public Trust/Other Required:

None

Job Family:

IT Infrastructure and Operations

Job Qualifications:

Skills:

Access Management, Authentication, Authentication Protocols, Identity Access Management (IAM)

Certifications:

None

Experience:

5 + years of related experience

US Citizenship Required:

Yes

Job Description:

ICAM Operations Engineer – Enterprise Authentication Services

GDIT has an opportunity for an ICAM Operations Engineer supporting a large line of business delivering enterprise-scale Identity, Credential, and Access Management (ICAM) capabilities. This role supports the DoD ICAM mission by operating, sustaining, and troubleshooting enterprise Identity Provider (IdP) services that provide secure authentication and federation for more than 4 million DoD enterprise identities.

This is a fully remote position.

Meaningful Work and Personal Impact

The ideal candidate has at least 3 years of hands-on experience supporting identity or authentication systems and excels in enterprise operational environments. Strong foundational skills in Microsoft Active Directory Federation Services (ADFS), authentication protocols, troubleshooting, and Tier III support are essential. This role provides opportunities to work closely with senior engineers, respond to complex operational issues, and support mission-critical identity services across large-scale DoD environments.

Responsibilities:

  • Provide Tier III operational support for enterprise Identity Provider (IdP) services used by millions of DoD users.
  • Perform daily operations, monitoring, and troubleshooting of Microsoft ADFS infrastructure supporting authentication and federation.
  • Investigate and resolve complex incidents involving authentication, federation trust, certificates, tokens, claims rules, and identity assertion issues.
  • Manage and resolve ITSM tickets (incident, problem, and change) in coordination with engineering, cybersecurity, and infrastructure teams.
  • Support enterprise onboarding and integration efforts by validating application configurations and ensuring proper federation behavior.
  • Troubleshoot identity protocol issues involving SAML, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication.
  • Perform operational sustainment activities such as certificate lifecycle management, configuration updates, monitoring review, health checks, and patch validation.
  • Maintain authentication policies, claims rules, attribute mappings, and token issuance configurations under engineering guidance.
  • Support enterprise SSO, MFA, Conditional Access, and phishing-resistant authentication mechanisms.
  • Contribute to Zero Trust operational readiness by ensuring modern authentication and federation capabilities remain stable and functional.
  • Participate in Agile support activities and continuous improvement efforts.
  • Document operational procedures, incident resolutions, troubleshooting steps, and system behaviors.

Basic Qualifications:

  • Active Secret Clearance at minimum. Interim Secret Clearances are not allowed.
  • Bachelor27s Degree in a related technical discipline, or the equivalent combination of education, technical certifications or training, or work experience.
  • DoD 8570/8140 IAT Level II certification (Security+ CE or higher)

Required Skills/Knowledge:

  • Minimum of 5 years of experience with at least 3 years of experience supporting Identity and Access Management (IAM), Authentication, Federation, or ICAM-related technologies.
  • Hands-on experience with Microsoft ADFS in enterprise operational environments.
  • Strong understanding of authentication, authorization, and federation concepts.
  • Familiarity with SAML, OAuth, OIDC, WS-Federation, certificates, and related identity technologies.
  • Experience with PKI, certificate-based authentication, smart cards, or MFA.
  • Experience supporting application integrations with identity/federation platforms.
  • Familiarity with Active Directory, LDAP, and enterprise identity repositories.
  • Strong troubleshooting skills for identity/ADFS issues and ability to perform Tier III diagnostics.
  • Ability to document findings and communicate technical issues effectively.
  • Self-starter with desire for growth in enterprise identity operations.

Desired Skills/Knowledge:

  • Experience with ADFS farms, Web Application Proxy (WAP), load balancers, or disaster recovery setups.
  • Exposure to modern identity platforms such as Microsoft Entra ID, PingFederate, PingAccess, Okta, or Keycloak.
  • Familiarity with DoD ICAM or federation initiatives.
  • Understanding of NIST 800963 identity assurance concepts.
  • Experience with phishing-resistant authentication or passwordless technologies.
  • Basic PowerShell scripting for identity operations.
  • Experience with monitoring, performance tuning, or troubleshooting authentication issues at scale.
  • Familiarity with PKI/certificate services, CAC authentication, or DoD credentialing.
  • Awareness of container technologies such as Docker and Kubernetes.


The likely salary range for this position is $114,750 - $155,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

Less than 10%

Telecommuting Options:

Remote

Work Location:

Any Location / Remote

Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee27s date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.


Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

Similar Jobs

More Jobs at General Dynamics Information Technology, Inc.

More Enterprise Technology Jobs

Find similar ICAM Operations Engineer – Enterprise Authentication Services jobs: