Type of Requisition:Regular
Clearance Level Must Currently Possess:Top Secret
Clearance Level Must Be Able to Obtain:Top Secret
Public Trust/Other Required:None
Job Family:IT Infrastructure and Operations
Job Qualifications:Skills:Authentication Methods, Cybersecurity, Enterprise IT
Certifications:None
Experience:10 + years of related experience
US Citizenship Required:Yes
Job Description:The Identity Access Management (IAM) Architect will lead the technical design and implementation of large-scale, global identity access management services supporting the U.S. Department of State's
Bureau of Diplomatic Technologies (DT). This role oversees 24x7 worldwide technical operations, modernization activities, ZTA adoption and compliance, security integration, service management, and customer engagement across all geographic regions.
WHAT YOU'LL DO:- Collaborate with DT and Program Director on defining outputs, outcomes, and adoption framework for project creation and implementation
- Leading team providing steady-state support for current environment IAM implementation, preparing for a modernization journey
- Define and evolve the enterprise architecture, strategy, and roadmap for IAM capabilities, aligning solutions with business, technology, and cybersecurity objectives, including proper management of non-human identities to securely support AI-implementation.
- Design secure, scalable, and automated and AI-augmented solutions for managing service accounts, machine identities, secrets, certificates, APIs, and other identity platforms or use cases.
- Establish governance frameworks, lifecycle controls, and operational standards that identities are securely created, monitored, maintained, and decommissioned.
- Develop architecture artifacts, implementation guidance, metrics, and reporting that promote consistency, automation, resiliency, and operational excellence.
- Serve a trusted advisor, technical leader, and mentor across the program, collaborating with other senior technical leaders and mid- to junior-career staff
REQUIRED QUALIFICATIONS:- Active TS/SCI clearance
- Bachelor's Degree in a related technical discipline
- Minimum of 10 years' technical experience
- Experience working within a government enterprise environment
- Deep understanding of and previous experience with Zero Trust Architecture, NIST frameworks, and other government standards and compliance frameworks.
- Deep understanding of and previous experience with Active Directory and Microsoft Entra, including leading cloud-focused, ZTA centered modernization efforts
- Deep understanding of and previous experience with providing DNS, TCP/IP, PKI, ADFS, and other services from Active Directory, including collaborating with technical leaders to lead cloud-focused, ZTA centered modernization efforts
- Previous experience with identity solutions such as Okta, Ping, CyberArk, and other industry leaders
- Previous experience with Microsoft Azure, Amazon Web Services (AWS), and/or Google Cloud Platform (GCP), primarily implementing modern, secure authentication and access management strategies for cloud hosted applications
- Experience integrating workflows and automation solutions with ITSM platforms such as ServiceNow
- Microsoft Identity and access Administrator Associate (SC-300)
PREFERRED QUALIFICATIONS:
- Experience working within a government enterprise environment
- One or more of the following Microsoft certifications: Microsoft Administrator Expert (MS-102), Microsoft Endpoint Administrator (MD-102), Microsoft Cybersecurity Architect Expert (SC-100), Microsoft Azure Administrator Associate (AZ-104), Microsoft Solutions Architect Expert (AZ-305), Microsoft AI-centric professional certifications or Applied Skills
- CISSP
- Technical certifications from other industry leaders in the IAM segment
- Project Management Professional (PMP)
The likely salary range for this position is $169,604 - $229,464. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours:40
Travel Required:Less than 10%
Telecommuting Options:Onsite
Work Location:USA DC Washington
Additional Work Locations:Total Rewards at GDIT:Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
Our Identity Verification Process:As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.