OverviewDecisionPointseeks an Identity & Access Management (IAM) Engineer to support enterprise identity operations and authentication services for a large federal and DoD-aligned mission environment. This role manages identity governance, access control enforcement, single sign-on (SSO) integrations, and multi-factor authentication (MFA) capabilities across cloud andon-premiseenvironments. The IAM Engineer will contribute directly to the implementation of the Zero Trust identity pillar, ensuring secure, reliable, and policy-driven access to mission-critical systems.
This position is fully remote.
Duties & Responsibilities
The Identity & Access Management Engineer will:
- Manage SSO integrations across enterprise applications and services.
- Configure andmaintainidentitygovernanceworkflows, account lifecycle management, and access approval processes.
- Implement and manage MFA, conditional access policies, and identity verification mechanisms.
- Support development and enforcement of identity-based access controls aligned with Zero Trust principles.
- Configure IAM roles, permissions, and policies in cloud environments, including AWS IAM.
- Conduct access reviews, entitlement audits, and privileged access assessments.
- Partner with cybersecurity teams to align identity controls with DoD security and compliance requirements.
- Troubleshoot identity issues related to SSO, MFA, directory services, and authentication flows.
- Assistwith identity roadmap planning, modernization activities, and capability enhancements.
- Maintain identity standards, configuration documentation, and architectural artifacts.
- Support incident response activities related to identity threats or compromised accounts.
- Contribute to the development and refinement of IAM procedures, playbooks, and governance models.
Qualifications
Clearance Requirement
Must hold an active Top Secret clearance, supported by a Tier 5 background investigation.
Education (Required)
Bachelor27s degree in Cybersecurity, Information Technology, Computer Science, ora relatedfield.
Experience (Required)
- Minimum 6yearsof experience in identity and access management, authentication engineering, or IAM operations.
- Experience implementing or supporting SSO integrations, MFA configurations, or identity governance processes.
- Experience managing IAM roles, policies, and permissions in cloud environments (AWS preferred).
- Experience conducting access reviews, entitlement audits, or privilege management activities.
- Experience supporting the implementation of identity-focused security controls.
Technical Knowledge (Required)
- Strong understanding of IAM concepts, including authentication, authorization, federation, and identity governance.
- Experience with SSO technologies, MFA systems, and identity providers.
- Proficiencyin AWS IAM roles, policies, access keys, and permission boundaries.
- Knowledge of Zero Trust identity principles and identity-centric access control models.
- Understanding of DoD cybersecurity requirements related to identity and access management.
Technical Knowledge (Preferred)
- Experience with directory services (e.g., Active Directory, Azure AD).
- Familiarity with identity risk scoring, behavioral analytics, or conditional access signals.
- Experience integrating IAM with CI/CD pipelines orDevSecOpsworkflows.
Certifications
Required:
Preferred:
- AWS IAM or AWS Security specialty certification
- Additional DoD 8570/8140 IAM-related certifications
Skills
- Strong problem-solving abilities for diagnosing authentication and access issues.
- Excellent communication skills for collaborating with cybersecurity, engineering, and application teams.
- High attention to detail for managing access controls, policies, and identity workflows.
- Ability to manage multiple IAM initiatives in a fast-paced, mission-critical environment.
- Strong documentation skills formaintainingidentity policies, standards, and technical procedures.