Job Title: Identity Access Management SME
Location: Washington, DC
Type: Contract
Compensation: $63.75/hr
Work Model: Onsite - onsite
Hours: 40.0
Security Clearance: Ability to obtain and maintain a Public Trust Clearance (or higher if required)
Overview This is a
senior-level cybersecurity and identity management role focused on leading enterprise
Identity and Access Management (IAM) strategy, governance, and operations. The position serves as the technical authority for
Microsoft Entra ID (Azure AD), Microsoft ICAM, Zero Trust security, and identity governance, ensuring secure access across cloud and on-premises environments.
Responsibilities - Serve as the senior technical authority for enterprise IAM capabilities supporting the contract.
- Lead the design, implementation, and governance of Microsoft Entra- and Microsoft ICAM-based frameworks and identity services to ensure secure authentication, authorization, compliance, and least-privilege access across cloud and on-premises environments.
- Drive the implementation of conditional access, MFA, PIM/PAM, RBAC, and identity governance workflows aligned with SEC zero-trust objectives and OMB M-22-09 direction.
- Partner with infrastructure, security, and operations teams to sustain audit readiness, support FISMA evidence requirements, and resolve complex identity and access challenges at enterprise scale.
- Design and implement secure authentication and authorization models using Microsoft Entra ID, Microsoft ICAM, and role-based access controls.
- Lead the integration of Entra identity services with Microsoft 365 and enterprise applications for consistent identity lifecycle and policy enforcement.
- Define IAM standards, patterns, and operating procedures aligned with zero-trust principles and federal security requirements.
- Manage joiner/mover/leaver identity lifecycle processes, directory services, and account governance to maintain accurate access provisioning.
- Implement and maintain conditional access policies, MFA, privileged identity/access management, and identity protection controls.
- Establish and operate access reviews, entitlement management, and governance workflows to enforce least privilege and reduce insider-risk exposure.
- Oversee RBAC design, assignment, and recertification, including automated processes for policy consistency.
- Ensure IAM services support continuing Authorization to Operate objectives with complete SOP and control documentation.
- Align IAM controls with NIST, ISO 27001, CISA SCuBA, FISMA, and SEC/OIT security policy requirements.
- Produce artifacts and evidence for audits, assessments, FISMA, and internal/external reviews.
- Support remediation planning and corrective actions for IAM findings, risks, and deficiencies.
- Lead resolution of complex identity and access incidents, root causes, and recurring gaps.
- Drive automation of identity provisioning, deprovisioning, policy enforcement, and reporting.
- Collaborate with security, cloud, endpoint, and service management teams to implement identity-dependent controls.
- Provide strategic guidance to stakeholders on IAM roadmap priorities, modernization, and operational risk.
Requirements - Must meet contract requirements for citizenship/work authorization.
- Ability to obtain and maintain Public Trust clearance (or higher if required).
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Engineering, or a related field.
- Minimum 8 years of experience in identity governance, IAM, or cybersecurity roles supporting enterprise environments.
- Hands-on experience implementing and operating Microsoft Entra ID (Azure AD) and Microsoft ICAM capabilities.
- Advanced experience with MFA, conditional access, privileged access management, and identity governance.
- Strong understanding of compliance frameworks (NIST, ISO 27001, CISA SCuBA) and zero-trust principles.
- Experience supporting federal or highly regulated enterprise IAM modernization initiatives (preferred).
- Knowledge of scripting/automation tools for IAM operations (preferred).
- Certifications such as Microsoft SC-300, CISSP, or CISM are a plus.
System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
#M-M2
#LI-HJA
Ref: #851-Rockville-S1