ECS

Identity and Access Management Engineer

ECS$130K — $180K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • U.S. Citizen with Active DoD Secret security clearance
  • High School Diploma and 6+ years experience in Identity and Access Management
  • Required Active Certifications: IAT Level II Security+ (or higher), SAA-C03 AWS Certified Solutions Architect - Associate, AZ-104 Azure Administrator - Associate or AZ-800
  • Working knowledge of AppGate SDP architecture and components
  • Strong understanding of Zero Trust principles and least-privilege access

Responsibilities

  • Design and implement a formal RBAC framework across environments
  • Establish and enforce least privilege policies based on Zero Trust architecture
  • Validate access controls for compliance with Zero Trust security requirements
  • Develop identity lifecycle processes for timely onboarding and offboarding
  • Implement and manage a Privileged Access Management program
  • Lead access reviews and audits for compliance
  • Collaborate with leadership to align IAM policies with organizational changes

Benefits

  • Opportunity for hybrid work in Fairfax, VA (up to 3 days in office)
Full Job Description
Everforth ECS is seeking an Identity Infrastructure Engineer to work in our Fairfax, VA office in a hybrid capacity.

Everforth ECS is seeking an experienced and technically sharp Identity Infrastructure Engineer to join a team responsible for managing and maintaining multiple network enclaves to support the DoW community. This role oversees the design, implementation, and ongoing support of the organization's directory and identity management solutions which is the foundational layer that underpins access, authentication, and security across the entire enterprise.

In this role, you will own the health, integrity, and security of the organization's identity infrastructure. That means administering Microsoft Active Directory and related directory services, managing PKI and certificate lifecycle operations, and ensuring that the identity backbone supporting thousands of users and systems is reliable, well-documented, and hardened against threats.

This is a hands-on senior-level role for someone who takes pride in keeping complex infrastructure running cleanly, communicates clearly with teams across the organization, and understands that identity is not just a technical function but a critical security control.

Key Responsibilities:
  • Design and implement a formal RBAC framework across associated environments, including EntraID, AWS, NGINX, AppGate, And Keycloak
  • Establish and enforce least privilege policies in alignment with Zero Trust Architecture principles and federal directives
  • Validate that implemented access controls align with organizational Zero Trust and security requirements.
  • Develop and manage identity lifecycle processes for joiners, movers, and leavers across the program, ensuring timely provisioning and deprovisioning
  • Implement and manage a Privileged Access Management (PAM) program including identification, governance, and monitoring of privileged accounts
  • Lead access review and audit processes to support PAR/RAR reporting requirements and ongoing compliance obligations
  • Develop and maintain role-to-privilege mappings and job function definitions across the program to eliminate access ambiguity
  • Collaborate with program leadership, system owners, to ensure IAM policies align with organizational changes and personnel transitions
  • Support the implementation and ongoing operation of AppGate SDP Zero Trust Network Access solutions.
  • Gather user, application, device and connectivity requirements and translate them into documented access-control requirements.
  • Assist senior engineers with designing identity-based, least-privilege access policies.
  • Support onboarding of users, endpoints, applications and protected network resources into AppGate SDP.
  • Produce IAM metrics, reports, and dashboards to communicate access risk and governance posture to program leadership
  • Serve as the IAM subject matter expert for program compliance activities, audits, and government stakeholder engagements
  • Other duties, as assigned.

Note: Salary is commensurate with skillset, qualifications, experience, and educational background.

Salary Range: $130,000-180,000

General Description of Benefits

  • U.S. Citizen.
  • Active DoD Secret security clearance.
  • High School Diploma and 6+ years of experience in Identity and Access Management in a complex enterprise or federal environment.
  • Required Active Certifications:
    • DoD 8140 IAT Level II Security+ (or higher).
    • SAA-C03 AWS Certified Solutions Architect - Associate.
    • AZ-104 Azure Administrator - Associate OR Exam AZ-800: Administering Windows Server Hybrid Core Infrastructure.
  • Ability to work in a hybrid capacity in Fairfax, VA (up to 3 days in office).
  • Working knowledge of AppGate SDP architecture, components, policies, entitlements and conditions.
  • Understanding of Zero Trust Network Access, least-privilege access and identity-based security principles.
  • Knowledge of TCP/IP, DNS, routing, firewalls, ports and common network troubleshooting methods.
  • Familiarity with identity and access-management technologies, including SAML, OpenID Connect, LDAP, Active Directory, Keycloak, and multifactor authentication.
  • Ability to:
    • Gather technical requirements and translate business access needs into documented security requirements.
    • Diagnose basic authentication, client-connectivity, entitlement and application-access issues.
  • Experience supporting:
    • User, endpoint, application and network-resource onboarding.
    • Or implementing PAM solutions and privileged account governance
  • Demonstrated expertise with:
    • Microsoft EntraID (Azure AD) including conditional access, role assignments, and identity governance
    • AWS IAM, including policies, roles, permission boundaries, and access analysis tools
  • Strong knowledge of RBAC design, least privilege principles, and Zero Trust Architecture frameworks
  • Familiarity with:
    • CDM program requirements, PAR/RAR processes, and federal ICAM policies
    • Keycloak Admin Console, command-line tools and REST Admin API.
  • Experience conducting access reviews, audits, and compliance reporting
  • Strong documentation and communication skills with the ability to present complex IAM concepts to both technical and non-technical stakeholders
  • Understanding of Keycloak clustering, high availability, caching, database connectivity, backup and disaster recovery.
  • Ability to document identity architecture, authentication flows, integrations and operating procedures.
  • Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
  • Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).

About ECS

ECS is a leading provider of digital solutions and services to the federal government. The company was founded in 2001 by Roy Kapani and has since grown to become a trusted partner to a wide range of government agencies. ECS offers a broad range of services, including cloud computing, cybersecurity, and artificial intelligence. The company has been recognized for its innovative solutions and has won numerous awards, including the AWS Public Sector Partner of the Year award.
Learn more about ECS
Size
2,000 employees
Industry

Similar Jobs

More Jobs at ECS

More Information Technology Jobs

Find similar Identity and Access Management Engineer jobs: