Lead Specialist, Federal ICAM (Identity, Credential, and Access Management) Engineer

KPMG

$120K — $145K *
Education, Government & Non-Profit
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in cybersecurity focusing on Identity and Access Management; federal government consulting experience preferred.
  • Bachelor's degree from an accredited institution.
  • Experience with federal ICAM frameworks and guidelines (FICAM, HSPD-12, NIST SP 800-53).
  • Hands-on experience with ICAM platforms like SailPoint, Okta, and CyberArk.
  • Preferred certifications include CISSP, GSEC, GCED; specific platform certifications are strongly favored.
  • Experience with major cloud identity services (AWS, Azure, GCP).
  • Strong communication skills to convey technical concepts to varied audiences.
  • U.S. Government Secret clearance required.

Responsibilities

  • Lead the development and management of ICAM solutions using platforms like Okta, SailPoint, and CyberArk.
  • Implement and enforce access control policies in line with Zero Trust principles.
  • Manage the identity lifecycle, including provisioning and access reviews.
  • Integrate ICAM solutions across various applications and infrastructures.
  • Lead initiatives on Privileged Access Management to secure high-risk accounts.
  • Translate mission requirements into ICAM technical strategies.
  • Resolve complex identity and access-related issues for clients.
  • Mentor junior engineers and provide technical guidance to leadership.

Benefits

  • Comprehensive medical, dental, and vision coverage.
  • Disability and life insurance options.
  • 401(k) retirement plan with company contributions.
  • Personal well-being benefits focused on mental health.
  • Personal Time Off policy with standard work hours and additional holiday breaks.
Full Job Description
Responsibilities:
  • Lead the architecture, deployment, and management of Identity, Credentialing, and Access Management (ICAM) solutions using platforms such as Okta, SailPoint, and CyberArk
  • Develop and enforce access control policies, standards, and procedures in alignment with Zero Trust principles and federal mandates (e.g. NIST, FICAM, HSPD-12)
  • Engineer and manage the full lifecycle of digital identifies, including provisioning, de-provisioning, and periodic access reviews
  • Integrate ICAM solutions with a wide variety of applications and infrastructure, including cloud (IaaS, PaaS, SaaS) and on-premises environments
  • Serve as technical lead for Privileged Access Management (PAM) initiatives, securing and monitoring access for high-risk accounts using tools like CyberArk
  • Translate federal client unique mission requirements into technical ICAM strategies and roadmaps
  • Troubleshoot and resolve complex issues related to identity federation, single sign-on (SSO), multi-factor authentication (MFA), and directory services
  • Mentor and review work of junior engineers and act as a key technical advisor to senior leadership

Qualifications:
  • A minimum of five years of experience in cybersecurity with a focus on Identify and Access Management; U.S. Federal government consulting experience preferred
  • Bachelor's degree from an accredited college/university
  • Demonstrated experience with federal ICAM programs and frameworks, such as Federal Identity, Credential, and Access Management (FICAM), HSPD-12, PIV/CAC, and NIST SP 800-53 (Digital Identity Guidelines)
  • Hands-on implementation experience with one or more of the following platforms: Identify Governance and Administration (IGA), Sailtpoint (IdentityIQ or IdentityNOW), Access Management, SSO (Okta), PAM (CyberArk)
  • Preferred certifications: CISSP, GSEC, GCED
  • Okta, SailPoint IdentityIQ Engineer, and/or CyberArk Delivery Engineer certifications strongly preferred
  • Experience with identity services in major cloud providers (AWS, Azure, GCP)
  • Excellent written and verbal communication skills with the ability to articulate complex technical concepts to both technical and non-technical stakeholders
  • Ability to travel as required to support firm engagements
  • Applicant must possess a U.S. Government Secret clearance


KPMG LLP and its affiliates and subsidiaries ("KPMG") complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work .

Follow this link to obtain salary ranges by city outside of CA:

https://kpmg.com/us/en/how-we-work/pay-transparency.html/?id=M105ADV_3_26

Similar Jobs

More Jobs at KPMG

More Education, Government & Non-Profit Jobs

Find similar Lead Specialist, Federal ICAM (Identity, Credential, and Access Management) Engineer jobs: