GovCIO

SME Systems Engineer (ICAM Architect)

GovCIO$135K — $172K *
Education, Government & Non-Profit
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • High School diploma with 10+ years of relevant experience.
  • Certifications: DoD 8570 IAT Level II or higher (e.g., Security+ CE, CySA+, vendor-specific identity certifications).
  • Deep understanding of federated identity concepts (SAML, OAuth, OIDC) and Active Directory/LDAP.
  • Hands-on experience managing Smart Card/CAC authentication and PKI certificate validation.
  • Experience implementing federal Zero Trust identity guidelines (NIST SP 800-207) in enterprise networks.
  • Active Secret clearance required.

Responsibilities

  • Lead modernization of legacy access controls to secure ICAM solutions.
  • Manage enterprise directories and authentication protocols including SSO.
  • Architect identity lifecycles and user provisioning workflows.
  • Design and enforce Zero Trust identity principles across network hubs.
  • Configure and manage enterprise-grade PKI systems and authenticators.
  • Implement logical and physical access controls, including MFA and PAM.
  • Build federated identity services for secure interoperability with partners.
  • Conduct technical root cause analysis and privilege audits.
  • Develop technical interfaces and compliance documentation.

Benefits

  • Hybrid work model with flexibility in location.
  • Opportunity to work on critical projects within U.S. Coast Guard.
  • Potential for career advancement in a specialized technical role.
  • Access to cutting-edge identity management technologies.
  • Contribute to national security through technology.
Full Job Description
Overview

GovCIO is currently hiring a highly experienced SME Systems Engineer specializing in Cross-Cutting Support Across All Product Lines with a primary focus on ICAM Enterprise Architecture. This technical role supports critical Identity, Credential, and Access Management (ICAM) modernization activities for the U.S. Coast Guard (USCG). This position focuses on designing, engineering, and executing secure, identity-centric access control frameworks across legacy and modern enterprise architectures. This position will be located in Alexandria, VA, and will be a hybrid position.

ResponsibilitiesThe SME Systems Engineer / ICAM Engineer will serve as a primary technical authority for the enterprise identity management and access control framework. Core responsibilities include:
  • Lead Modernize legacy access controls into robust, secure ICAM solutions.
  • Manage enterprise directories, federation, authentication, authorization, and SSO protocols.
  • Architect identity lifecycles, user provisioning workflows, and privilege management controls.
  • Design and deploy strict Zero Trust identity principles (NIST SP 800-207) across network hubs.
  • Configure and manage enterprise-grade PKI systems, credentials, and authenticators.
  • Implement logical and physical access control systems, including MFA, SSO, and PAM.
  • Build federated identity services to enable secure interoperability with mission partners.
  • Conduct technical root cause analysis, privilege audits, and system performance tuning.
  • Develop custom technical interfaces, architectures, data flows, and compliance documentation.
  • Provide advanced engineering and architecture ownership across the following specialization:
    • ICAM Enterprise Architecture (Primary Product Area: Cross-cutting support for all product lines): Serve as the chief technical architect for the consolidated ICAM enterprise. Own the overarching hybrid identity strategy, ensuring the on-premises Active Directory and the Entra ID tenant are designed to function as a seamless, secure, and integrated system. Own the architectural design, placement, and lifecycle strategy for all Domain Controllers (DCs). Ensure that solutions designed by the other SMEs are interoperable and aligned with overall enterprise architecture standards. Lead the technical design for large-scale, cross-product initiatives and act as the primary technical liaison between the ICAM team and other enterprise architecture groups.
Qualifications

High School with 10+ years (or commensurate experience)

 

Required Skills & Experience
  • Certifications: DoD 8570 IAT Level II or higher (e.g., Security+ CE, CySA+, or vendor-specific identity certifications).
  • Deep technical understanding of federated identity concepts, including SAML, OAuth, OIDC, and Active Directory / LDAP architecture.
  • Hands-on engineering experience managing Smart Card / Common Access Card (CAC) authentication and PKI certificate validation.
  • Proven experience designing and applying federal Zero Trust identity guidelines (NIST SP 800-207) within enterprise networks.

Clearance Level: Must have an active Secret clearance

 

Preferred Skills & Experience
  • Prior experience supporting U.S. Coast Guard (USCG) or Department of Homeland Security (DHS) identity management programs.
  • Familiarity with integrating data governance frameworks with ICAM solutions to enforce data-level access controls.
  • Direct experience with enterprise identity tools such as SailPoint, Okta, Microsoft Entra ID, Ping Identity, DigiCert, or Power BI.
  • Advanced knowledge of RESTful API authorization protocols, secure gateways, and data schema security standards.
Posted Salary RangeUSD $135,000.00 - USD $172,000.00 /Yr.

About GovCIO

GovCIO is a technology and consulting firm that provides IT solutions to government agencies. The company specializes in cloud computing, cybersecurity, and digital transformation. GovCIO's mission is to help government agencies improve their IT infrastructure and enhance their services to the public. The company was founded in 2015 and is headquartered in Washington, DC.
Learn more about GovCIO
Size
50 employees
Industry
Founded
2015

Similar Jobs

More Jobs at GovCIO

More Education, Government & Non-Profit Jobs

Find similar SME Systems Engineer (ICAM Architect) jobs: