Responsibilities:- Lead the architecture, design, and deployment of comprehensive ICAM solutions using platforms such as Okta, SailPoint, and CyberArk
- Develop / enforce access control policies, standards, and procedures in alignment with federal mandates (e.g. - NIST, FICAM, HSPD-12)
- Engineer / manage the full lifecycle of digital identities, including provisioning, de-provisioning, and periodic access reviews
- Integrate ICAM solutions with a wide variety of applications and infrastructure, including cloud (IaaS, PaaS, SaaS) and on-premises environments
- Serve as the technical lead for Privileged Access Management (PAM) initiatives, securing and monitoring access for high-risk accounts utilizing tools like CyberArk
- Collaborate with federal clients to understand their unique mission requirements, translate them into technical ICAM strategies, and roadmaps
- Troubleshoot / resolve complex issues related to identity federation, single sign-on (SSO), multi-factor authentication (MFA), and directory services
- Provide mentorship to junior engineers and act as a key technical advisor to senior leadership
Qualifications:- A minimum of eight years of technical Identity (ICAM) architecture experience
- Bachelor's degree from an accredited college/university
- Preferred Certifications: CISSP (Certified Information Systems Security Professional), GIAC certifications (e.g. - GSEC, GCED), vendor specific certifications (e.g. - Okta Certified Professional, SailPoint Certified IdentityIQ Engineer, CyberArk Certified Delivery Engineer)
- Experience with federal ICAM programs / frameworks, such as Federal Identity, Credential, and Access Management (FICAM), HSPD-12, PIV/CAC, and NIST SP 800-63 (Digital Identity Guidelines)
- Experience managing staff and project engagements
- Experience with identity services in major cloud providers (e.g. - AWS, Azure, GCP)
- Implementation experience with one or more of the following platforms: Identity Governance & Adminstration (IGA), SailPoint (IdentityIQ or IdentityNow), Access Management/SSO: Okta, Privileged Access Management (PAM): CyberArk
- Ability to travel as required to support firm engagements
- Applicant must possess a U.S. Government Secret clearance
KPMG LLP and its affiliates and subsidiaries ("KPMG") complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work .
Follow this link to obtain salary ranges by city outside of CA:
https://kpmg.com/us/en/how-we-work/pay-transparency.html/?id=M105ADV_2_26