ICAM Identity Provider (IdP) Engineer β Enterprise Authentication Services
Type of Requisition:
Regular
Clearance Level Must Currently Possess:
Secret
Clearance Level Must Be Able to Obtain:
Secret Public Trust/Other Required:
None
Job Family:
IT Infrastructure and Operations Job Qualifications:
Skills:
Active Directory Domain Services (AD DS), Active Directory Federation Services (AD FS), Authentication Systems, Microsoft Azure Certifications:
None Experience:
8 + years of related experience US Citizenship Required:
Yes
Job Description:
ICAM Identity Provider (IdP) Engineer β Enterprise Authentication Services
GDIT has an opportunity for an ICAM Engineer supporting a large line of business that delivers enterprise-scale Identity, Credential, and Access Management (ICAM) capabilities. This role supports the DoD ICAM mission by designing, developing, integrating, and maintaining enterprise Identity Provider (IdP) services that provide secure authentication and federation for more than 4 million enterprise identities across the Department of Defense.
This is a fully remote position.
MEANINGFUL WORK AND PERSONAL IMPACT
The ideal candidate is a senior hands-on identity engineer with expertise in Microsoft Active Directory Federation Services (ADFS), enterprise authentication, federation technologies, and modern identity protocols. This role focuses on delivering highly available authentication services, federation trust management, single sign-on (SSO), multi-factor authentication (MFA), and secure application integration across a large-scale enterprise environment..
- Design, develop, configure, and maintain enterprise Identity Provider (IdP) services supporting over 4 million enterprise identities.
- Engineer, administer, and sustain Microsoft Active Directory Federation Services (ADFS) infrastructure supporting enterprise authentication and federation.
- Configure and maintain federation trust relationships with internal and external Identity Providers (IdPs), Service Providers (SPs), and mission partners.
- Design, implement, and troubleshoot authentication solutions utilizing SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication.
- Support onboarding and integration of enterprise applications into the authentication and federation ecosystem.
- Develop authentication policies, claims rules, attribute mappings, token issuance policies, and authorization workflows.
- Support enterprise Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, and phishing-resistant authentication capabilities.
- Collaborate with cybersecurity, Active Directory, cloud, infrastructure, and application teams to implement secure authentication services.
- Support implementation of Zero Trust Architecture through modern authentication, federation, and identity assurance capabilities.
- Monitor, troubleshoot, and resolve complex authentication, federation, trust, certificate, token, and identity assertion issues.
- Engineer highly available and resilient authentication services supporting mission-critical enterprise applications.
- Develop technical documentation including architecture diagrams, integration guides, SOPs, TTPs, operational procedures, and onboarding documentation.
- Participate in Agile development activities and continuous service improvement initiatives.
- Actively manage technical risks and contribute to enterprise identity modernization efforts.
Basic Qualifications:
- Active Secret Clearance at minimum. Interim Secret Clearances are not allowed.
- Bachelorβs Degree in a related technical discipline, or the equivalent combination of education, technical certifications or training, or work experience.
- DoD 8570/8140 IAT Level II certification (Security+ CE or higher)
Required Skills/Knowledge:
- Minimum of 8 years of experience supporting Identity and Access Management (IAM), Authentication, Federation, or ICAM solutions within government or regulated environments
- Strong experience designing, implementi