
ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services
GDIT
Completely RemoteFull TimeInformation Technology
Posted Today
Job description
Responsibilities
- Design, develop, configure, and maintain enterprise Identity Provider (IdP) services supporting over 4 million enterprise identities
- Engineer, administer, and sustain Microsoft Active Directory Federation Services (ADFS) infrastructure
- Configure and maintain federation trust relationships with internal and external Identity Providers (IdPs), Service Providers (SPs), and mission partners
- Implement and troubleshoot authentication solutions utilizing SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication
- Support onboarding and integration of enterprise applications into the authentication and federation ecosystem
- Develop authentication policies, claims rules, attribute mappings, and authorization workflows
- Support enterprise Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Conditional Access
- Collaborate with cybersecurity, Active Directory, cloud, and infrastructure teams to implement secure authentication services
- Support implementation of Zero Trust Architecture
- Monitor, troubleshoot, and resolve complex authentication, federation, trust, and identity assertion issues
- Develop technical documentation including architecture diagrams, integration guides, and SOPs
- Participate in Agile development activities
Requirements
- Active Secret Clearance at minimum (Interim Secret Clearances are not allowed)
- Bachelor's Degree in a related technical discipline, or equivalent combination of education, technical certifications, or work experience
- DoD 8570/8140 IAT Level II certification (Security+ CE or higher)
- Minimum of 8 years of experience supporting Identity and Access Management (IAM), Authentication, Federation, or ICAM solutions
- Strong experience designing, implementing, and supporting Microsoft Active Directory Federation Services (ADFS)
- Extensive experience implementing enterprise Identity Provider (IdP) services supporting large user populations
- Experience implementing and troubleshooting SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and JWT technologies
- Experience supporting PKI, certificate-based authentication, and MFA solutions
- Experience with Active Directory, LDAP directories, and enterprise identity repositories
- Experience supporting Linux and/or Windows Server environments
- Strong written and verbal communication skills
Preferred Qualifications
- Experience designing and supporting highly available ADFS farms with Web Application Proxy (WAP)
- Experience with Microsoft Entra ID (Azure AD), PingFederate, PingAccess, PingDirectory, Okta, or Keycloak
- Experience supporting DoD Enterprise ICAM or mission partner federation initiatives
- Experience implementing federation solutions for coalition or cross-organizational environments
- Experience supporting NIST 800-63 Identity Assurance Levels (IAL)
- Experience implementing phishing-resistant authentication and passwordless solutions
- Familiarity with PowerShe
Skills & tools
ADFSSAMLOAuth 2.0IAMAzure
What the team is looking for
Use this list as a quick fit check before you apply.
- 01Active Secret Clearance
- 02Bachelor's Degree in technical discipline
- 03DoD 8570/8140 IAT Level II certification
- 048+ years IAM experience
- 05ADFS expertise
- 06SAML 2.0/OAuth 2.0/OIDC experience
AdWake up to a shortlist, not a search results page.
NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.
Get your daily matches
GDIT
Job details
- Work model
- Completely Remote
- Commitment
- Full Time
- Category
- Information Technology
- Posted
- Today
AdWake up to a shortlist, not a search results page.
NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.
Get your daily matches