ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services

GDIT

Completely RemoteFull TimeInformation Technology
Posted Today

Job description

Responsibilities

  • Design, develop, configure, and maintain enterprise Identity Provider (IdP) services supporting over 4 million enterprise identities
  • Engineer, administer, and sustain Microsoft Active Directory Federation Services (ADFS) infrastructure
  • Configure and maintain federation trust relationships with internal and external Identity Providers (IdPs), Service Providers (SPs), and mission partners
  • Implement and troubleshoot authentication solutions utilizing SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and certificate-based authentication
  • Support onboarding and integration of enterprise applications into the authentication and federation ecosystem
  • Develop authentication policies, claims rules, attribute mappings, and authorization workflows
  • Support enterprise Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Conditional Access
  • Collaborate with cybersecurity, Active Directory, cloud, and infrastructure teams to implement secure authentication services
  • Support implementation of Zero Trust Architecture
  • Monitor, troubleshoot, and resolve complex authentication, federation, trust, and identity assertion issues
  • Develop technical documentation including architecture diagrams, integration guides, and SOPs
  • Participate in Agile development activities

Requirements

  • Active Secret Clearance at minimum (Interim Secret Clearances are not allowed)
  • Bachelor's Degree in a related technical discipline, or equivalent combination of education, technical certifications, or work experience
  • DoD 8570/8140 IAT Level II certification (Security+ CE or higher)
  • Minimum of 8 years of experience supporting Identity and Access Management (IAM), Authentication, Federation, or ICAM solutions
  • Strong experience designing, implementing, and supporting Microsoft Active Directory Federation Services (ADFS)
  • Extensive experience implementing enterprise Identity Provider (IdP) services supporting large user populations
  • Experience implementing and troubleshooting SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation, and JWT technologies
  • Experience supporting PKI, certificate-based authentication, and MFA solutions
  • Experience with Active Directory, LDAP directories, and enterprise identity repositories
  • Experience supporting Linux and/or Windows Server environments
  • Strong written and verbal communication skills

Preferred Qualifications

  • Experience designing and supporting highly available ADFS farms with Web Application Proxy (WAP)
  • Experience with Microsoft Entra ID (Azure AD), PingFederate, PingAccess, PingDirectory, Okta, or Keycloak
  • Experience supporting DoD Enterprise ICAM or mission partner federation initiatives
  • Experience implementing federation solutions for coalition or cross-organizational environments
  • Experience supporting NIST 800-63 Identity Assurance Levels (IAL)
  • Experience implementing phishing-resistant authentication and passwordless solutions
  • Familiarity with PowerShe

Skills & tools

ADFSSAMLOAuth 2.0IAMAzure

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 01Active Secret Clearance
  2. 02Bachelor's Degree in technical discipline
  3. 03DoD 8570/8140 IAT Level II certification
  4. 048+ years IAM experience
  5. 05ADFS expertise
  6. 06SAML 2.0/OAuth 2.0/OIDC experience
NeverApplyAd

Wake up to a shortlist, not a search results page.

NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.

Get your daily matches