Today
Top Secret/SCI
$85,800 - $180,200
None
IT - Hardware
San Antonio, TX (On-Site/Office)
Senior Cloud DevOps Engineer - Identity Management
Job Category: Information Technology
Time Type: Full time
Minimum Clearance Required to Start: TS/SCI
Employee Type: Regular
Percentage of Travel Required: None
Type of Travel: None
* * *
The Opportunity:
Join a forward-thinking cloud engineering team responsible for designing, securing, and maintaining enterprise identity and access management systems.
Lead the integration and automation of identity services across hybrid cloud and on-premises infrastructures.
• Drive the modernization of authentication, authorization, and secrets management capabilities using Keycloak, HashiCorp Vault, and related technologies.
• Collaborate with cybersecurity, DevSecOps, and infrastructure teams to enhance security posture and streamline identity workflows.
• Play a critical role in ensuring seamless, secure, and scalable access to secure multi-cloud and on-prem systems across the organization.
Responsibilities:
• Architect, deploy, and maintain Keycloak identity management systems in hybrid and multi-cloud environments.
• Implement and manage secrets management solutions using HashiCorp Vault, including dynamic secrets, PKI, and access policies.
• Integrate cloud-native and on-prem identity stores (e.g., AWS IAM, Azure AD, LDAP, Active Directory) into unified ICAM architectures.
• Develop and automate CI/CD pipelines for deploying and maintaining ICAM-related infrastructure as code (IaC).
• Define and enforce security policies for authentication, authorization, and token management across distributed systems.
• Collaborate with security teams to implement Zero Trust and least-privilege access principles.
• Configure and maintain high availability, backup, and recovery strategies for Keycloak and Vault services.
• Monitor, troubleshoot, and optimize performance and reliability of identity systems and associated integrations.
• Maintain documentation of configurations, operational procedures, and identity management standards.
• Support compliance initiatives by ensuring alignment with NIST, FedRAMP, and organizational security frameworks.
Qualifications:
• Bachelor's degree in Computer Science, Information Systems, or related technical field.
• 5+ years of experience in DevOps, Cloud Engineering, or Infrastructure Automation roles.
• Hands-on experience managing Keycloak, HashiCorp Vault, or comparable IAM and secrets management tools.
• Strong understanding of identity federation (SAML, OIDC, OAuth2) and directory integration concepts.
• Proficiency with infrastructure as code (Terraform, Ansible, or CloudFormation).
• Experience with at least one major cloud provider (AWS, Azure, or GCP) and hybrid integration patterns.
• Strong scripting skills in Bash, Python, or Go for automation and operational tasks.
• Solid understanding of networking, PKI, TLS, and secure service-to-service communication.
• Demonstrated ability to troubleshoot complex system and identity-related issues in production environments.
• Must be located in San Antonio, TX or willing to relocate.
Desired:
• Experience implementing Zero Trust architectures or enterprise ICAM modernization initiatives.
• Knowledge of Kubernetes, containerized deployments, and service mesh identity integration.
• Familiarity with regulatory compliance frameworks (FedRAMP, DoD RMF, ISO 27001).
• Experience with GitOps workflows and CI/CD tools such as GitLab CI, Jenkins, or ArgoCD.
• Relevant certifications such as HashiCorp Certified Vault Associate, Certified Kubernetes Administrator (CKA), or AWS Certified DevOps Engineer.
-
________________________________________________________________________________________
What You Can Expect:
A culture of integrity.
At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose - to ensure the safety of our nation.
An environment of trust.
CACI values the unique contributions that every employee brings to our company and our customers - every day. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.
A focus on continuous growth.
Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy.
Your potential is limitless. So is ours.
Learn more about CACI here.
________________________________________________________________________________________
Pay Range: There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits. Learn more here .
The proposed salary range for this position is:
$85,800 - $180,200
CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.
Job Category: Information Technology
Time Type: Full time
Minimum Clearance Required to Start: TS/SCI
Employee Type: Regular
Percentage of Travel Required: None
Type of Travel: None
* * *
The Opportunity:
Join a forward-thinking cloud engineering team responsible for designing, securing, and maintaining enterprise identity and access management systems.
Lead the integration and automation of identity services across hybrid cloud and on-premises infrastructures.
• Drive the modernization of authentication, authorization, and secrets management capabilities using Keycloak, HashiCorp Vault, and related technologies.
• Collaborate with cybersecurity, DevSecOps, and infrastructure teams to enhance security posture and streamline identity workflows.
• Play a critical role in ensuring seamless, secure, and scalable access to secure multi-cloud and on-prem systems across the organization.
Responsibilities:
• Architect, deploy, and maintain Keycloak identity management systems in hybrid and multi-cloud environments.
• Implement and manage secrets management solutions using HashiCorp Vault, including dynamic secrets, PKI, and access policies.
• Integrate cloud-native and on-prem identity stores (e.g., AWS IAM, Azure AD, LDAP, Active Directory) into unified ICAM architectures.
• Develop and automate CI/CD pipelines for deploying and maintaining ICAM-related infrastructure as code (IaC).
• Define and enforce security policies for authentication, authorization, and token management across distributed systems.
• Collaborate with security teams to implement Zero Trust and least-privilege access principles.
• Configure and maintain high availability, backup, and recovery strategies for Keycloak and Vault services.
• Monitor, troubleshoot, and optimize performance and reliability of identity systems and associated integrations.
• Maintain documentation of configurations, operational procedures, and identity management standards.
• Support compliance initiatives by ensuring alignment with NIST, FedRAMP, and organizational security frameworks.
Qualifications:
• Bachelor's degree in Computer Science, Information Systems, or related technical field.
• 5+ years of experience in DevOps, Cloud Engineering, or Infrastructure Automation roles.
• Hands-on experience managing Keycloak, HashiCorp Vault, or comparable IAM and secrets management tools.
• Strong understanding of identity federation (SAML, OIDC, OAuth2) and directory integration concepts.
• Proficiency with infrastructure as code (Terraform, Ansible, or CloudFormation).
• Experience with at least one major cloud provider (AWS, Azure, or GCP) and hybrid integration patterns.
• Strong scripting skills in Bash, Python, or Go for automation and operational tasks.
• Solid understanding of networking, PKI, TLS, and secure service-to-service communication.
• Demonstrated ability to troubleshoot complex system and identity-related issues in production environments.
• Must be located in San Antonio, TX or willing to relocate.
Desired:
• Experience implementing Zero Trust architectures or enterprise ICAM modernization initiatives.
• Knowledge of Kubernetes, containerized deployments, and service mesh identity integration.
• Familiarity with regulatory compliance frameworks (FedRAMP, DoD RMF, ISO 27001).
• Experience with GitOps workflows and CI/CD tools such as GitLab CI, Jenkins, or ArgoCD.
• Relevant certifications such as HashiCorp Certified Vault Associate, Certified Kubernetes Administrator (CKA), or AWS Certified DevOps Engineer.
-
________________________________________________________________________________________
What You Can Expect:
A culture of integrity.
At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose - to ensure the safety of our nation.
An environment of trust.
CACI values the unique contributions that every employee brings to our company and our customers - every day. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.
A focus on continuous growth.
Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy.
Your potential is limitless. So is ours.
Learn more about CACI here.
________________________________________________________________________________________
Pay Range: There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits. Learn more here .
The proposed salary range for this position is:
$85,800 - $180,200
CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.
group id: caci
CACI Careers – Your potential is limitless. So is ours.