user avatar

Cybersecurity Engineer - ISSE/ISSO

Serco Inc.

Posted today

Job Requirements

Amarillo, TX
Secret Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries

Job Description



We are seeking a Senior ISSE/ISSO to serve as both the technical security engineer and the officer of record for identity, credential, and access management (ICAM) security across our enterprise and program systems. This role owns the security architecture, implementation, and continuous authorization of identity governance and access control capabilities, with broad expertise across the ICAM discipline - including credentialing, federation, PKI/PIV-based authentication, privileged access management, and identity governance - and deep hands-on expertise in Okta (identity provider, SSO, MFA, lifecycle/adaptive policies) and SailPoint (IdentityNow/IdentityIQ - identity governance, access certification, provisioning, and role-based access control). Okta and SailPoint are this program's primary toolset, but the candidate must understand ICAM as a discipline, not just these two products, and be able to evaluate, integrate, and troubleshoot the broader ICAM ecosystem (directories, PKI, federation protocols, PAM, and governance) that these tools operate within. The ideal candidate blends the risk-management and compliance responsibilities of an ISSO with the hands-on engineering depth of an ISSE, ensuring identity systems are securely designed, properly authorized, and continuously monitored in accordance with RMF/NIST requirements.

This position is contingent upon the ability to maintain/transfer a DoD Secret Security clearance.

In this role, you will:
  • Design, implement, and maintain secure identity and access management architecture leveraging Okta and SailPoint across enterprise and mission systems.
  • Configure and harden Okta SSO, adaptive MFA, lifecycle management, and API access policies in accordance with security baselines.
  • Engineer SailPoint identity governance workflows, including access certifications, role mining, segregation-of-duties (SoD) policies, and automated provisioning/deprovisioning.
  • Integrate Okta/SailPoint with directory services (Active Directory/Azure AD), PKI/CAC authentication, and downstream applications via SCIM, SAML, and OIDC.
  • Conduct security control implementation and testing for identity systems in support of Risk Management Framework (RMF) Assessment & Authorization (A&A) packages.
  • Support vulnerability remediation, patch management, and secure configuration baselines (STIGs/CIS benchmarks) for IAM infrastructure.
  • Partner with application owners and engineering teams to embed zero trust and least-privilege principles into identity workflows.
  • Serve as the ISSO of record for identity management systems, maintaining continuous authorization to operate (ATO) status.
  • Conduct and document risk assessments, POA&Ms, and continuous monitoring activities for assigned systems.
  • Coordinate with the ISSM, AO, and assessment teams during A&A activities, audits, and inspections (NIST SP 800-53, RMF, FedRAMP as applicable).
  • Monitor and report on security events, incidents, and access anomalies related to identity and access systems; support incident response as needed.
  • Maintain audit-ready documentation for access reviews, certification campaigns, and compliance evidence collection.
  • Ensure identity-related controls align with applicable frameworks (NIST 800-53, NIST 800-63, ICD 503, DoD RMF, or agency-specific requirements).
  • Brief leadership and stakeholders on identity security posture, risk, and remediation status.


To be successful in this role, you will have:
  • Active DoD Secret clearance required at time of hire.
  • A Bachelor's degree plus 8 years of information systems security experience, with demonstrated ISSE and/or ISSO responsibilities.
    • OR an Associate's degree and 10 years of information systems security experience, with demonstrated ISSE and/or ISSO responsibilities.
    • OR a Master's degree and 6 years of information systems security experience, with demonstrated ISSE and/or ISSO responsibilities.
  • DoD 8570 IAT Level II or III certification (Security+, CySA+, CISSP, or equivalent)
  • Demonstrated subject-matter expertise across Identity, Credential, and Access Management (ICAM) solutions broadly - not limited to any single vendor product - spanning identity governance, credentialing/PKI, federation, directory services, and access management architecture.
  • Hands-on production experience configuring and administering Okta (SSO, MFA, workflows, lifecycle management).
  • Hands-on production experience with SailPoint (IdentityNow or IdentityIQ) for identity governance, certifications, and provisioning.
  • Working knowledge of NIST SP 800-53, RMF, and Assessment & Authorization (A&A) processes.
  • Experience with SAML, OIDC, SCIM, and federated identity integration patterns.
  • Experience with PKI/PIV/CAC-based credentialing and certificate-based authentication as part of an enterprise ICAM strategy.
  • Understanding of adjacent ICAM capabilities such as privileged access management (PAM), directory services (Active Directory/Azure AD/LDAP), and role-based/attribute-based access control (RBAC/ABAC), and how Okta/SailPoint integrate with them.
  • Ability to assess, integrate, and troubleshoot ICAM solutions and architectures beyond the current Okta/SailPoint toolset, including evaluating new or legacy identity platforms as mission needs evolve.
  • Familiarity with STIGs, CIS benchmarks, and secure configuration management.
  • Strong written communication skills for security documentation (SSPs, POA&Ms, risk assessments).
  • Must be able to work Central Time Zone work hours.
  • The ability to travel up to 25% (CONUS).
    • Must be okay traveling to San Antonio, TX on a customer needed basis.


Additional desired experience and skills:
  • CISSP, CISM, or SailPoint/Okta vendor certifications (Okta Certified Administrator, SailPoint IdentityNow Engineer).
  • Broader ICAM platform experience beyond Okta/SailPoint (Ping Identity, ForgeRock, Microsoft Entra ID, CyberArk, or similar IAM/PAM/governance products), demonstrating vendor-agnostic ICAM fluency.
  • Experience integrating IAM platforms with PKI/CAC/PIV authentication.
  • Familiarity with zero trust architecture (ZTA) principles and DoD Zero Trust reference architecture.
  • Scripting/automation experience (PowerShell, Python) for identity workflow automation.



Serco Inc. (Serco) is the Americas division of Serco Group, plc. In North America, Serco's 9,000+ employees strive to make an impact every day across 100+ sites in the areas of Defense, Citizen Services, and Transportation. We help our clients deliver vital services more efficiently while increasing the satisfaction of their end customers. Serco serves every branch of the U.S. military, numerous U.S. Federal civilian agencies, the Intelligence Community, the Canadian government, state, provincial and local governments, and commercial clients. While your place may look a little different depending on your role, we know you will find yours here. Wherever you work and whatever you do, we invite you to discover your place in our world. Serco is a place you can count on and where you can make an impact because every contribution matters.

To review Serco benefits please visit: https://careers.serco-na.com/us/en/what-we-offer . If you require an accommodation with the application process please email: careers@serco-na.com or call the HR Service Desk at 800-628-6458, option 1. Please note, due to EEOC/OFCCP compliance, Serco is unable to accept resumes by email.

Candidates may be asked to present proof of identify during the selection process. If requested, this will require presentation of a government-issued I.D. (with photo) with name and address that match the information entered on the application. Serco will not take possession of or retain/store the information provided as proof of identity. For more information on how Serco uses your information, please see our Applicant Privacy Policy and Notice.

Serco does not accept unsolicited resumes through or from search firms or staffing agencies without being a contracted approved vendor. All unsolicited resumes will be considered the property of Serco and will not be obligated to pay a placement or contract fee. If you are interested in becoming an approved vendor at Serco, please email Agencies@serco-na.com .

Serco is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, and other legally protected characteristics.



Our Total Rewards package includes competitive pay, performance-based incentives, and benefits that promote well-being and work-life balance-so you can thrive both professionally and personally. Eligible employees also gain access to a wide range of benefits from comprehensive health coverage and health savings accounts to retirement plans, life and disability insurance, and time-off programs that support work-life balance. Program availability may vary based on factors such as contract type, location, hire date, and applicable collective bargaining agreements.

Salary range: The range for this position can be found at the top of this posting. This range is provided as a general guideline and represents a good faith estimate across all experience levels. Actual base salary will be determined by a variety of factors, including but not limited to, the scope of the role, relevant experience, job-related knowledge, education and training, key skills, and geographic market considerations. For roles available in multiple states, the range may vary to reflect differences in local labor markets. In addition to base salary, eligible positions may include other forms of compensation such as annual bonuses or long-term incentive opportunities. Benefits - Comprehensible benefits for full-time employees (part-time employees receive a limited package tailored to their role):

  • Medical, dental, and vision insurance
  • Robust vacation and sick leave benefits, and flexible work arrangements where permitted by role or contract
  • 401(k) plan that includes employer matching funds
  • Tuition reimbursement program
  • Life insurance and disability coverage
  • Optional coverages that can be purchased, including pet insurance, home and auto insurance, additional life and accident insurance, critical illness insurance, group legal, ID theft protection
  • Birth, adoption, parental leave benefits
  • Employee Assistance Plan


To review all Serco benefits please visit: https://careers.serco-na.com/us/en/about-us .

Serco complies with all applicable state and local leave laws, including providing time off under the Colorado Healthy Families and Workplaces Act for eligible Colorado residents, in alignment with our policies and benefit plans. The application window for this position is for no more than 60 days. We encourage candidates to apply promptly after the posting date, as the position may close earlier if filled or if the application volume exceeds expectations. Please submit applications exclusively through Serco's external (or internal) career site. If an applicant has any concerns with job posting compliance, please send an email to: careers@serco-na.com .
group id: 10118317
Find Serco Inc. on Social Media
Recruiters
user avatar
About Us
Serco, Inc. is the North America division of Serco Group, plc, one of the world’s leading service companies. At Serco we serve every branch of the U.S. Military, federal, state and local governments, Canadian and provincial governments, as well as commercial customers. We are a leading provider of professional, technology, engineering, trades, and management services, and we support the public service areas of Defense, Citizen Services, and Transportation. Discover your place in our world.

Serco Inc. Jobs


Job Category
IT - Security
Clearance Level
Secret
Employer
Serco Inc.