user avatar
Posted today

Job Requirements

Chantilly, VA
Top Secret/SCI Polygraph Unspecified
Senior Level Career (10+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries

Job Description



Bailey Information Technology, LLC

TS/SCI ICAM Architect
  • Chantilly, VA
  • Information Technology


ICAM Architect – GEOAxIS Modernization

(PDP, PEP/PIP, EMS & RPMS Modernization)



Location: Chantilly, VA

Clearance: TS, SCI/Poly eligible

Certifications: Ability to obtain Security+ within 90 days of hire.

Level: T5



Job Description:

Bailey Information Technology  is undergoing a significant modernization effort to transition legacy ICAM capabilities including Policy Enforcement Points (PEP), Policy Information Points (PIP), Enterprise Management Services (EMS), and Resource & Policy Management Services (RPMS) to modern on-prem and cloud-ready technologies, improved architectural patterns, and automated deployment pipelines.


The ICAM Architect role provides the technical architectural oversight necessary to ensure the modernization effort is strategically aligned, technically sound, secure, and extensible. This position supports the Technical Lead and program leadership by defining the target architecture, guiding engineering teams, mapping legacy-to-modern transitions, and ensuring all designs meet mission, security, and interoperability requirements. This position is a short‑term assignment with an expected duration of 7 months.


Responsibilities:


  • Define and maintain the enterprise ICAM architecture across PEP/PIP/EMS and RPMS modernization, ensuring alignment with NGA’s ZT and ICAM strategic framework. Transition from the legacy PDP to JBlocks.

  • Develop end‑to‑end architectural patterns for identity, attribute services, authorization flows, policy distribution, and resource/role lifecycle management.

  • Partner closely with the Technical Lead to validate modernization roadmaps, architectural decisions, and integration strategies for on-prem and cloud-native, microservices-based ICAM components.

  • Translate mission needs into technical requirements, sequence diagrams, data models, interface specifications, and system architecture artifacts.

  • Oversee the design of modern PEP/PIP interfaces that support attribute-based access control, dynamic policy evaluation, and event-driven decision making.

  • Architect improved EMS and RPMS capabilities including resource registration, policy lifecycle automation, attribute orchestration, and enterprise authorization services.

  • Provide architectural guidance to Development and Operations (DevOps) and Software teams to ensure solutions meet scalability, resilience, security, and maintainability requirements.

  • Conduct architectural reviews, risk assessments, and compliance verification for modernization milestones and incremental releases.

  • Ensure modernization reduces operational overhead through automation, standardization, improved observability, and optimized deployment pipelines.

  • Identify opportunities for innovation in identity services, authentication technologies, authorization models, and system integration patterns.

  • Serve as a senior advisor to program management, providing technical insight to support planning, budgeting, and customer engagement.



Requirements/Qualifications:


  • Master’s degree in a Science, Technology, Engineering, and Mathematics (STEM) field and 10+ years of relevant experience, or Bachelor’s degree and 12+ years of experience.

  • Demonstrated experience as a solutions architect, systems architect, or enterprise architect supporting complex modernization, security, or ICAM programs.

  • Significant experience designing distributed systems, microservices architectures, and cloud-native solutions.

  • Experience leading or supporting teams engaged in ICAM modernization, enterprise identity technology, or authorization/policy services.

  • Familiarity with Agile methodologies and experience contributing to Program Increment (PI) planning, architectural runway development, and iterative delivery.

  • Ability to define architectural goals, strategic plans, and detailed implementation guidance aligned with mission priorities.

  • Ability to obtain Security+ within 90 days of hire.



Preferred Qualifications:


  • Experience with Kubernetes, OpenShift, or container orchestration platforms.

  • Experience with modern programming languages and integration (Java and/or Python).

  • Knowledge of GitOps tools for managing modern environments.

  • Certifications in enterprise architecture frameworks.

  • Expertise with identity and authorization standards (X.509, SAML, OAuth2, OIDC, LDAP).

  • Experience architecting ICAM solutions using Oracle or other enterprise-grade identity platforms.

  • Experience defining ABAC/RBAC models, policy-as-code, and ZT-aligned access patterns.

  • Prior experience supporting NGA or Intelligence Community authorization/identity systems.




Clearance Requirements*

Requires an active Top Secret security clearance upon hire and must meet SCI eligibility. Must be willing and able to obtain a polygraph within the customer’s timeline after hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required.

Apply Now

More Openings


Share This Job

group id: 10501622