user avatar

ICAM/IAM Security Engineer (REMOTE)

TEKsystems c/o Allegis Group

Posted today

Job Requirements

Remote
Secret Polygraph not specified
Mid Level Career (5+ yrs experience)
$90,000 - $150,000

Job Description

We are seeking an Identity and Access Management Engineer to support a growing federal cybersecurity program. This position will help design, implement, and operationalize enterprise Identity, Credential, and Access Management solutions across cloud and on-premises environments.

The ideal candidate is a hands-on identity engineer who has participated in ICAM implementations from planning through deployment and application onboarding. This is not a governance, audit, or purely advisory position. The team needs someone who understands identity architecture but is also comfortable configuring platforms, integrating applications, troubleshooting technical issues, and working directly with stakeholders.

Responsibilities
Support the design, implementation, deployment, and ongoing management of enterprise ICAM solutions
Configure and integrate identity platforms such as Okta, SailPoint, Ping Identity, CyberArk, or comparable IAM technologies
Participate in full lifecycle ICAM implementations, from requirements gathering and solution design through deployment, testing, and operational support
Lead or support the onboarding of applications into identity management, governance, and access management platforms
Work directly with application owners and stakeholders to collect requirements, identify technical dependencies, resolve onboarding challenges, and drive adoption
Implement identity lifecycle processes, including:
User provisioning and deprovisioning
Joiner, mover, and leaver workflows
Access requests and approvals
Entitlement management
Periodic access reviews and recertification
Configure and troubleshoot Single Sign-On, Multi-Factor Authentication, identity federation, authentication, authorization, and directory services
Integrate ICAM solutions with enterprise applications, APIs, directories, cloud platforms, and on-premises infrastructure
Develop and enforce access control policies and technical standards aligned with federal ICAM requirements and Zero Trust principles
Support identity services across IaaS, PaaS, SaaS, and traditional data center environments
Identify and resolve technical or organizational friction points that affect application onboarding and identity program adoption
Translate federal mission and security requirements into practical identity solutions and implementation plans
Collaborate with cybersecurity engineers, architects, application teams, infrastructure teams, and client stakeholders
Document technical designs, configurations, integration requirements, implementation procedures, and operational processes
Provide technical guidance to junior engineers and support the review of implementation work

Required Qualifications
Approximately four or more years of cybersecurity, identity engineering, or related technical experience
Hands-on experience implementing, configuring, integrating, or supporting enterprise identity and access management solutions
Experience with at least one enterprise identity platform, such as:
Okta
SailPoint IdentityIQ or IdentityNow
Ping Identity
CyberArk
A comparable IAM, IGA, access management, or PAM platform
Experience supporting one or more of the following:
Identity Governance and Administration
Access Management
Single Sign-On
Multi-Factor Authentication
Identity federation
Privileged Access Management
Identity lifecycle management
Demonstrated experience participating in a technical implementation rather than only auditing, assessing, or providing governance oversight
Experience integrating identity platforms with applications, directories, APIs, or enterprise infrastructure
Understanding of identity architecture and the processes required to operationalize an enterprise identity program
Experience gathering requirements and working with application owners or business stakeholders during application onboarding
Strong troubleshooting and problem-solving skills
Ability to clearly communicate technical concepts to both technical and non-technical stakeholders
Bachelor’s degree from an accredited college or university
Active U.S. Government Secret clearance

Preferred Qualifications
Experience supporting U.S. federal government clients or federal cybersecurity programs
Knowledge of federal identity standards and frameworks, including:
Federal Identity, Credential, and Access Management
HSPD-12
PIV and CAC authentication
NIST SP 800-53
NIST SP 800-63 Digital Identity Guidelines
Experience implementing identity capabilities within a broader Zero Trust security model
Experience with identity services in AWS, Microsoft Azure, or Google Cloud Platform
Experience onboarding multiple applications into an IAM, IGA, or access management platform
Experience working across both cloud and on-premises environments
Platform-specific certifications from Okta, SailPoint, Ping Identity, or CyberArk
Cybersecurity certifications such as CISSP, GSEC, or GCED

Work Location
The position may be performed primarily remotely, with occasional travel for client meetings or project-specific requirements
Candidates located in the National Capital Region or St. Louis area may receive additional consideration based on current and future program needs
Candidates supporting the program from St. Louis should be comfortable with periodic onsite client support, potentially up to three days per week based on project needs
Onsite expectations may remain flexible depending on the individual, location, and client requirements

Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms.  If eligible, the benefits available for this temporary role may include the following:
• Medical, dental & vision
• Critical Illness, Accident, and Hospital
• 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available
• Life Insurance (Voluntary Life & AD&D for the employee and dependents)
• Short and long-term disability
• Health Spending Account (HSA)
• Transportation benefits
• Employee Assistance Program
• Time Off/Leave (PTO, Vacation or Sick Leave)

· This position requires an active DoD Clearance (Secret, Top Secret, Top Secret/SCI) or the ability to be obtain an (Interim Secret, Interim Top Secret)
· Because an active or interim DoD clearance is required, U.S. Citizenship is required
group id: 10105424
Find TEKsystems c/o Allegis Group on Social Media
Recruiters
user avatar
About Us
We’re partners in transformation. We help customers activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services and real-world application, we work with progressive leaders to drive change. That’s the power of true partnership. TEKsystems is an Allegis Group company.

TEKsystems c/o Allegis Group Jobs


Job Category
IT - Security
Clearance Level
Secret