IAM Lead
Washington, DC - USA
Job Summary
This role is contingent upon a contract award.
ICF is seeking an IAM Lead to architect implement andoperatethe identity and access management platform for a federal technology program.Reporting toengineering leadership this role is the subjectmatterauthority on how users devices and applications authenticate and are authorized across a cloud-first Zero Trust environment. The IAM Lead owns the full identity lifecycle from onboarding automation to privileged access controls to external identity federation.
The ideal candidate is a senior identity engineer who has built and operated IAM programs in federal cloud environments. This is a deeply technical role. The right candidate understands not just the tooling but the underlying standards can implement NIST identity assurance requirements and can hold their own with cybersecurity and enterprise architecture teams on access policy design.
Job Location:This is a remote-friendly position with occasional onsite requirements in the Washington DC Metro area.
This position requires that the job be performed in the United States.If you accept this position you should note that ICF does monitor employee work locations and blocks access from foreign locations/foreign IP addressesand alsoprohibits personal VPN connections.
What Youll Be Doing
Architect configure andmaintainidentity platforms including Entra ID Entra External ID and Okta covering authentication authorization provisioning and lifecycle management across all users applications and devices.
Configure and enforce phishing-resistant authentication for all users including passkeys FIDO2 security keysWebAuthn and biometrics. Drive the transition away from legacy authentication methods toward a fullypasswordlessposture.
Define and implement Zero Trust access rules based on user risk device health location and behavior using risk-based and conditional access policies.
Design configure andoperateauthorization models including RBAC PBAC and ABAC with fine-grained permissions and attribute-based access rules aligned to job function and least-privilege principles.
Manage privileged accounts and administrative roles using privileged access management (PAM) and just-in-time elevation ensuring that standing admin access isminimizedand all elevated access is logged and time-bound.
Build andmaintainHR-driven joiner mover and leaver automation including automated provisioning license assignment role changes access revocation and data archival triggered by HR system events.
Federate external identities including partners contractors and external collaborators using Entra External ID or equivalent including self-service registrationverificationworkflows and consent management.
Configure identity proofing and verification to NIST IAL and AAL levels where coordinating with cybersecurity and compliance teams on assurance requirements.
Integrate applications and APIs with identity platforms using OIDC OAuth2 SAML and SCIM for single sign-on and automated provisioning.
Monitor sign-in activity risk signals and anomalies. Respond to identity-related incidents including account takeover phishing access abuse and fraud in coordination with the cybersecurity team.
Maintain identity data quality and consistency across directories HR systems and applications including synchronization schema management and attribute mapping.
Support compliance and audit activities by producing access reports certifications attestations and evidence of controls.
Documentidentity architectures configurations standards and runbooks. Provide guidance to application teams on how toonboard tocentral identity platforms and implement authentication best practices.
MinimumRequirements
Bachelors degree or equivalent
7 years of experience in identity and access management engineering or a related discipline
3 years of hands-on experience designing and operating Entra ID or Okta in production environments including conditional access lifecycle management and federation
2 years implementing PAM solutions and just-in-time elevation controls for privileged accounts
2 years configuring authorization models including RBAC PBAC or ABAC in enterprise environments
2 years supporting federal IT programs in HHS NIH FDA or other health-focused agencies
U.S. Citizenshipdue to federal contract requirements
Ability to obtain andmaintaina Public Trust background investigation
Candidate mustresidein the USbe authorized towork in the US and work must be performed in the US
Preferred Qualifications
Experience implementing NIST SP 800-63 identity assurance levels (IAL/AAL) in a federal context
Experience federating external identities using Entra External ID including self-service registration and consent workflows
Familiarity with FISMA NIST 800-53 and Zero Trust architecture requirements as they apply to identity and access
Experience integrating identity platforms with HR systems for automated joiner mover and leaver workflows
Relevant certifications such as Microsoft Certified: Identity and Access Administrator Okta Certified Administrator or equivalent
Experience supporting identity incident response including account takeover phishing and access abuse investigations
Working at ICF
ICF is a global advisory and technology services provider but were not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges navigate change and shape the future.We can only solve the worlds toughest challenges by building a workplace that allows everyone to thrive. We are an equal opportunity employer.Together our employees are empowered to share theirexpertiseand collaborate with others to achieve personal and professional goals. For more information please read ourEEOpolicy.
We will consider for employment qualified applicants with arrest and conviction records.
Reasonable Accommodations are available including but not limited to for disabled veterans individuals with disabilities and individuals withsincerely heldreligious beliefs in all phases of the application and employment process. To requestan accommodationplease emailand we will be happy toassist. All information you provide will be kept confidential and will be used only to the extentto provide needed reasonable accommodations.
Read more aboutworkplacediscriminationrightsor our benefit offerings which are included in theTransparency in (Benefits) CoverageAct.
At ICF we are committed to ensuring a fair interview process for all candidates based on their own skills and knowledge. As part of this commitment the use of artificial intelligence (AI) tools to generate orassistwith responses during interviews (whether in-person or virtual) is notpermitted. This policy is in place tomaintainthe integrity and authenticity of the interview process.
However we understand that some candidates may require accommodationthat involves the use of AI. Ifsuch anaccommodation is needed candidates are instructed to contact us in advance at. Weare dedicated to providingthe necessary support to ensure that all candidates have an equal opportunity to succeed.
Pay Range - There are multiple factors that are considered in determining final pay for a position including but not limited to relevant work experience skills certifications and competencies that align to the specified role geographic location education and certifications as well as contract provisions regarding labor categories that are specific to the position.
The pay range for this position based on full-time employment is:
$108006.00 - $183610.00DC Remote Office (DC99)About Company
About ICF: The Integral Coach Factory is one of the earliest production units of independent India. It was inaugurated by the first Prime Minister of India Pt. Jawaharlal Nehru on 2nd October, 1955. Later the Furnishing Division was inaugurated on 2nd October, 1962 and the production ... View more