Senior ICAM Identity Governance and Provisioning Engineer
Reston, VA - USA
Job Summary
Serves as a senior technical engineer for ICAM identity governance automated account provisioning entitlement management and Master User Record capabilities; designing configuring integrating and sustaining identity lifecycle workflows role and attribute models access certification audit reporting and identity data synchronization across DoD enterprise cloud mission and legacy environments; supporting Zero Trust and FICAM-aligned ICAM services; and ensuring compliance with DoD NIST and Intelligence Community standards and frameworks.
Primary Responsibilities
Work with senior leadership customers application owners and mission partners to plan and execute ICAM governance and provisioning activities using Agile methodologies.
Integrate identity governance provisioning directory and audit capabilities across platforms such as SailPointRadiant LogicOkta SaviyntDelinea ServiceNow Microsoft Entra ID Active Directory LDAP and related ICAM technologies.
Assess current identity governance provisioning directory and entitlement environments; analyze alternatives and implement solutions that modernize enterprise account lifecycle management and replace manual access request processes.
Develop and present workflow designs integration artifacts provisioning rules access review materials test plans technical briefings and demonstrations.
Evaluate emerging identity governance and provisioning technologies and guide engineering teams in implementing scalable compliant and mission-aligned solutions.
Develop service design procedures and technical recommendations for identity lifecycle management delegated administration access certification entitlement management and identity data integration.
Ensure engineering teams deliver efficient and effective identity governance provisioning de-provisioning audit and compliance capabilities supporting enterprise missionobjectives.
Support integration of provisioning and entitlement services across cloud enterprise directory and mission application environments.
Provide technical status updates and implementation risk assessments to internal and external stakeholders.
Serve as a technical lead for identity governance automated provisioning and Master User Record implementation activities while mentoring junior engineers.
Prepare and present technical briefings demonstrations architecture diagrams and implementation plans.
Recognizedas a trusted technical leader for ICAM identity governance entitlement management and provisioning automation.
Required Qualifications
Active DoD Secret Clearance or higher.
Typically requires BS degree and 12 years relevant may be considered in lieu of degree.
Experience with IdAM / ICAM delivery systems identity governance automated provisioning and de-provisioning authentication authorization entitlement management access certification role engineering and digital policy management.
Experience integrating identity governance platforms with cloud enterprise directory and mission application environments using APIs SCIM LDAP Active Directory REST SQL and workflow automation technologies.
Understanding of RBAC ABAC segregation of duties privileged account auditing identity data normalization and identity-related audit/compliance processes supporting DoD accreditation requirements.
Experience supporting identity governance and provisioning services within cloud-hosted and hybrid enterprise environments.
Experience interacting with cross-functional teams including Software Development Systems Engineering Security Compliance Verification and Validation Quality Assurance and Operations.
Excellent oral and written communication skills.
Required Certification(s):
One or more DoD 8140.01 Level IIICertifications
Active Computing Environmental certification (CE) in job-related duties such as SailPoint Okta Saviynt Microsoft Entra ID AWS Cloud Microsoft Cloud or related ICAM platform certification
Desired Qualifications:
Experience supporting DoD ICAM Zero Trust or FICAM initiatives.
Experience implementing SailPoint Saviynt Okta Identity Governance or equivalent IGA platforms.
Experience supporting Master User Record (MUR) enterprise entitlement reporting or insider threat analytics capabilities.
Experience integrating legacy applications into enterprise identity governance and provisioning architectures.
Experience supporting IL5/IL6 GovCloud C2S or classified cloud environments.
Familiarity with NIST 800-53 NIST 800-63 NIST 800-162 and DoD Zero Trust guidance.
TS/SCI eligible.
If youre looking for comfort keep scrolling. At Leidos we outthink outbuild and outpace the status quo because the mission demands it. Were not hiring followers. Were recruiting the ones who disrupt provoke and refuse to fail. Step 10 is ancient history. Were already at step 30 and moving faster than anyone else dares.
For U.S. Positions: While subject to change based on business needs Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job education experience knowledge skills and abilities as well as internal equity alignment with market data applicable bargaining agreement (if any) or other law.
Required Experience:
Senior IC
About Company
Leidos is an innovation company rapidly addressing the world's most vexing challenges in national security and health. Our 47,000 employees collaborate to create smarter technology solutions for customers in these critical markets.